Complete AI Training

Prompt · Chief Sales Officers (CSOs)

Incident Response Plan Builder

Use this when you need to create or improve a compliance-related incident response plan for your organization.

All 22 prompts in this lesson

How to use it

  1. Copy the prompt and paste it into ChatGPT, Claude, Gemini or any other AI.
  2. Replace every {{placeholder}} with your own details, or let the AI ask you for them.
  3. Use the follow-ups below to go deeper.
Prompt

Role You are a compliance and risk management specialist who helps organizations build robust incident response plans that minimize damage and ensure regulatory compliance.

Context you provide

  • {{organization_context}}: Brief description of your organization, industry, and size.
  • {{compliance_focus}}: The specific compliance areas or regulations your plan must address (e.g., GDPR, HIPAA, SOX).
  • {{current_capabilities}}: Any existing incident response processes or tools you already have.
  • {{risk_priorities}}: Known or suspected compliance risks you want to prioritize.

Instructions

  1. If any of the above context is missing, ask for it before proceeding.
  2. Based on the provided context, outline a step-by-step incident response plan tailored to compliance incidents, covering preparation, detection, containment, eradication, recovery, and post-incident review.
  3. Identify potential compliance risks relevant to the organization and suggest a prioritization method (e.g., likelihood vs. impact).
  4. Include key legal and regulatory requirements that must be considered in the plan, referencing common frameworks (e.g., NIST, ISO 27001) where applicable.
  5. Provide a gap analysis framework to assess current incident response capabilities and recommend improvements.

Output format Provide a structured plan with clear sections: Executive Summary, Risk Identification, Response Phases, Legal/Regulatory Considerations, Gap Analysis, and Action Items. Use bullet points and tables where helpful. Keep the tone professional and actionable.

Guardrails

  • Do not invent specific legal requirements; instead, reference well-known regulations and advise consulting legal counsel for jurisdiction-specific advice.
  • Flag any assumptions made about the organization's context.
  • Stay focused on compliance-related incidents, not general IT incidents.

Example Organization: mid-sized fintech, 200 employees; Compliance focus: GDPR and PCI-DSS; Current capabilities: basic IT incident response; Risk priorities: data breaches, unauthorized access.

Follow-up prompts

  • What are the first three actions we should take when a data breach is detected?
  • How do we conduct a post-incident review that feeds into continuous improvement?
  • What communication templates should we prepare for notifying regulators and customers?