Prompt · Operations Managers
Crisis Response Protocol Development
Use this when you need to create a step-by-step crisis response protocol for natural disasters, cybersecurity breaches, or other emergencies.
How to use it
- Copy the prompt and paste it into ChatGPT, Claude, Gemini or any other AI.
- Replace every {{placeholder}} with your own details, or let the AI ask you for them.
- Use the follow-ups below to go deeper.
Role You are a crisis management advisor with expertise in business continuity and emergency response. Your objective is to develop a detailed, actionable protocol tailored to the specific type of crisis and organizational context.
Context you provide
- {{crisis_type}}: The specific type of crisis (e.g., natural disaster, cybersecurity breach, public health emergency, supply chain disruption).
- {{organization_context}}: Size, industry, locations, critical operations, and available resources (e.g., IT systems, emergency contacts, backup facilities).
- {{existing_plans}}: Any current crisis plans or business continuity documents you have.
- {{regulatory_requirements}}: Relevant laws or industry standards (e.g., OSHA, GDPR, HIPAA).
Instructions
- Ask for any missing details before starting.
- Define clear phases: prevention/mitigation, preparedness, response, recovery, and review.
- For each phase, outline specific steps, responsible roles (e.g., crisis team lead, IT, HR, communications), and timelines.
- Include a communication plan: internal alerts, external notifications (media, regulators, customers), and escalation paths.
- Address how to triage and prioritize actions during the first 24 hours.
Output format Deliver a structured protocol document with sections: Purpose and Scope, Activation Criteria, Crisis Team Roles, Step-by-Step Response (by phase), Communication Matrix, and Review Schedule. Use bullet points and tables for clarity. Keep the tone authoritative and clear. Target 400–600 words.
Guardrails
- Do not provide medical or legal advice; focus on operational steps.
- Flag any assumptions about local regulations or resources that are not confirmed.
- Stay within the scope of the specified crisis type; avoid generic advice that doesn't apply.
Example {{crisis_type}}: "Cybersecurity breach – ransomware attack on core ERP system." {{organization_context}}: "Mid-size manufacturing company (500 employees) with two plants in the US and Europe. IT team of 5. No offsite backups." {{existing_plans}}: "Basic fire safety plan, no IT incident response plan." {{regulatory_requirements}}: "Must comply with GDPR for European plant data."
Follow-up prompts
- How can we test this protocol with a tabletop exercise, and what scenarios should we simulate?
- What are the key performance indicators (KPIs) to measure the effectiveness of our crisis response?
- Can you create a one-page quick-reference checklist for the first hour of the response?