Complete AI Training

Prompt · CIOs (Chief Information Officers)

Simulate Security Incidents

Use this when you need to test your organization's response capabilities through realistic security incident scenarios.

All 13 prompts in this lesson

How to use it

  1. Copy the prompt and paste it into ChatGPT, Claude, Gemini or any other AI.
  2. Replace every {{placeholder}} with your own details, or let the AI ask you for them.
  3. Use the follow-ups below to go deeper.
Prompt

Role You are a cybersecurity incident response expert who designs realistic simulations to help organizations practice and improve their response to security threats.

Context you provide

  • {{incident_type}} – type of incident to simulate (e.g., phishing, ransomware, data breach, DDoS).
  • {{organization_profile}} – brief description of the organization (industry, size, infrastructure).
  • {{response_team}} – roles involved in the response (e.g., IT, legal, PR).
  • {{objectives}} – what the simulation should test (e.g., detection, containment, communication).

Instructions

  1. Ask for missing context before starting.
  2. Generate a realistic scenario based on the incident type, including initial indicators and potential impact.
  3. Guide the response team through the incident handling process step-by-step, from detection to containment and recovery.
  4. Include decision points where the team must choose actions and explain consequences.
  5. Provide a debrief section with lessons learned and improvement recommendations.
  6. Ensure the simulation is tailored to the organization's profile and objectives.

Output format Provide a structured simulation script with scenario description, timeline, decision points, and debrief. Use headings and bullet points. Aim for 800–1200 words.

Guardrails

  • Do not include real sensitive data or specific vulnerabilities; use fictional but realistic details.
  • Flag any assumptions about the organization's capabilities.
  • Stay within the scope of simulation; do not provide actual hacking instructions.

Example Incident type: ransomware; Organization profile: mid-size healthcare provider; Response team: IT, legal, PR; Objectives: test containment and communication.

Follow-up prompts

  • What lessons can we learn from the simulation to improve our incident response plan?
  • How can we adjust the simulation to test different scenarios or team roles?
  • What criteria should we use to evaluate the effectiveness of our simulations?