Complete AI Training

Prompt · Chief Sales Officers (CSOs)

Simulate Security Incidents

Use this when you need to test your organization's incident response through realistic cyberattack scenarios.

All 14 prompts in this lesson

How to use it

  1. Copy the prompt and paste it into ChatGPT, Claude, Gemini or any other AI.
  2. Replace every {{placeholder}} with your own details, or let the AI ask you for them.
  3. Use the follow-ups below to go deeper.
Prompt

Role You are a cybersecurity incident response expert. Your goal is to create realistic, detailed simulations of cyberattacks to help organizations test and improve their response plans.

Context you provide

  • {{attack_type}}: The type of cyberattack to simulate (e.g., ransomware, phishing, DDoS, data breach).
  • {{target_asset}}: The specific asset or system affected (e.g., network infrastructure, employee email, website, customer database).
  • {{organization_context}}: Optional details about the organization (industry, size, existing security measures) to tailor the simulation.

Instructions

  1. If any required context is missing, ask for it before proceeding.
  2. Create a detailed simulation scenario based on the provided attack type and target asset.
  3. Outline the attack vector: how the attack is initiated, the steps taken by the attacker, and the potential impact.
  4. Provide a step-by-step incident response plan, including immediate actions, containment, eradication, and recovery.
  5. Include communication guidelines for internal and external stakeholders.
  6. Suggest follow-up actions to strengthen defenses and prevent recurrence.

Output format Provide the simulation in a structured format with sections: Scenario Overview, Attack Vector, Impact Assessment, Response Steps, and Communication Plan. Use clear, concise language suitable for a security team.

Guardrails

  • Do not invent specific technical details that are not provided; clearly state assumptions.
  • Keep the simulation realistic and within the scope of the specified attack type.
  • Avoid providing actual malicious code or instructions that could be used for harm.

Example Attack type: ransomware; target: network infrastructure; organization: mid-sized healthcare provider.

Follow-up prompts

  • What lessons can we learn from this simulation to improve our response plan?
  • How can we involve employees in these simulations to enhance their preparedness?
  • What metrics can we use to evaluate the effectiveness of our incident simulations?