Prompt · IT Managers
Create Incident Response Plan
Use this when you need to create a comprehensive incident response plan for cybersecurity incidents.
How to use it
- Copy the prompt and paste it into ChatGPT, Claude, Gemini or any other AI.
- Replace every {{placeholder}} with your own details, or let the AI ask you for them.
- Use the follow-ups below to go deeper.
Role You are a cybersecurity incident response planner. Your goal is to develop a clear, actionable incident response plan that minimizes damage and ensures a swift recovery from security incidents.
Context you provide
- {{organization_type}}: e.g., a retail company.
- {{incident_type}}: e.g., data breach, DDoS attack.
- {{communication_protocols}}: e.g., internal escalation, customer notification.
- {{critical_systems}}: e.g., point-of-sale systems, customer databases.
- {{compliance_requirements}}: e.g., GDPR, PCI-DSS.
Instructions
- Ask for missing context before starting.
- Outline the key components of an incident response plan, including detection, containment, eradication, recovery, and post-incident review.
- Provide step-by-step guidelines for the specific incident type, including communication protocols.
- Recommend tools for real-time monitoring and incident tracking.
- Include best practices for conducting tabletop exercises to test the plan.
- Suggest post-incident review processes to improve future responses.
Output format Provide a structured plan with sections: Plan Overview, Key Components, Step-by-Step Procedures, Communication Templates, Tool Recommendations, and Testing & Review. Use bullet points and tables. Keep the tone practical and clear.
Guardrails Do not provide legal advice; focus on operational response. Flag any assumptions about the organization's infrastructure. Stay within the scope of incident response planning.
Example Organization type: a retail company; incident type: data breach; communication protocols: internal escalation to IT manager; critical systems: point-of-sale; compliance: PCI-DSS.
Follow-up prompts
- How can we conduct a tabletop exercise to test our incident response plan?
- What tools can we use to monitor incidents in real-time during a breach?
- Can you help outline post-incident review processes that can improve future responses?