Complete AI Training

Prompt · IT Managers

Build Incident Response Playbook

Use this when you need to develop a detailed incident response plan for cybersecurity incidents.

All 21 prompts in this lesson

How to use it

  1. Copy the prompt and paste it into ChatGPT, Claude, Gemini or any other AI.
  2. Replace every {{placeholder}} with your own details, or let the AI ask you for them.
  3. Use the follow-ups below to go deeper.
Prompt

Role You are a cybersecurity incident response expert. Your objective is to create a comprehensive, actionable playbook that guides the organization through detection, containment, and recovery from security incidents.

Context you provide

  • {{incident_type}}: e.g., ransomware attack, data breach, insider threat.
  • {{organization_type}}: e.g., a government agency.
  • {{infrastructure}}: e.g., cloud-based, on-premises, hybrid.
  • {{critical_assets}}: e.g., customer database, email servers.
  • {{communication_protocols}}: e.g., internal escalation, external reporting.

Instructions

  1. Ask for missing context before starting.
  2. Outline the incident response lifecycle: preparation, detection, analysis, containment, eradication, recovery, and post-incident review.
  3. Provide step-by-step guidelines for the specific incident type, including roles and responsibilities.
  4. Recommend incident management tools that facilitate tracking and reporting.
  5. Include communication templates for internal and external stakeholders.
  6. Suggest metrics to measure the effectiveness of the response plan.

Output format Deliver a structured playbook with sections: Incident Overview, Response Phases, Roles & Responsibilities, Communication Plan, Tool Recommendations, and Metrics. Use numbered steps and tables for clarity. Keep the tone authoritative and precise.

Guardrails Do not provide legal advice; focus on operational response. Flag any assumptions about the organization's infrastructure. Stay within the scope of incident response planning.

Example Incident type: ransomware; organization type: a government agency; infrastructure: hybrid; critical assets: citizen data; communication protocols: internal escalation to CISO.

Follow-up prompts

  • What metrics should we track to measure the effectiveness of our incident response?
  • How can we conduct a post-incident analysis to improve our response plan?
  • Can you provide examples of tools that facilitate incident tracking and reporting?