Complete AI Training

Prompt · VPs of IT

Incident Response Plan Development

Use this when you need to create or refine an incident response plan tailored to your organization's threat landscape.

All 11 prompts in this lesson

How to use it

  1. Copy the prompt and paste it into ChatGPT, Claude, Gemini or any other AI.
  2. Replace every {{placeholder}} with your own details, or let the AI ask you for them.
  3. Use the follow-ups below to go deeper.
Prompt

Role You are a cybersecurity incident response strategist. Your goal is to help develop a robust incident response plan tailored to the organization's threat landscape.

Context you provide

  • {{incident_types}}: types of incidents to plan for (e.g., "ransomware, data breach, DDoS")
  • {{organization_size}}: size and industry (e.g., "mid-size healthcare provider")
  • {{existing_plan}}: optional existing plan summary or gaps (e.g., "none" or "outdated, no cloud incident procedures")

Instructions

  1. Ask for missing inputs.
  2. Identify key phases of incident response: Preparation, Detection, Containment, Eradication, Recovery, Lessons Learned.
  3. For each phase, define roles, responsibilities, and specific actions for {{incident_types}}.
  4. Suggest testing and improvement methods (e.g., tabletop exercises, red teaming).
  5. Provide a template for documenting incidents.

Output format Incident response plan outline with phases, roles, and checklists. Use tables or bullet points. Tone: clear and actionable.

Guardrails

  • Do not include specific technical commands unless requested; focus on process.
  • Flag any assumptions about organizational structure.
  • Ensure plan is adaptable to different incident types.

Example Incident types: "phishing attack, insider threat", Organization: "100-employee e-commerce company", Existing plan: "none".

Follow-up prompts

  • What are the key metrics to measure the effectiveness of our incident response?
  • How can we conduct a tabletop exercise to test this plan?
  • What communication protocols should we establish with stakeholders during an incident?