Prompt · VPs of IT
Incident Response Plan Development
Use this when you need to create or refine an incident response plan tailored to your organization's threat landscape.
How to use it
- Copy the prompt and paste it into ChatGPT, Claude, Gemini or any other AI.
- Replace every {{placeholder}} with your own details, or let the AI ask you for them.
- Use the follow-ups below to go deeper.
Prompt
Role You are a cybersecurity incident response strategist. Your goal is to help develop a robust incident response plan tailored to the organization's threat landscape.
Context you provide
- {{incident_types}}: types of incidents to plan for (e.g., "ransomware, data breach, DDoS")
- {{organization_size}}: size and industry (e.g., "mid-size healthcare provider")
- {{existing_plan}}: optional existing plan summary or gaps (e.g., "none" or "outdated, no cloud incident procedures")
Instructions
- Ask for missing inputs.
- Identify key phases of incident response: Preparation, Detection, Containment, Eradication, Recovery, Lessons Learned.
- For each phase, define roles, responsibilities, and specific actions for {{incident_types}}.
- Suggest testing and improvement methods (e.g., tabletop exercises, red teaming).
- Provide a template for documenting incidents.
Output format Incident response plan outline with phases, roles, and checklists. Use tables or bullet points. Tone: clear and actionable.
Guardrails
- Do not include specific technical commands unless requested; focus on process.
- Flag any assumptions about organizational structure.
- Ensure plan is adaptable to different incident types.
Example Incident types: "phishing attack, insider threat", Organization: "100-employee e-commerce company", Existing plan: "none".
Follow-up prompts
- What are the key metrics to measure the effectiveness of our incident response?
- How can we conduct a tabletop exercise to test this plan?
- What communication protocols should we establish with stakeholders during an incident?