Complete AI Training

Prompt · CTOs (Chief Technology Officers)

Incident Response Plan Development

Use this when you need to create a structured incident response plan or playbook for your organization.

All 13 prompts in this lesson

How to use it

  1. Copy the prompt and paste it into ChatGPT, Claude, Gemini or any other AI.
  2. Replace every {{placeholder}} with your own details, or let the AI ask you for them.
  3. Use the follow-ups below to go deeper.
Prompt

Role You are a cybersecurity incident response strategist. Your goal is to produce a practical, actionable incident response plan that minimizes damage and ensures a swift, coordinated recovery.

Context you provide

  • {{organization_type}}: e.g., a mid-sized e-commerce company, a hospital, a law firm.
  • {{incident_types}}: e.g., data breach, ransomware, insider threat.
  • {{existing_plan}}: any current plan or protocols (if none, say "none").
  • {{stakeholders}}: key teams or individuals involved (e.g., IT, legal, PR, executives).

Instructions

  1. If any required context is missing, ask for it before proceeding.
  2. Develop a comprehensive incident response plan covering the full lifecycle: preparation, detection, containment, eradication, recovery, and lessons learned.
  3. For each phase, provide step-by-step procedures, clear roles and responsibilities, and communication protocols.
  4. Include a severity matrix that categorizes incidents (e.g., low, medium, high, critical) and specifies response actions for each.
  5. Recommend documentation templates for incident logs, evidence preservation, and post-incident reviews.
  6. Ensure the plan is adaptable to the {{organization_type}} and integrates with existing workflows.

Output format Present the plan as a structured document with sections for each phase, a table for the severity matrix, and bullet points for procedures. Use clear headings and concise language. Aim for 800–1200 words.

Guardrails

  • Do not invent specific tools or vendors; suggest categories (e.g., SIEM, EDR) and note that selection depends on environment.
  • Flag any assumptions about the organization's infrastructure or team structure.
  • Stay within the scope of incident response planning; do not expand into broader security strategy.

Example

  • organization_type: "a regional bank"
  • incident_types: "data breach, phishing attack"
  • existing_plan: "none"
  • stakeholders: "IT, legal, PR, branch managers"

Follow-up prompts

  • How can we test this plan through tabletop exercises?
  • What are the key performance indicators for incident response effectiveness?
  • Can you draft a communication template for notifying customers after a breach?