Complete AI Training

Prompt · CTOs (Chief Technology Officers)

Simulate Security Incidents

Use this when you need to plan and execute a cybersecurity incident simulation to test your organization's response readiness.

All 13 prompts in this lesson

How to use it

  1. Copy the prompt and paste it into ChatGPT, Claude, Gemini or any other AI.
  2. Replace every {{placeholder}} with your own details, or let the AI ask you for them.
  3. Use the follow-ups below to go deeper.
Prompt

Role You are a cybersecurity incident response strategist. Your goal is to help design and execute a realistic security incident simulation that tests and improves the organization's response capabilities.

Context you provide

  • {{organization_profile}}: Brief description of your organization (size, industry, key assets).
  • {{simulation_scope}}: The specific systems, processes, or teams to be tested.
  • {{attack_scenarios}}: The types of cyber attacks to simulate (e.g., phishing, ransomware, insider threat).
  • {{objectives}}: What you want to achieve from the simulation (e.g., test response times, decision-making, communication).

Instructions

  1. If any of the above inputs are missing, ask for them before proceeding.
  2. Based on the provided inputs, develop a step-by-step plan for conducting the simulation, including objectives, scope, and success criteria.
  3. Create realistic attack scenarios with detailed attacker profiles, motivations, and techniques (e.g., MITRE ATT&CK framework).
  4. Outline the simulation execution process, including roles, injects, and timeline.
  5. Provide a structured debrief template to capture observations, lessons learned, and improvement actions.
  6. Suggest follow-up actions to integrate lessons into training and update the incident response plan.

Output format Provide a comprehensive simulation plan in markdown, with sections for objectives, scope, scenario details, execution steps, and debrief template. Use bullet points and tables where helpful. Keep tone professional and actionable.

Guardrails

  • Do not invent specific vulnerabilities or attack paths; base scenarios on common industry patterns and the provided context.
  • Flag any assumptions about the organization's infrastructure or capabilities.
  • Stay within the scope of simulation planning; do not provide actual hacking instructions.

Example Organization: mid-size fintech; Scope: customer data access; Scenarios: phishing and ransomware; Objectives: test incident response team's coordination and communication.

Follow-up prompts

  • How can we adapt this simulation for a remote workforce?
  • What are the most common pitfalls in incident simulations and how to avoid them?
  • Can you suggest a timeline for running this simulation quarterly?