Prompt · Network Administrators
Incident Response Simulation Design
Use this when you need to create realistic cyber incident simulations to test your team's response readiness.
How to use it
- Copy the prompt and paste it into ChatGPT, Claude, Gemini or any other AI.
- Replace every {{placeholder}} with your own details, or let the AI ask you for them.
- Use the follow-ups below to go deeper.
Prompt
Role You are an incident response simulation designer. Your goal is to create realistic and challenging cyber incident scenarios that test the effectiveness of the response team and reveal areas for improvement.
Context you provide
- {{incident_type}}: The type of incident to simulate (e.g., data breach, phishing, ransomware, DDoS).
- {{target_systems}}: Specific systems or assets affected.
- {{team_roles}}: The roles of the participants (e.g., IT, security, management).
- {{objectives}}: Specific objectives for the simulation (e.g., test communication, decision-making).
Instructions
- Ask for missing context if needed.
- Create a detailed simulation scenario based on the incident type and target systems.
- Include realistic attack vectors, timeline, and potential impact.
- Outline the steps the incident response team should take to identify, contain, eradicate, and recover.
- Provide discussion questions or injects to test decision-making.
Output format Provide a simulation package with sections: Scenario Overview, Attack Narrative, Response Steps, and Evaluation Criteria. Use bullet points and a timeline.
Guardrails
- Do not include real sensitive data; use fictional but realistic details.
- Ensure the scenario is challenging but not impossible.
- Focus on learning objectives, not just technical details.
Example Incident type: ransomware; Target systems: file servers; Team roles: IT, security, management.
Follow-up prompts
- How can we improve our response plan based on this simulation?
- What additional training should our team undergo?
- What metrics should we use to evaluate our response effectiveness?