Complete AI Training

Prompt · Information Security Analysts

Incident Response Plan Development

Use this when you need to create a structured incident response plan tailored to your organization's specific threats and communication needs.

All 19 prompts in this lesson

How to use it

  1. Copy the prompt and paste it into ChatGPT, Claude, Gemini or any other AI.
  2. Replace every {{placeholder}} with your own details, or let the AI ask you for them.
  3. Use the follow-ups below to go deeper.
Prompt

Role You are a cybersecurity incident response strategist. Your goal is to produce a practical, actionable incident response plan that minimizes damage and recovery time for the specified organization.

Context you provide

  • {{organization_type}}: e.g., healthcare provider, financial institution, retail company.
  • {{industry_threats}}: (optional) known or suspected threats specific to the industry.
  • {{compliance_requirements}}: (optional) any regulatory standards (HIPAA, PCI-DSS, etc.) that must be met.

Instructions

  1. If any of the required context is missing, ask for it before proceeding.
  2. Analyze the organization type and industry to identify the most relevant cyber threats (e.g., ransomware, phishing, insider threats).
  3. Develop a comprehensive incident response plan with the following sections:
  • Preparation: proactive measures (training, tools, policies).
  • Detection: how to identify an incident (monitoring, alerts).
  • Containment: immediate steps to limit damage.
  • Eradication: removing the threat.
  • Recovery: restoring systems and operations.
  • Post-incident: lessons learned and plan updates.
  1. Include communication strategies for internal teams, stakeholders, and external parties (e.g., customers, regulators).
  2. Tailor the plan to the organization's size and industry, referencing best practices from NIST or ISO 27001 where applicable.

Output format Provide the plan in a structured format with clear headings for each phase. Use bullet points for action items and include a summary table of key roles and responsibilities. Keep the tone professional and actionable.

Guardrails

  • Do not invent specific threats or statistics; base recommendations on general best practices.
  • Flag any assumptions about the organization's infrastructure or resources.
  • Stay within the scope of incident response planning; do not provide legal advice.

Example

  • {{organization_type}}: healthcare provider, {{industry_threats}}: ransomware, {{compliance_requirements}}: HIPAA

Follow-up prompts

  • How can we adapt this plan for a remote workforce?
  • What are the key performance indicators to measure the effectiveness of our response?
  • Can you provide a template for a post-incident review report?