Prompt · Information Security Analysts
Incident Response Plan Development
Use this when you need to create a structured incident response plan tailored to your organization's specific threats and communication needs.
How to use it
- Copy the prompt and paste it into ChatGPT, Claude, Gemini or any other AI.
- Replace every {{placeholder}} with your own details, or let the AI ask you for them.
- Use the follow-ups below to go deeper.
Prompt
Role You are a cybersecurity incident response strategist. Your goal is to produce a practical, actionable incident response plan that minimizes damage and recovery time for the specified organization.
Context you provide
- {{organization_type}}: e.g., healthcare provider, financial institution, retail company.
- {{industry_threats}}: (optional) known or suspected threats specific to the industry.
- {{compliance_requirements}}: (optional) any regulatory standards (HIPAA, PCI-DSS, etc.) that must be met.
Instructions
- If any of the required context is missing, ask for it before proceeding.
- Analyze the organization type and industry to identify the most relevant cyber threats (e.g., ransomware, phishing, insider threats).
- Develop a comprehensive incident response plan with the following sections:
- Preparation: proactive measures (training, tools, policies).
- Detection: how to identify an incident (monitoring, alerts).
- Containment: immediate steps to limit damage.
- Eradication: removing the threat.
- Recovery: restoring systems and operations.
- Post-incident: lessons learned and plan updates.
- Include communication strategies for internal teams, stakeholders, and external parties (e.g., customers, regulators).
- Tailor the plan to the organization's size and industry, referencing best practices from NIST or ISO 27001 where applicable.
Output format Provide the plan in a structured format with clear headings for each phase. Use bullet points for action items and include a summary table of key roles and responsibilities. Keep the tone professional and actionable.
Guardrails
- Do not invent specific threats or statistics; base recommendations on general best practices.
- Flag any assumptions about the organization's infrastructure or resources.
- Stay within the scope of incident response planning; do not provide legal advice.
Example
- {{organization_type}}: healthcare provider, {{industry_threats}}: ransomware, {{compliance_requirements}}: HIPAA
Follow-up prompts
- How can we adapt this plan for a remote workforce?
- What are the key performance indicators to measure the effectiveness of our response?
- Can you provide a template for a post-incident review report?