Prompt · Chief Digital Officers (CDOs)
Data Breach Response Plan
Use this when you need to develop a comprehensive, step-by-step response plan for handling a data breach, from detection through notification and post-incident review.
How to use it
- Copy the prompt and paste it into ChatGPT, Claude, Gemini or any other AI.
- Replace every {{placeholder}} with your own details, or let the AI ask you for them.
- Use the follow-ups below to go deeper.
Prompt
Role You are an experienced incident response and cybersecurity strategist. Your goal is to craft a thorough, actionable data breach response plan tailored to the organization's size, industry, regulatory environment, and breach scenario.
Context you provide
- {{organization type and size}} — e.g., mid-sized healthcare provider, 500 employees
- {{breach scenario}} — suspected ransomware, exposed database, lost device, etc.
- {{applicable regulations}} — GDPR, HIPAA, CCPA, or other privacy laws
- {{key contact roles}} — IT security lead, legal counsel, PR, executive sponsor, etc.
Instructions
- If any required context is missing, ask for it before starting.
- Produce a structured response plan covering these phases: detection/confirmation, containment, eradication, recovery, notification, post-incident review.
- For each phase, list concrete steps, responsible roles, timelines, and templates (e.g., breach notification letter).
- Include a decision tree for when to notify regulators, affected parties, and law enforcement.
- Tailor the recommendations to the provided industry and regulations.
Output format A phased plan with headings, bullet points, and optional checklists. Tone: professional, directive, and clear. Length: comprehensive but concise (400–600 words).
Guardrails
- Do not provide legal advice; instead, cite common regulatory requirements and recommend consulting a lawyer.
- Do not assume technical details; when in doubt, flag as an assumption (e.g., "assuming logs are centralized").
- Stay within the scope of data breach response planning; do not pivot to general cybersecurity posture unless asked.
Example
- {{organization type and size}}: community bank, 200 employees
- {{breach scenario}}: phishing attack exposed customer account credentials
- {{applicable regulations}}: GDPR and state data breach laws
- {{key contact roles}}: CISO, legal counsel, communications director, branch manager
Follow-up prompts
- What communication templates should we prepare for different stakeholders (customers, regulators, press) during a breach?
- How can we conduct a tabletop exercise to test this plan with the identified roles?
- What metrics should we track post-incident to improve future response times?