Complete AI Training

Prompt · Chief Digital Officers (CDOs)

Data Breach Response Plan

Use this when you need to develop a comprehensive, step-by-step response plan for handling a data breach, from detection through notification and post-incident review.

All 24 prompts in this lesson

How to use it

  1. Copy the prompt and paste it into ChatGPT, Claude, Gemini or any other AI.
  2. Replace every {{placeholder}} with your own details, or let the AI ask you for them.
  3. Use the follow-ups below to go deeper.
Prompt

Role You are an experienced incident response and cybersecurity strategist. Your goal is to craft a thorough, actionable data breach response plan tailored to the organization's size, industry, regulatory environment, and breach scenario.

Context you provide

  • {{organization type and size}} — e.g., mid-sized healthcare provider, 500 employees
  • {{breach scenario}} — suspected ransomware, exposed database, lost device, etc.
  • {{applicable regulations}} — GDPR, HIPAA, CCPA, or other privacy laws
  • {{key contact roles}} — IT security lead, legal counsel, PR, executive sponsor, etc.

Instructions

  1. If any required context is missing, ask for it before starting.
  2. Produce a structured response plan covering these phases: detection/confirmation, containment, eradication, recovery, notification, post-incident review.
  3. For each phase, list concrete steps, responsible roles, timelines, and templates (e.g., breach notification letter).
  4. Include a decision tree for when to notify regulators, affected parties, and law enforcement.
  5. Tailor the recommendations to the provided industry and regulations.

Output format A phased plan with headings, bullet points, and optional checklists. Tone: professional, directive, and clear. Length: comprehensive but concise (400–600 words).

Guardrails

  • Do not provide legal advice; instead, cite common regulatory requirements and recommend consulting a lawyer.
  • Do not assume technical details; when in doubt, flag as an assumption (e.g., "assuming logs are centralized").
  • Stay within the scope of data breach response planning; do not pivot to general cybersecurity posture unless asked.

Example

  • {{organization type and size}}: community bank, 200 employees
  • {{breach scenario}}: phishing attack exposed customer account credentials
  • {{applicable regulations}}: GDPR and state data breach laws
  • {{key contact roles}}: CISO, legal counsel, communications director, branch manager

Follow-up prompts

  • What communication templates should we prepare for different stakeholders (customers, regulators, press) during a breach?
  • How can we conduct a tabletop exercise to test this plan with the identified roles?
  • What metrics should we track post-incident to improve future response times?