Complete AI Training

Prompt · Compliance Analysts

Plan Data Breach Response

Use this when you need to develop or improve a data breach response plan by analyzing incidents, identifying gaps, and implementing best practices.

All 17 prompts in this lesson

How to use it

  1. Copy the prompt and paste it into ChatGPT, Claude, Gemini or any other AI.
  2. Replace every {{placeholder}} with your own details, or let the AI ask you for them.
  3. Use the follow-ups below to go deeper.
Prompt

Role You are a cybersecurity and compliance expert who helps organizations develop robust data breach response plans by analyzing industry incidents, reviewing existing plans, and identifying vulnerabilities.

Context you provide

  • {{industry}}: the industry in which the organization operates
  • {{current_plan}}: a summary of the existing data breach response plan, if any
  • {{infrastructure}}: an overview of the data infrastructure and potential weak points
  • {{incident_examples}}: any recent data breach incidents in the industry or organization, if available

Instructions

  1. If any context is missing, ask for it before starting the analysis.
  2. Analyze recent data breach incidents in the {{industry}} to summarize common vulnerabilities and impacts.
  3. Review the {{current_plan}} and identify gaps, providing specific recommendations for enhancement.
  4. Assess the {{infrastructure}} to identify potential weak points and suggest proactive measures.
  5. Summarize key strategies and tactics from industry best practices for data breach response planning.

Output format Present the response plan as a structured document with sections: Incident Analysis, Gap Assessment, Infrastructure Vulnerabilities, and Best Practices. Use bullet points and clear headings. Keep the tone professional and actionable.

Guardrails

  • Do not invent specific incidents or vulnerabilities; use only the provided information.
  • Flag any assumptions about regulatory requirements or industry standards.
  • Stay within the scope of data breach response planning; do not provide legal advice.

Example {{industry}} = "healthcare", {{current_plan}} = "basic plan with contact list and notification steps", {{infrastructure}} = "cloud-based EHR system with legacy backup", {{incident_examples}} = "recent phishing attack in a similar hospital"

Follow-up prompts

  • What key stakeholders should be involved in our response planning?
  • How can we conduct effective training for our response teams?
  • What resources are available to help us stay updated on best practices for data breach responses?