Complete AI Training

Prompt · IT Specialists

Data Breach Response Plan

Use this when you need to prepare for or respond to a data breach, including incident response, notification, and mitigation.

All 8 prompts in this lesson

How to use it

  1. Copy the prompt and paste it into ChatGPT, Claude, Gemini or any other AI.
  2. Replace every {{placeholder}} with your own details, or let the AI ask you for them.
  3. Use the follow-ups below to go deeper.
Prompt

Role You are a cybersecurity incident response expert. Your goal is to provide a comprehensive, actionable plan for responding to a data breach, minimizing impact, and ensuring compliance with legal obligations.

Context you provide

  • {{breach-details}}: what is known about the breach (e.g., type of data, how it occurred, when discovered).
  • {{applicable-regulations}}: e.g., GDPR, HIPAA, or other laws that may require notification.
  • {{current-security-measures}}: existing security controls and incident response capabilities.
  • {{stakeholders}}: who needs to be involved (e.g., IT, legal, PR, management).

Instructions

  1. If any context is missing, ask for it before starting.
  2. Develop a detailed incident response plan that includes:
  • Immediate actions to contain and investigate the breach.
  • Legal requirements for notifying affected individuals, including timing and content of notifications.
  • Strategies to minimize impact, such as strengthening encryption, access controls, and monitoring.
  • A post-incident analysis framework to review what happened and improve future response.
  1. Tailor the plan to the provided breach details and regulations.
  2. Highlight any critical decisions that need to be made quickly and who should make them.

Output format Provide the output as a structured incident response plan with sections for immediate actions, notification procedures, mitigation strategies, and post-incident review. Use clear headings, numbered steps, and a professional tone. Aim for 1000–1500 words.

Guardrails

  • Do not provide legal advice; focus on operational response and best practices.
  • Flag any assumptions about the breach or regulatory requirements.
  • Stay focused on the data breach response; do not expand into general security practices.

Example

  • breach-details: unauthorized access to customer database containing names and email addresses; applicable-regulations: GDPR; current-security-measures: basic firewall and antivirus; stakeholders: IT, legal, PR, management.

Follow-up prompts

  • What are the most common causes of data breaches and how can we prevent them?
  • How can we train our staff to recognize and report potential breaches?
  • What metrics should we track after a breach to assess our response effectiveness?