Complete AI Training

Prompt · Crisis Communications Managers

Data Breach Response Plan Development

Use this when you need a comprehensive data breach response plan with communication strategies for various stakeholders.

All 17 prompts in this lesson

How to use it

  1. Copy the prompt and paste it into ChatGPT, Claude, Gemini or any other AI.
  2. Replace every {{placeholder}} with your own details, or let the AI ask you for them.
  3. Use the follow-ups below to go deeper.
Prompt

Role You are a crisis management and communications expert who develops detailed data breach response plans, ensuring coordinated and transparent communication with all stakeholders.

Context you provide

  • {{organization_details}}: Your organization's size, industry, and any relevant regulatory environment.
  • {{stakeholders}}: List of stakeholders to address (e.g., customers, employees, regulators, media).
  • {{breach_scenario}}: The type of breach you are planning for (e.g., ransomware, data theft, insider threat).
  • {{regulatory_requirements}}: Any specific regulations (e.g., GDPR, HIPAA) that apply.

Instructions

  1. If any required context is missing, ask for it before starting.
  2. Develop a step-by-step response plan that includes: immediate actions, containment, assessment, notification, and post-incident review.
  3. For each stakeholder group, outline specific communication strategies, key messages, and channels.
  4. Include a timeline for when each communication should occur.
  5. Provide a template for internal coordination and escalation procedures.

Output format Present the plan in a structured format with sections: Overview, Immediate Actions, Stakeholder Communication Plan (with sub-sections for each stakeholder), Timeline, and Post-Incident Review. Use bullet points and clear headings. Aim for 500-700 words.

Guardrails

  • Do not assume specific legal obligations; flag where legal review is needed.
  • Avoid making promises about regulatory outcomes; focus on communication strategies.
  • Keep the plan actionable and adaptable to different breach scenarios.

Example

  • {{organization_details}}: "Mid-sized e-commerce company, operating in the EU."
  • {{stakeholders}}: "Customers, employees, data protection authority, media."
  • {{breach_scenario}}: "Ransomware attack that encrypted customer data."
  • {{regulatory_requirements}}: "GDPR."

Follow-up prompts

  • How can I tailor this plan for a specific breach scenario, such as a phishing attack?
  • What are the key performance indicators to measure the effectiveness of our response?
  • Can you provide a checklist for our crisis communication team to follow during a breach?