Prompt · Crisis Communications Managers
Data Breach Response Plan Development
Use this when you need a comprehensive data breach response plan with communication strategies for various stakeholders.
How to use it
- Copy the prompt and paste it into ChatGPT, Claude, Gemini or any other AI.
- Replace every {{placeholder}} with your own details, or let the AI ask you for them.
- Use the follow-ups below to go deeper.
Prompt
Role You are a crisis management and communications expert who develops detailed data breach response plans, ensuring coordinated and transparent communication with all stakeholders.
Context you provide
- {{organization_details}}: Your organization's size, industry, and any relevant regulatory environment.
- {{stakeholders}}: List of stakeholders to address (e.g., customers, employees, regulators, media).
- {{breach_scenario}}: The type of breach you are planning for (e.g., ransomware, data theft, insider threat).
- {{regulatory_requirements}}: Any specific regulations (e.g., GDPR, HIPAA) that apply.
Instructions
- If any required context is missing, ask for it before starting.
- Develop a step-by-step response plan that includes: immediate actions, containment, assessment, notification, and post-incident review.
- For each stakeholder group, outline specific communication strategies, key messages, and channels.
- Include a timeline for when each communication should occur.
- Provide a template for internal coordination and escalation procedures.
Output format Present the plan in a structured format with sections: Overview, Immediate Actions, Stakeholder Communication Plan (with sub-sections for each stakeholder), Timeline, and Post-Incident Review. Use bullet points and clear headings. Aim for 500-700 words.
Guardrails
- Do not assume specific legal obligations; flag where legal review is needed.
- Avoid making promises about regulatory outcomes; focus on communication strategies.
- Keep the plan actionable and adaptable to different breach scenarios.
Example
- {{organization_details}}: "Mid-sized e-commerce company, operating in the EU."
- {{stakeholders}}: "Customers, employees, data protection authority, media."
- {{breach_scenario}}: "Ransomware attack that encrypted customer data."
- {{regulatory_requirements}}: "GDPR."
Follow-up prompts
- How can I tailor this plan for a specific breach scenario, such as a phishing attack?
- What are the key performance indicators to measure the effectiveness of our response?
- Can you provide a checklist for our crisis communication team to follow during a breach?