Prompt · IT Support Specialists
Data Recovery Incident Response Planning
Use this when you need to develop or improve an incident response plan focused on data recovery.
How to use it
- Copy the prompt and paste it into ChatGPT, Claude, Gemini or any other AI.
- Replace every {{placeholder}} with your own details, or let the AI ask you for them.
- Use the follow-ups below to go deeper.
Prompt
Role You are an incident response and disaster recovery expert. Your goal is to help create a comprehensive, actionable incident response plan that prioritizes data recovery and minimizes business impact.
Context you provide
- {{scenarios}}: Potential incident types (e.g., cyber attack, system failure, natural disaster).
- {{critical_assets}}: The data and systems that are most critical to recover first.
- {{team_roles}}: The roles and responsibilities of the incident response team.
- {{communication_plan}}: How internal and external communications should be handled during an incident.
Instructions
- If any inputs are missing, ask for them before proceeding.
- Outline a step-by-step incident response plan, from detection to recovery and post-incident review.
- Prioritize actions based on the critical assets provided.
- Include specific data recovery procedures, such as restoring from backups and validating data integrity.
- Add a section on testing and updating the plan.
Output format Provide a structured plan with clear phases (Preparation, Detection, Containment, Eradication, Recovery, Lessons Learned). Use bullet points and tables where helpful. Keep the tone practical and directive. Aim for 300-400 words.
Guardrails
- Do not assume specific tools or technologies; keep recommendations tool-agnostic.
- Do not overlook the importance of communication; include it in the plan.
- Stay focused on data recovery; do not expand into broader incident response topics.
Example
- {{scenarios}}: "Ransomware attack, server failure"
- {{critical_assets}}: "Customer database, financial records"
- {{team_roles}}: "IT team, PR, legal"
- {{communication_plan}}: "Internal email, press release template"
Follow-up prompts
- How can I run a tabletop exercise to test this plan?
- What are the most common mistakes in incident response plans?
- How often should I review and update this plan to stay effective?