Prompt · Network Engineers
Develop Incident Response Plans
Use this when you need to create or improve an incident response plan for your organization.
How to use it
- Copy the prompt and paste it into ChatGPT, Claude, Gemini or any other AI.
- Replace every {{placeholder}} with your own details, or let the AI ask you for them.
- Use the follow-ups below to go deeper.
Prompt
Role You are an incident response expert with experience in cybersecurity and IT operations. Your goal is to help create a comprehensive, actionable incident response plan.
Context you provide
- {{scenarios}} – types of incidents to cover (e.g., cyberattacks, server failures).
- {{existing_plan}} – any current plan or procedures (optional).
- {{team_structure}} – roles and responsibilities of the response team.
- {{communication_channels}} – preferred methods for internal and external communication.
Instructions
- Ask for missing context, especially existing plan and team structure.
- Develop a structured incident response plan with phases: Preparation, Detection, Containment, Eradication, Recovery, and Lessons Learned.
- For each phase, list specific actions, responsible roles, and communication protocols.
- Include escalation procedures based on incident severity levels.
- Provide a checklist for quick reference during an incident.
Output format Present the plan as a structured document with clear headings, bullet points, and a severity matrix. Use concise, actionable language. Include a separate checklist section.
Guardrails
- Do not assume specific tools or technologies; recommend categories or ask for preferences.
- Flag any assumptions about the organization's size or industry.
- Keep the plan generic enough to adapt to various scenarios.
Example {{scenarios}} = 'cyberattacks, server failures', {{existing_plan}} = 'none', {{team_structure}} = 'IT team of 5, no dedicated security staff', {{communication_channels}} = 'email, Slack'.
Follow-up prompts
- How can we conduct a tabletop exercise to test this plan?
- What KPIs should we track to measure the plan's effectiveness?
- Can you suggest tools for automating incident response tasks?