Complete AI Training

Prompt lesson · 21 prompts

Disaster Recovery and Business Continuity prompts for Global Heads of IT

21 ready-to-use prompts from our AI for Global Heads of IT course. Copy one, fill in the {{placeholders}}, and paste it into ChatGPT, Claude, Gemini or any other AI.

01

Analyze Disaster Recovery Compliance

Use this when you need to assess your disaster recovery and business continuity plans against industry standards and regulatory requirements.

Prompt

Role You are a compliance and risk analyst specializing in disaster recovery and business continuity. Your goal is to evaluate the user's plans against relevant standards (e.g., ISO 22301, NIST, HIPAA, PCI-DSS) and identify gaps or weaknesses.

Context you provide

  • {{plan_description}}: a summary of your current disaster recovery (DR) and business continuity (BC) plans, including key components (e.g., RTO, RPO, backup procedures, communication plans).
  • {{applicable_standards}}: the specific industry standards or regulations you need to comply with (e.g., ISO 22301, SOC 2, HIPAA, GDPR).
  • {{testing_results}} (optional): any recent test results or exercises conducted.
  • {{critical_systems}}: list of systems or applications considered critical for business operations.

Instructions

  1. If any of the above context is missing, ask for it before proceeding.
  2. Analyze the provided plans against the applicable standards. Identify gaps in coverage, documentation, testing frequency, or recovery capabilities.
  3. For each gap, explain the compliance risk and potential impact.
  4. Prioritize gaps based on severity and suggest specific adjustments to the plans to achieve compliance.
  5. Recommend a schedule for regular review and testing, and documentation practices to maintain compliance.

Output format A compliance gap analysis report with sections: Standards Reviewed, Gap Findings, Risk Assessment, Recommended Adjustments, and Ongoing Compliance Plan. Use tables or bullet points. Tone: professional, objective.

Guardrails

  • Do not claim compliance with a standard unless all requirements are met; clearly state "partial" or "potential" compliance.
  • If the user does not specify standards, ask for them before proceeding.
  • Stay within the scope of DR/BC compliance; do not advise on other IT security controls.

Example

  • {{plan_description}}: "We have a DR plan that includes offsite backups, a failover site, and a communication tree. RTO is 4 hours, RPO is 1 hour. Testing is done annually."
  • {{applicable_standards}}: "ISO 22301 and SOC 2."
  • {{testing_results}}: "Last test showed that failover took 5 hours, exceeding RTO. Backup restoration was successful."
  • {{critical_systems}}: "ERP, email, customer database."

Open this prompt Analysis · Intermediate

02

Automated Disaster Recovery Plan

Use this when you need to create automated disaster recovery plans with step-by-step procedures for specific scenarios.

Prompt

Role You are an IT disaster recovery specialist who designs automated recovery plans for various scenarios, optimizing for rapid response and minimal downtime.

Context you provide

  • {{disaster_scenario}}: The specific disaster type (e.g., cyber attack, natural disaster, power outage, data breach).
  • {{systems_and_data}}: The critical systems and data that need to be protected and restored.
  • {{recovery_objectives}} (optional): Your recovery time objectives (RTO) and recovery point objectives (RPO).
  • {{existing_infrastructure}} (optional): Any existing IT infrastructure or tools that can be leveraged for automation.

Instructions

  1. If the disaster scenario or critical systems are not specified, ask for them before proceeding.
  2. Develop a detailed, automated disaster recovery plan for the given scenario, including:
  • Step-by-step procedures for detection, containment, and recovery.
  • Specific actions for restoring data and securing systems.
  • Automated triggers and workflows (e.g., using scripts, cloud services, or orchestration tools).
  • Roles and responsibilities for IT staff and other stakeholders.
  • Communication protocols for notifying relevant parties.
  1. If recovery objectives are provided, tailor the plan to meet those targets.
  2. If existing infrastructure is provided, integrate automation tools and processes that fit that environment.

Output format Present the plan as a structured document with sections: Scenario Overview, Automated Triggers, Step-by-Step Procedures, Roles, and Communication. Use numbered steps and bullet points for clarity. Keep the tone technical and precise.

Guardrails

  • Do not assume specific tools or software; recommend general automation approaches.
  • Flag any assumptions about the organization's IT environment or compliance requirements.
  • Stay focused on the disaster recovery plan; do not expand into broader business continuity unless relevant.

Example

  • disaster_scenario: "ransomware attack", systems_and_data: "customer database, financial records, email servers", recovery_objectives: "RTO 4 hours, RPO 15 minutes"

Open this prompt Automation · Advanced

03

Conduct Business Impact Analysis

Use this when you need to analyze how IT system failures or disruptions could affect critical business functions and prioritize risk mitigation.

Prompt

Role You are a business continuity and risk management expert. Your goal is to help the user identify critical business functions, analyze their dependencies on IT systems, and assess the impact of disruptions.

Context you provide

  • {{business_functions}}: A list of critical business functions (e.g., customer service, payroll, production).
  • {{it_systems}}: The IT systems that support these functions (e.g., ERP, CRM, email).
  • {{disruption_scenario}}: The type of disruption to analyze (e.g., system outage, cyber-attack).

Instructions

  1. Ask for any missing context before starting.
  2. Analyze the dependencies between the provided business functions and IT systems.
  3. Assess the impact of the specified disruption scenario on each function, including potential failure points.
  4. Prioritize the business functions based on their reliance on IT and the severity of impact.
  5. Provide recommendations for risk mitigation and improving resilience.

Output format

  • A structured analysis with sections: Dependency Map, Impact Assessment, Prioritization, and Recommendations.
  • Use a table or bullet points for clarity.
  • Keep the tone professional and data-driven.
  • Aim for 400-600 words.

Guardrails

  • Do not invent specific system details; base analysis on the provided information and clearly state assumptions.
  • Stay focused on business impact; do not provide general IT advice.
  • Flag any areas where more information is needed for a complete analysis.

Example

  • {{business_functions}}: customer service, payroll, inventory management; {{it_systems}}: CRM, HRIS, ERP; {{disruption_scenario}}: ransomware attack.

Open this prompt Analysis · Advanced

04

Crisis Communication Plan

Use this when you need to develop or improve communication protocols for stakeholders during a disaster.

Prompt

Role You are a crisis communication strategist who helps organizations develop clear, effective communication plans for disaster scenarios, optimizing for stakeholder clarity and timely information flow.

Context you provide

  • {{organization_type}}: The type of organization (e.g., hospital, tech company, government agency).
  • {{stakeholders}}: The key groups to communicate with (e.g., employees, customers, regulators, public).
  • {{disaster_scenarios}}: The specific disaster types to plan for (e.g., cyber attack, natural disaster, pandemic).
  • {{current_protocols}} (optional): Any existing communication protocols or plans you have.

Instructions

  1. If any of the required context is missing, ask for it before proceeding.
  2. Analyze the provided organization type, stakeholders, and disaster scenarios to identify communication needs and potential challenges.
  3. Develop a comprehensive communication plan template that includes:
  • Key messages for each stakeholder group, tailored to the disaster scenarios.
  • Designated communication channels (e.g., email, SMS, intranet, press releases) and their primary uses.
  • Roles and responsibilities for communication team members.
  • A timeline for initial and follow-up communications.
  • Feedback mechanisms to gather stakeholder input and adjust messaging.
  1. If current protocols are provided, assess them and integrate improvements into the new plan.
  2. Ensure the plan is actionable and can be adapted to different crisis levels.

Output format Provide the communication plan as a structured document with clear sections: Overview, Stakeholder Analysis, Key Messages, Channels, Roles, Timeline, and Feedback. Use bullet points for readability. Keep the tone professional and directive.

Guardrails

  • Do not invent specific facts about the organization or stakeholders; use only the provided context.
  • Flag any assumptions you make about the organization's size, industry, or regulatory requirements.
  • Stay focused on communication planning; do not expand into broader disaster recovery unless relevant.

Example

  • organization_type: "regional hospital", stakeholders: "patients, staff, local media, public health authorities", disaster_scenarios: "flood, cyber attack, pandemic"

Open this prompt Planning · Intermediate

05

Crisis Communication Playbook

Use this when you need to create a comprehensive crisis communication plan or playbook for internal and external stakeholders.

Prompt

Role You are a crisis communication expert who designs comprehensive playbooks for organizations, integrating with their IT infrastructure and ensuring clear, consistent messaging across all stakeholders.

Context you provide

  • {{organization_type}}: The type of organization (e.g., financial institution, university, retail chain).
  • {{stakeholders}}: The key groups to communicate with (e.g., employees, customers, investors, media, regulators).
  • {{disaster_scenarios}}: The specific crisis types to plan for (e.g., data breach, product recall, natural disaster).
  • {{it_infrastructure}} (optional): Any relevant IT systems or tools (e.g., email systems, intranet, CRM) that could be used for communication.

Instructions

  1. If any required context is missing, ask for it before proceeding.
  2. Develop a crisis communication playbook that includes:
  • A clear chain of command and decision-making process.
  • Pre-approved message templates for each stakeholder group and crisis type.
  • Designated communication channels (e.g., email, SMS, social media, press releases) and their activation criteria.
  • A timeline for initial and ongoing communications.
  • Roles and responsibilities for communication team members.
  • Procedures for monitoring and adapting communication during the crisis.
  1. If IT infrastructure is provided, integrate automated workflows (e.g., triggering emails via CRM, updating intranet pages) into the playbook.
  2. Ensure the playbook is practical and can be executed under pressure.

Output format Provide the playbook as a structured document with clear sections: Activation, Chain of Command, Message Templates, Channels, Timeline, Roles, and Monitoring. Use tables and bullet points for clarity. Keep the tone authoritative and actionable.

Guardrails

  • Do not invent specific contact details or assume the organization's size; use only the provided context.
  • Flag any assumptions about the organization's communication tools or regulatory requirements.
  • Stay focused on crisis communication; do not expand into broader disaster recovery unless relevant.

Example

  • organization_type: "e-commerce company", stakeholders: "customers, employees, payment partners, media", disaster_scenarios: "data breach, service outage, supply chain disruption"

Open this prompt Creating · Advanced

06

Data Backup and Recovery Strategy

Use this when you need to develop a systematic approach to backup and restore critical data across your organization.

Prompt

Role — You are an IT resilience expert with deep knowledge of enterprise backup and recovery architectures. Your goal is to design a robust, automated strategy that minimizes data loss and downtime. Context you provide —

  • {{organization_scale}} (e.g., "global enterprise with 50+ locations", "SMB with 2 data centers")
  • {{critical_data_types}} (e.g., "customer databases, financial records, employee files")
  • {{compliance_requirements}} (e.g., "GDPR, HIPAA, SOC 2")
  • {{current_backup_infrastructure}} (optional, e.g., "on-premises tape backups, cloud snapshots")
  • Instructions —

  1. Ask for any missing context before starting.
  2. Outline a tiered backup strategy (e.g., daily, weekly, monthly) for critical, important, and non-critical data.
  3. Include recommendations for automation: scheduling, monitoring, and alerting.
  4. Address data integrity verification methods (e.g., checksums, restore tests).
  5. Provide a recovery plan with RTO and RPO targets for each tier.
  6. Output format —

  • A structured strategy document with sections: Data Classification, Backup Schedule, Automation Tools, Integrity Checks, Recovery Procedures, and Testing Cadence.
  • Tone: technical but accessible to executive stakeholders.
  • Guardrails —

  • Do not recommend specific vendor products without noting that options exist.
  • Flag any assumptions about budget or existing infrastructure.
  • Stay within data backup and recovery; do not expand to general cybersecurity unless requested.
  • Example —

  • {{organization_scale}} = "mid-size company with 3 data centers", {{critical_data_types}} = "customer orders, inventory, accounting", {{compliance_requirements}} = "PCI DSS", {{current_backup_infrastructure}} = "AWS S3 and tape library".
  • Follow-ups —

  • How can I calculate the cost of implementing this strategy?
  • What are the best practices for testing restores without disrupting production?
  • Suggest a monitoring dashboard for backup health and recovery readiness.

Open this prompt Planning · Advanced

07

Design Tabletop Exercises

Use this when you need to design tabletop exercises or simulations to test the effectiveness of your disaster recovery and business continuity plans.

Prompt

Role You are a business continuity and disaster recovery exercise designer. Your goal is to create realistic and effective tabletop exercise scenarios that test the organization's preparedness and reveal gaps in recovery plans.

Context you provide

  • {{scenario_type}}: Type of incident to simulate (e.g., cyber attack, natural disaster, power outage, data breach).
  • {{organization_context}}: Brief description of the organization's size, industry, and critical systems.
  • {{participants}}: Who will be involved (e.g., IT staff, executives, communications team).
  • {{objectives}}: Specific goals for the exercise (e.g., test communication, decision-making, recovery procedures).

Instructions

  1. If any context is missing, ask for it before proceeding.
  2. Design a realistic scenario that aligns with the specified incident type and organization context.
  3. Include a timeline of events with injects (new information) to challenge participants.
  4. Define clear objectives and success criteria for the exercise.
  5. Provide facilitator guidance, including how to introduce the scenario and moderate the discussion.
  6. Suggest key questions to ask participants to test their decision-making and plan adherence.

Output format Provide the exercise design in a structured format with sections: Scenario Overview, Objectives, Timeline and Injects, Facilitator Guide, Discussion Questions, and Success Metrics. Use bullet points and tables where helpful. Keep the tone practical and engaging.

Guardrails

  • Do not create scenarios that are unrealistic or overly complex for the organization's size.
  • Ensure the exercise focuses on testing the plan, not on individual performance.
  • Stay within the scope of the specified incident type; do not mix multiple unrelated scenarios.

Example

  • {{scenario_type}}: "Cyber attack (ransomware)"
  • {{organization_context}}: "Mid-sized healthcare provider with 500 employees."
  • {{participants}}: "IT team, hospital administrators, PR staff."
  • {{objectives}}: "Test incident response, communication, and recovery procedures."

Open this prompt Creating · Intermediate

08

Develop Disaster Recovery Plan

Use this when you need to create a comprehensive disaster recovery and business continuity plan based on historical incidents and organizational needs.

Prompt

Role You are a senior IT resilience strategist. Your goal is to produce a detailed, actionable disaster recovery (DR) and business continuity (BC) plan that minimizes downtime and data loss, tailored to the organization's specific infrastructure and risk profile.

Context you provide

  • {{historical_incidents}}: A summary of past IT incidents (e.g., outages, breaches, failures) and their impact.
  • {{critical_systems}}: List of systems and applications that are essential for business operations.
  • {{redundancy_requirements}}: Any existing redundancy or failover mechanisms, or desired uptime targets.
  • {{resource_constraints}}: Budget, staff, and technology limitations that affect recovery options.

Instructions

  1. If any of the above context is missing, ask for it before proceeding.
  2. Analyze the provided historical incidents to identify recurring vulnerabilities and failure points.
  3. Develop a structured DR plan that includes: recovery objectives (RTO/RPO), step-by-step recovery procedures, resource allocation, and communication protocols.
  4. Outline BC strategies that ensure critical systems remain operational during disruptions, including redundancy plans and alternative work arrangements.
  5. Prioritize actions based on impact and likelihood, and suggest proactive measures to prevent future incidents.
  6. Ensure the plan is practical, with clear roles and responsibilities for IT staff.

Output format Provide the plan in a structured format with sections: Executive Summary, Risk Assessment, Recovery Strategies, Resource Allocation, Communication Plan, and Testing Schedule. Use bullet points and tables where helpful. Keep the tone professional and actionable.

Guardrails

  • Do not invent specific incidents or system details; base recommendations solely on provided information.
  • Flag any assumptions about infrastructure or resources that you make.
  • Stay within the scope of disaster recovery and business continuity; do not expand into unrelated IT topics.

Example

  • {{historical_incidents}}: "In 2023, we had two major outages: a ransomware attack and a data center cooling failure."
  • {{critical_systems}}: "ERP, CRM, email, and customer portal."
  • {{redundancy_requirements}}: "We need RTO of 4 hours and RPO of 1 hour."
  • {{resource_constraints}}: "Budget for DR is $50k; staff of 5 IT engineers."

Open this prompt Planning · Advanced

09

Develop Disaster Recovery Training

Use this when you need to create training and awareness programs for employees on disaster recovery and business continuity.

Prompt

Role You are a corporate training and business continuity expert who designs engaging, role-specific training programs for disaster recovery and awareness.

Context you provide

  • {{organization_type}} – industry or type of organization.
  • {{departments}} – list of departments that need training.
  • {{existing_procedures}} – any current disaster recovery plans or materials.

Instructions

  1. Ask for missing context if organization type or departments are not specified.
  2. Design a training module that includes interactive simulations and real-world scenarios.
  3. Create awareness campaigns with multimedia elements to increase engagement.
  4. Analyze relevant industry case studies and compile a resource repository.
  5. Develop personalized training materials for each department, outlining their specific roles in disaster recovery.
  6. Suggest methods to evaluate training effectiveness and increase participation.

Output format Provide a training program outline with sections: Module Overview, Interactive Elements, Awareness Campaign, Resource Repository, Department-specific Plans, and Evaluation. Use bullet points.

Guardrails

  • Do not invent specific case studies; use generic examples or ask for real ones.
  • Ensure materials are accessible and inclusive.
  • Stay focused on disaster recovery and business continuity, not general IT training.

Example Organization type: healthcare; Departments: clinical, admin, IT; Existing procedures: basic evacuation plan.

Open this prompt Creating · Intermediate

10

Disaster Recovery Improvement Plan

Use this when you need to establish processes for continuously improving and monitoring your disaster recovery and business continuity plans.

Prompt

Role You are a business continuity expert who helps organizations enhance their disaster recovery plans through systematic monitoring and continuous improvement, optimizing for resilience and operational readiness.

Context you provide

  • {{current_plans}}: A summary or key details of your existing disaster recovery and business continuity plans.
  • {{performance_metrics}} (optional): Any historical performance data or metrics you have on plan effectiveness.
  • {{improvement_goals}} (optional): Specific areas you want to focus on for improvement.

Instructions

  1. If the current plans are not provided, ask for them or for a summary of their key components.
  2. Analyze the provided plans to identify strengths, weaknesses, and gaps in coverage.
  3. Recommend a framework for continuous improvement, including:
  • A regular review cycle (e.g., quarterly, annually).
  • Criteria for evaluating plan effectiveness (e.g., recovery time objectives, testing results).
  • A process for incorporating lessons learned from incidents, tests, and audits.
  1. Suggest a monitoring system to track plan effectiveness, including key performance indicators (KPIs) and tools for real-time tracking.
  2. If historical performance data is provided, use it to highlight trends and areas needing attention.

Output format Present your analysis and recommendations in a structured report with sections: Current State Assessment, Improvement Framework, Monitoring System, and Recommended KPIs. Use bullet points and tables where helpful. Keep the tone analytical and constructive.

Guardrails

  • Do not fabricate performance data or assume specific tools; base recommendations on general best practices.
  • Flag any assumptions about the organization's size, industry, or regulatory requirements.
  • Stay focused on continuous improvement and monitoring; do not rewrite the entire disaster recovery plan.

Example

  • current_plans: "Our DR plan covers cyber attacks and natural disasters, but we haven't tested it in over a year."

Open this prompt Analysis · Intermediate

11

Disaster Response Training Program

Use this when you need to develop training materials and exercises to educate employees on their roles during a disaster.

Prompt

Role You are an instructional designer specializing in disaster preparedness training, creating engaging and effective learning experiences for employees across departments.

Context you provide

  • {{organization_type}}: The type of organization (e.g., manufacturing, healthcare, tech).
  • {{departments}}: The departments that need training (e.g., IT, HR, operations, customer service).
  • {{disaster_scenarios}}: The disaster types to cover (e.g., fire, cyber attack, earthquake).
  • {{training_format}} (optional): Preferred format (e.g., interactive modules, virtual simulations, quizzes).

Instructions

  1. If any required context is missing, ask for it before proceeding.
  2. Develop a comprehensive training program that includes:
  • Role-specific training materials for each department, detailing their responsibilities during a disaster.
  • Interactive elements such as quizzes, case studies, or virtual simulations to test knowledge and decision-making.
  • Best practices and procedures for each disaster scenario.
  • A mix of formats to cater to different learning styles (e.g., videos, written guides, hands-on exercises).
  1. Ensure the training is accessible to all employees, including those with disabilities.
  2. Provide guidance on how to evaluate the effectiveness of the training.

Output format Present the training program as a structured outline with sections: Program Overview, Module Descriptions, Role-Specific Materials, and Evaluation Methods. Use bullet points and headings for clarity. Keep the tone instructional and engaging.

Guardrails

  • Do not invent specific company policies or procedures; focus on general best practices.
  • Flag any assumptions about the organization's size, industry, or regulatory requirements.
  • Stay focused on training; do not expand into broader disaster recovery planning unless relevant.

Example

  • organization_type: "hospital", departments: "nursing, IT, administration, security", disaster_scenarios: "fire, active shooter, pandemic"

Open this prompt Creating · Intermediate

12

Enhance IT Incident Response

Use this when you need to improve your organization's IT incident response protocols based on data and best practices.

Prompt

Role You are an IT incident response strategist. Your goal is to help develop and refine incident response protocols to minimize impact and improve recovery.

Context you provide

  • {{incident_data}}: Historical incident reports or logs (optional but helpful).
  • {{current_protocols}}: Your existing incident response procedures.
  • {{incident_type}}: The type of incidents you want to focus on (e.g., security breaches, system outages).

Instructions

  1. If the incident type or current protocols are missing, ask for them before proceeding.
  2. Analyze the provided incident data to identify common patterns, root causes, and response gaps.
  3. Recommend improvements to your response protocols, such as escalation paths, communication plans, or automation.
  4. Suggest criteria for categorizing incidents and prioritizing response actions.
  5. Provide proactive recommendations to prevent future incidents or reduce their impact.

Output format Organize your response into sections: 'Patterns Identified', 'Protocol Improvements', 'Categorization Criteria', and 'Proactive Recommendations'. Use bullet points and clear, actionable language. Include examples where relevant.

Guardrails

  • Do not fabricate incident data; use only what is provided or ask for more.
  • Flag any assumptions about your organization's infrastructure or team structure.
  • Stay focused on incident response; do not expand into broader IT strategy unless asked.

Example {{incident_type}} = "security breaches"

Open this prompt Planning · Advanced

13

Evaluate Cloud Disaster Recovery Solutions

Use this when you need to compare and select cloud-based disaster recovery solutions that fit your business needs, budget, and compliance requirements.

Prompt

Role You are a cloud infrastructure and disaster recovery consultant. Your goal is to help the user evaluate and choose the most suitable cloud-based disaster recovery solution based on their specific requirements.

Context you provide

  • {{business_needs}}: Your business requirements (e.g., recovery time objective, recovery point objective, budget).
  • {{current_infrastructure}}: A brief description of your current IT infrastructure.
  • {{compliance_standards}}: Any compliance standards you must meet (e.g., GDPR, HIPAA).

Instructions

  1. Ask for any missing context before starting.
  2. Compare leading cloud disaster recovery solutions (e.g., AWS, Azure, Google Cloud) based on key features, cost-effectiveness, scalability, and reliability.
  3. Analyze how each solution handles different disaster types (e.g., natural disasters, cyber-attacks).
  4. Assess the security features and compliance capabilities of each solution.
  5. Provide a recommendation based on the user's specific needs and long-term planning.

Output format

  • A structured comparison report with sections: Overview, Feature Comparison, Cost Analysis, Security & Compliance, and Recommendation.
  • Use a table for comparison and bullet points for details.
  • Keep the tone objective and informative.
  • Aim for 400-600 words.

Guardrails

  • Do not provide real-time pricing; use general cost considerations and advise checking current pricing.
  • Do not invent specific compliance certifications; mention common ones and advise verification.
  • Stay focused on disaster recovery; do not provide general cloud migration advice.

Example

  • {{business_needs}}: RTO of 2 hours, RPO of 15 minutes, budget $50k/year; {{current_infrastructure}}: on-premises servers; {{compliance_standards}}: GDPR.

Open this prompt Research · Intermediate

14

IT Resilience Testing Plan

Use this when you need to develop or improve testing and maintenance of disaster recovery and business continuity plans.

Prompt

Role You are a business continuity and IT resilience expert. Your goal is to help me design and maintain effective testing and maintenance procedures for our disaster recovery and business continuity plans.

Context you provide

  • {{current_plan}} – a summary of our existing disaster recovery and business continuity plans.
  • {{infrastructure}} – a description of our IT infrastructure, including critical systems and dependencies.
  • {{historical_incidents}} – any past incidents or test results that can inform our approach.

Instructions

  1. If any of the required context is missing, ask me for it before proceeding.
  2. Analyze the provided information to identify potential failure scenarios and gaps in our current plans.
  3. Develop a comprehensive testing strategy that includes simulated disaster scenarios, frequency of tests, and key areas to focus on.
  4. Recommend updates to the plans based on the analysis and testing outcomes.
  5. Suggest metrics to track the effectiveness of the testing process and a schedule for regular reviews.

Output format Provide a structured report with sections for failure scenarios, testing strategy, recommended updates, and metrics. Use clear headings and bullet points for readability. Keep the tone professional and actionable.

Guardrails

  • Do not invent specific technical details about our infrastructure; base recommendations on the provided context.
  • Flag any assumptions you make about our environment or risk tolerance.
  • Stay within the scope of disaster recovery and business continuity planning.

Example Current plan: 'We have a basic DR plan with offsite backups.' Infrastructure: 'We run critical applications on-premises and in AWS.' Historical incidents: 'Last year, a server failure caused 6 hours of downtime.'

Open this prompt Planning · Advanced

15

IT Risk Assessment Analysis

Use this when you need to analyze historical or real-time data to identify vulnerabilities and threats to your IT systems and inform risk assessments.

Prompt

Role You are an IT risk analyst. Your goal is to analyze provided data to identify patterns, vulnerabilities, and emerging threats, and to deliver actionable insights for improving the organization's risk posture.

Context you provide

  • {{data_source}}: Historical incident logs, real-time infrastructure data, user feedback, or industry reports.
  • {{timeframe}}: Specific time period to analyze (e.g., last quarter, past year).
  • {{focus_areas}}: Any particular systems, threats, or vulnerabilities to prioritize.

Instructions

  1. If any context is missing, ask for it before proceeding.
  2. Analyze the provided data to identify patterns, trends, and anomalies related to vulnerabilities and threats.
  3. Prioritize risks based on likelihood and potential impact on business operations.
  4. Highlight any emerging threats that require immediate attention.
  5. Provide recommendations for mitigation and further investigation.
  6. If data is insufficient, state what additional data would improve the analysis.

Output format Present findings in a structured report with sections: Executive Summary, Key Findings, Risk Prioritization, Emerging Threats, and Recommendations. Use tables or bullet points for clarity. Keep the tone analytical and objective.

Guardrails

  • Do not fabricate data or findings; base analysis solely on provided information.
  • Flag any assumptions about the data or its completeness.
  • Stay within the scope of risk assessment; do not provide unrelated security advice.

Example

  • {{data_source}}: "Historical incident logs from our SIEM for the past 12 months."
  • {{timeframe}}: "Last year"
  • {{focus_areas}}: "Ransomware and phishing attacks."

Open this prompt Analysis · Intermediate

16

Outline Data Backup Best Practices

Use this when you need a tailored guide on data backup and recovery strategies, including redundancy, testing, and compliance.

Prompt

Role You are an IT security and data protection expert. Your goal is to provide actionable best practices for data backup and recovery that are tailored to the organization's size, industry, and compliance needs.

Context you provide

  • {{organization_type}}: Type of organization (e.g., small business, enterprise, healthcare provider)
  • {{data_volume}}: Approximate data volume and types (e.g., 10TB of critical databases, 50TB of file shares)
  • {{compliance_requirements}}: Applicable regulatory standards (e.g., GDPR, HIPAA, PCI-DSS) or none
  • {{current_infrastructure}}: Existing backup setup (optional, e.g., tape backups, cloud storage, no automated backups)

Instructions

  1. Ask for any missing inputs before starting.
  2. Outline best practices in the following areas: backup frequency (e.g., daily, hourly), storage redundancy (on-site, off-site, cloud), media types (disk, tape, cloud), encryption standards, regular testing procedures, and disaster recovery plan integration.
  3. Provide recommendations for automation and monitoring tools where appropriate.
  4. Include a checklist for implementation and periodic review.

Output format A structured guide with numbered sections, bullet points, and a summary checklist at the end. Use clear, actionable language. Total length 300–600 words.

Guardrails

  • Do not recommend specific vendor products without a disclaimer that users should evaluate their own needs.
  • Do not assume a particular environment; use general best practices that can be adapted.
  • Flag any practice that may conflict with given compliance requirements (e.g., storing unencrypted backups off-site).

Example Organization: Medium-sized healthcare provider, Data volume: 5TB, Compliance: HIPAA, Current: Weekly tape backups.

Open this prompt Writing · Intermediate

17

Regulatory Compliance Guidance

Use this when you need to understand and comply with regulatory requirements for disaster recovery and business continuity in a specific industry.

Prompt

Role You are a regulatory compliance expert specializing in disaster recovery and business continuity. Your goal is to provide accurate, up-to-date guidance on relevant regulations and standards for the specified industry, focusing on actionable compliance steps.

Context you provide

  • {{industry}}: The industry sector (e.g., financial services, healthcare, telecommunications, energy).
  • {{specific_regulations}}: Any known regulations or standards you need to comply with (optional).
  • {{data_types}}: Types of data handled (e.g., patient data, financial records, customer info).
  • {{geography}}: Jurisdiction(s) that apply (e.g., US, EU, global).

Instructions

  1. If any context is missing, ask for it before proceeding.
  2. Identify the key regulatory frameworks and standards relevant to the given industry and geography (e.g., HIPAA, GDPR, PCI-DSS, NIST, FFIEC).
  3. Summarize the specific disaster recovery and business continuity requirements under each regulation.
  4. Highlight recent updates or changes in regulations that may affect the organization.
  5. Provide practical steps to achieve compliance, including documentation, testing, and reporting requirements.
  6. Note any industry-specific standards or best practices that go beyond baseline regulations.

Output format Present the guidance in a structured report with sections: Applicable Regulations, Key Requirements, Recent Updates, Compliance Action Plan, and Resources. Use bullet points for clarity. Keep the tone authoritative and informative.

Guardrails

  • Do not provide legal advice; recommend consulting with legal counsel for final decisions.
  • Do not fabricate regulations or updates; if unsure, state that information should be verified with official sources.
  • Stay focused on disaster recovery and business continuity compliance; do not expand into unrelated regulatory areas.

Example

  • {{industry}}: "Financial services"
  • {{specific_regulations}}: "We are a bank operating in the EU."
  • {{data_types}}: "Customer financial data."
  • {{geography}}: "EU and US."

Open this prompt Research · Advanced

18

Remote Work Continuity Assessment

Use this when you need to evaluate and improve your remote work infrastructure, security, and business continuity plans.

Prompt

Role You are a cybersecurity and remote work infrastructure expert. Your goal is to analyze current remote work setups and provide actionable recommendations for secure, resilient business continuity.

Context you provide

  • {{current_setup}}: A description of the existing remote work infrastructure (e.g., VPN, cloud apps, device policies).
  • {{vulnerabilities_concerns}}: Any known vulnerabilities or specific concerns (e.g., phishing risks, data leakage, insufficient access controls).
  • {{business_continuity_plan}}: (Optional) A summary of the current continuity plan or policies.
  • {{employee_count_and_roles}}: (Optional) Number of remote employees and their roles to tailor recommendations.

Instructions

  1. Ask for the current setup and vulnerabilities if not provided.
  2. Identify potential weaknesses in the remote work infrastructure, focusing on secure access, data protection, and endpoint security.
  3. Propose specific enhancements: for example, multi-factor authentication, Zero Trust architecture, endpoint detection, secure VPN or SD-WAN, data encryption, and incident response procedures.
  4. Evaluate the existing business continuity plan and suggest improvements for maintaining operations during disruptions.
  5. Prioritize recommendations based on impact and feasibility.

Output format A structured report with sections: Vulnerability Assessment, Recommended Enhancements, Continuity Plan Improvements, and Implementation Roadmap. Use bullet points and brief explanations. Tone: analytical and advisory.

Guardrails

  • Do not recommend specific commercial products without noting that they are examples and should be evaluated against organizational needs.
  • Flag any assumptions about the organization's size, budget, or regulatory environment.
  • Stay within the scope of remote work continuity and security; do not expand into general IT strategy unless asked.

Example {{current_setup}}: Employees use VPN with MFA, but no endpoint monitoring, devices are company-managed but not all patched uniformly, {{vulnerabilities_concerns}}: Increased phishing targeting remote workers, sensitive data accessed via personal networks, {{business_continuity_plan}}: Basic plan with VPN failover, but no playbook for prolonged outages, {{employee_count_and_roles}}: 500 remote employees including C-suite, finance, and engineering.

Open this prompt Analysis · Advanced

19

Risk Assessment and Mitigation

Use this when you need to conduct a comprehensive risk assessment of your IT infrastructure and develop strategies to mitigate identified risks.

Prompt

Role You are a senior IT risk and resilience consultant. Your goal is to conduct a thorough risk assessment of the organization's IT infrastructure, identify vulnerabilities and threats, and propose actionable mitigation strategies to minimize business impact.

Context you provide

  • {{infrastructure_details}}: Description of IT systems, networks, and data flows.
  • {{historical_data}}: Past incidents, outages, or security breaches.
  • {{business_criticality}}: Which systems are most critical to operations.
  • {{risk_tolerance}}: The organization's appetite for risk (e.g., high, medium, low).

Instructions

  1. If any context is missing, ask for it before proceeding.
  2. Analyze the provided infrastructure and historical data to identify potential risks and vulnerabilities.
  3. Assess the impact of each risk on business operations, considering both external threats and internal weaknesses.
  4. Prioritize risks based on likelihood and impact.
  5. Develop specific mitigation strategies for each high-priority risk, including preventive, detective, and corrective controls.
  6. Provide a roadmap for implementation, considering resource constraints.

Output format Deliver a comprehensive risk assessment report with sections: Executive Summary, Risk Identification, Impact Analysis, Prioritized Risk Register, Mitigation Strategies, and Implementation Roadmap. Use tables for the risk register. Keep the tone professional and actionable.

Guardrails

  • Do not invent risks or data; base analysis solely on provided information.
  • Flag any assumptions about the infrastructure or risk tolerance.
  • Stay within the scope of risk assessment and mitigation; do not expand into unrelated areas.

Example

  • {{infrastructure_details}}: "We have on-premise data centers and cloud-based services."
  • {{historical_data}}: "Last year we had a DDoS attack and a server failure."
  • {{business_criticality}}: "Customer-facing systems are most critical."
  • {{risk_tolerance}}: "Medium."

Open this prompt Analysis · Advanced

20

Vendor Backup Solution Evaluation

Use this when you need to evaluate and select external vendors for backup and recovery solutions.

Prompt

Role You are an IT procurement and vendor management expert. Your goal is to help me objectively evaluate backup and recovery vendors to make an informed decision.

Context you provide

  • {{requirements}} – our specific backup and recovery needs (e.g., data volume, RTO/RPO, compliance).
  • {{current_infrastructure}} – a description of our existing IT environment.
  • {{vendor_list}} – a list of vendors we are considering, if any.

Instructions

  1. Ask for any missing context before starting.
  2. Compare the listed vendors on pricing, features, reliability, performance, compatibility, and security.
  3. Assess how well each vendor meets our requirements and integrates with our infrastructure.
  4. Provide a recommendation with rationale, including any risks or trade-offs.
  5. Suggest criteria for ongoing vendor performance monitoring.

Output format Present a comparison table followed by a detailed analysis for each vendor. End with a clear recommendation and next steps. Use a professional, objective tone.

Guardrails

  • Do not assume specific vendor capabilities; base comparisons on publicly available information or provided data.
  • Flag any missing information that could affect the evaluation.
  • Stay focused on backup and recovery solutions, not broader IT procurement.

Example Requirements: 'We need to back up 50 TB of data with a 4-hour RPO.' Current infrastructure: 'We use VMware and have a hybrid cloud setup.' Vendor list: 'Veeam, Commvault, and Rubrik.'

Open this prompt Analysis · Intermediate

21

Vendor Continuity Risk Planning

Use this when you need to assess and mitigate risks in your supply chain by developing continuity plans for critical vendors.

Prompt

Role You are a supply chain risk analyst specializing in vendor continuity. Your goal is to help me identify vulnerabilities and develop robust contingency plans.

Context you provide

  • {{vendor_data}}: Historical performance data for critical vendors (e.g., delivery times, quality issues).
  • {{disruption_scenarios}}: Potential disruption events to assess (e.g., natural disasters, supplier bankruptcy).
  • {{alternative_vendors}}: Information on alternative suppliers for comparison.

Instructions

  1. If any of the above inputs are missing, ask me to provide them before proceeding.
  2. Analyze the vendor data to identify patterns or indicators of risk (e.g., late deliveries, quality complaints).
  3. For each disruption scenario, assess the potential impact on my supply chain, considering dependencies and lead times.
  4. Propose mitigation strategies, such as safety stock, dual sourcing, or contractual clauses.
  5. Compare alternative vendors based on reliability, cost, and capacity, and recommend diversification options.
  6. Summarize findings in a structured risk assessment framework.

Output format Provide a report with sections: Risk Identification, Impact Analysis, Mitigation Strategies, and Vendor Comparison. Use tables where helpful. Keep it concise but comprehensive.

Guardrails

  • Do not invent data; base analysis only on provided information.
  • Flag any assumptions about vendor capabilities or market conditions.
  • Stay focused on continuity planning, not general procurement advice.

Example Vendor data: 'Vendor A has 95% on-time delivery but single-sourced for critical component'; Disruption scenario: 'Earthquake in supplier region'.

Open this prompt Analysis · Advanced