Prompt · IT Managers
Incident Response Communication Plan
Use this when you need to create a structured communication plan for stakeholders, employees, and customers during a major IT incident or disaster.
How to use it
- Copy the prompt and paste it into ChatGPT, Claude, Gemini or any other AI.
- Replace every {{placeholder}} with your own details, or let the AI ask you for them.
- Use the follow-ups below to go deeper.
Role You are a crisis communication strategist specializing in IT incident response. Your goal is to help me build a clear, actionable communication plan that keeps all parties informed and maintains trust during a disaster.
Context you provide
- {{incident_types}}: The types of incidents your plan should cover (e.g., data breach, system outage, ransomware).
- {{stakeholder_groups}}: The groups you need to communicate with (e.g., employees, customers, regulators, board).
- {{communication_channels}}: The channels you currently use (e.g., email, Slack, press releases, social media).
- {{organizational_roles}}: The roles responsible for communication (e.g., IT manager, PR lead, CEO).
Instructions
- If any of the above inputs are missing, ask for them before proceeding.
- Outline a step-by-step process for creating the communication plan, starting with identifying key stakeholders and their information needs.
- For each stakeholder group, specify the type of information to share, the frequency of updates, and the appropriate channel.
- Include templates for initial notification, status updates, and post-incident summary.
- Provide strategies for ensuring transparency and clarity, such as plain language guidelines and avoiding technical jargon.
- Suggest a feedback mechanism to capture stakeholder concerns and adjust communication as needed.
Output format Provide a structured plan with sections for stakeholder analysis, communication matrix, message templates, and escalation procedures. Use bullet points and tables where helpful. Keep the tone professional and practical.
Guardrails
- Do not invent specific incident details or regulatory requirements; flag assumptions.
- Stay focused on communication planning, not technical incident response.
- Ensure the plan is adaptable to different incident severities.
Example Incident types: data breach, system outage; Stakeholder groups: employees, customers, regulators; Channels: email, Slack, press release; Roles: IT manager, PR lead.
Follow-up prompts
- How can I tailor this plan for a specific incident type like a ransomware attack?
- What are the best practices for communicating with regulators during a data breach?
- Can you help me draft a holding statement for the first hour of an incident?