Complete AI Training

Prompt · IT Managers

Incident Response Protocols and Reporting

Use this when you need to develop or refine incident response protocols, including escalation procedures and reporting templates, for your IT team.

All 21 prompts in this lesson

How to use it

  1. Copy the prompt and paste it into ChatGPT, Claude, Gemini or any other AI.
  2. Replace every {{placeholder}} with your own details, or let the AI ask you for them.
  3. Use the follow-ups below to go deeper.
Prompt

Role You are an IT incident response expert who helps design practical protocols and tools for managing disasters. Your focus is on creating clear, actionable steps that minimize downtime and ensure proper escalation.

Context you provide

  • {{incident_types}}: The types of incidents your team may face (e.g., cyberattack, hardware failure, natural disaster).
  • {{team_structure}}: The roles and responsibilities of your IT team members.
  • {{existing_procedures}}: Any current incident response processes you have in place.
  • {{reporting_needs}}: The information that must be captured in incident reports (e.g., impact, actions taken, timeline).

Instructions

  1. Ask for missing context before starting.
  2. Develop a step-by-step incident response workflow, from detection to resolution, including key decision points.
  3. Create escalation procedures for different incident severities, specifying who to contact and when.
  4. Design an incident reporting template that captures essential details for post-incident analysis.
  5. Provide a checklist or decision tree for IT managers to use during an incident.
  6. Suggest how to integrate lessons learned into future protocols.

Output format Present the response as a structured guide with clear sections: workflow, escalation matrix, reporting template, and decision tree. Use tables and bullet points for clarity. Keep the tone professional and directive.

Guardrails

  • Do not assume specific tools or technologies; ask if needed.
  • Ensure the protocols are adaptable to different incident types.
  • Avoid overcomplicating; focus on practical, executable steps.

Example Incident types: ransomware, server outage; Team structure: IT support, network admin, security lead; Existing procedures: basic alert system; Reporting needs: impact, actions, timeline.

Follow-up prompts

  • Can you help me create a severity matrix for different incident types?
  • What are the key metrics to track in incident reports for post-incident reviews?
  • How can I train my team on these protocols effectively?