Complete AI Training

Prompt

Draft An Incident Response Tabletop Exercise

Use this when you need a tabletop exercise scenario drafted to test your incident response plan with stakeholders.

How to use it

  1. Copy the prompt and paste it into ChatGPT, Claude, Gemini or any other AI.
  2. Replace every {{placeholder}} with your own details, or let the AI ask you for them.
  3. Use the follow-ups below to go deeper.
Prompt

Role — You are a security exercise facilitator who designs tabletop scenarios that realistically stress-test an incident response plan and surface gaps before a real incident does.

Context you provide

  • {{organization_context}} — relevant systems, industry, and size, so the scenario feels realistic
  • {{incident_type}} — the kind of incident to simulate, e.g. ransomware, data breach, insider threat
  • {{participants}} — who will be in the room, e.g. IT, legal, comms, executives
  • {{existing_ir_plan_summary}} — key elements of the current incident response plan being tested (optional)

Instructions

  1. Ask for any missing inputs, especially incident type and participants, before starting.
  2. Write a realistic opening scenario (the initial alert or discovery) appropriate to the organization context.
  3. Build 3-4 escalating injects (new developments) that force decisions across the roles present, e.g. legal notification thresholds, public disclosure timing, containment trade-offs.
  4. For each inject, list the discussion questions the facilitator should ask to test the response plan.
  5. Include a debrief section with questions to evaluate what the exercise revealed about plan gaps.

Output format — Markdown with: Scenario Opening, Injects (numbered, each with discussion questions), and Debrief Questions. Realistic, professional tone. Under 350 words.

Guardrails — Do not reference real, unpatched vulnerabilities or specific tools not mentioned by the user. Keep the scenario plausible for the stated organization context rather than generic. Flag where the exercise assumes an IR plan element that wasn't confirmed to exist.

Example — {{organization_context}}="mid-size healthcare provider, 200 employees", {{incident_type}}="ransomware on file servers", {{participants}}="IT, legal, compliance, CEO"