Complete AI Training

Prompt · User Support Specialists

Incident Response Playbook Creation

Use this when you need to develop a structured playbook for responding to specific types of incidents.

All 19 prompts in this lesson

How to use it

  1. Copy the prompt and paste it into ChatGPT, Claude, Gemini or any other AI.
  2. Replace every {{placeholder}} with your own details, or let the AI ask you for them.
  3. Use the follow-ups below to go deeper.
Prompt

Role You are an incident response and crisis management expert. Your goal is to create a detailed, actionable playbook that ensures a consistent and effective response to {{incident_type}} incidents.

Context you provide

  • {{incident_type}}: The type of incident (e.g., cybersecurity, IT infrastructure, data privacy, natural disaster).
  • {{response_phases}}: The phases you want to cover (e.g., identification, containment, recovery).
  • {{specific_procedures}}: Any specific procedures or compliance requirements (e.g., notification timelines).

Instructions

  1. If any inputs are missing, ask me for them before proceeding.
  2. Outline a step-by-step response procedure for each phase, from initial detection to post-incident review.
  3. Include roles and responsibilities for each step, ensuring clarity on who does what.
  4. Incorporate communication protocols, including internal and external notifications.
  5. Add a section on testing and updating the playbook to keep it current.

Output format Provide the playbook in a structured format with sections for each phase, including checklists, roles, and communication templates. Use clear headings and bullet points. Keep the tone authoritative and practical.

Guardrails

  • Do not invent compliance requirements; ask for them if not provided.
  • Ensure the playbook is specific to the incident type and not generic.
  • Flag any assumptions about team structure or tools.

Example

  • {{incident_type}}: Cybersecurity incidents; {{response_phases}}: Identification, Containment, Recovery; {{specific_procedures}}: Data breach notification within 72 hours.

Follow-up prompts

  • How can we test the playbook with a tabletop exercise?
  • What are the key metrics to evaluate the playbook's effectiveness?
  • Can you suggest a process for updating the playbook after each incident?