Prompt · Service Managers
Create Incident Response Playbooks
Use this when you need to develop or update a playbook for responding to incidents like cybersecurity breaches or operational disruptions.
How to use it
- Copy the prompt and paste it into ChatGPT, Claude, Gemini or any other AI.
- Replace every {{placeholder}} with your own details, or let the AI ask you for them.
- Use the follow-ups below to go deeper.
Role You are an incident response and crisis management expert. Your goal is to create comprehensive, actionable playbooks that minimize damage and ensure a coordinated response.
Context you provide
- {{incident_types}}: List the types of incidents the playbook should cover (e.g., cybersecurity breaches, natural disasters, operational failures).
- {{organization_context}}: Describe your organization's size, industry, and any existing response procedures.
- {{stakeholders}}: Identify key roles or departments that would be involved in the response.
- {{compliance_requirements}}: Mention any regulatory or industry standards that must be met.
Instructions
- Ask for missing context before starting.
- For each incident type, outline a step-by-step response procedure, including detection, containment, eradication, recovery, and post-incident review.
- Define clear roles and responsibilities for each step.
- Include communication protocols for internal and external stakeholders.
- Suggest how to integrate automated response actions where appropriate.
- Provide guidance on how to keep the playbook updated and train staff.
Output format Structure the playbook with sections per incident type, each containing: Objective, Trigger, Response Steps (with roles), Communication Plan, and Post-Incident Actions. Use clear, actionable language.
Guardrails
- Do not invent specific threats or procedures not relevant to the user's context.
- Flag any assumptions about the organization's infrastructure or capabilities.
- Ensure the playbook aligns with common industry best practices, but do not provide legal advice.
Example Incident types: cybersecurity breach, data leak. Organization: mid-sized tech company with 200 employees. Stakeholders: IT, legal, PR, management. Compliance: GDPR.
Follow-up prompts
- What process should we establish for regularly reviewing and updating this playbook?
- Can you suggest a training exercise to test our team's readiness?
- How can we ensure our playbook aligns with industry standards like NIST or ISO 27001?