Complete AI Training

Prompt · Service Managers

Create Incident Response Playbooks

Use this when you need to develop or update a playbook for responding to incidents like cybersecurity breaches or operational disruptions.

All 20 prompts in this lesson

How to use it

  1. Copy the prompt and paste it into ChatGPT, Claude, Gemini or any other AI.
  2. Replace every {{placeholder}} with your own details, or let the AI ask you for them.
  3. Use the follow-ups below to go deeper.
Prompt

Role You are an incident response and crisis management expert. Your goal is to create comprehensive, actionable playbooks that minimize damage and ensure a coordinated response.

Context you provide

  • {{incident_types}}: List the types of incidents the playbook should cover (e.g., cybersecurity breaches, natural disasters, operational failures).
  • {{organization_context}}: Describe your organization's size, industry, and any existing response procedures.
  • {{stakeholders}}: Identify key roles or departments that would be involved in the response.
  • {{compliance_requirements}}: Mention any regulatory or industry standards that must be met.

Instructions

  1. Ask for missing context before starting.
  2. For each incident type, outline a step-by-step response procedure, including detection, containment, eradication, recovery, and post-incident review.
  3. Define clear roles and responsibilities for each step.
  4. Include communication protocols for internal and external stakeholders.
  5. Suggest how to integrate automated response actions where appropriate.
  6. Provide guidance on how to keep the playbook updated and train staff.

Output format Structure the playbook with sections per incident type, each containing: Objective, Trigger, Response Steps (with roles), Communication Plan, and Post-Incident Actions. Use clear, actionable language.

Guardrails

  • Do not invent specific threats or procedures not relevant to the user's context.
  • Flag any assumptions about the organization's infrastructure or capabilities.
  • Ensure the playbook aligns with common industry best practices, but do not provide legal advice.

Example Incident types: cybersecurity breach, data leak. Organization: mid-sized tech company with 200 employees. Stakeholders: IT, legal, PR, management. Compliance: GDPR.

Follow-up prompts

  • What process should we establish for regularly reviewing and updating this playbook?
  • Can you suggest a training exercise to test our team's readiness?
  • How can we ensure our playbook aligns with industry standards like NIST or ISO 27001?