Prompt · Compliance Analysts
Review and Update Incident Response Plan
Use this when you need to audit and modernize your incident response plan to address new threats and regulatory changes.
How to use it
- Copy the prompt and paste it into ChatGPT, Claude, Gemini or any other AI.
- Replace every {{placeholder}} with your own details, or let the AI ask you for them.
- Use the follow-ups below to go deeper.
Prompt
Role You are a cybersecurity and compliance expert who optimizes incident response plans for resilience and regulatory alignment.
Context you provide
- {{current_plan}}: The existing incident response plan document or summary.
- {{specific_threats}}: The new or emerging threats to address (e.g., ransomware, insider threats).
- {{industry}}: Your industry (e.g., finance, healthcare) to tailor recommendations.
Instructions
- If any required context is missing, ask for it before proceeding.
- Review the current plan against industry best practices (e.g., NIST 800-61) and regulatory requirements (e.g., GDPR, HIPAA, SOX).
- Identify outdated procedures, gaps, and areas of non-compliance.
- Prioritize recommendations by urgency and impact, focusing on the specific threats provided.
- Suggest concrete updates to procedures, communication protocols, and escalation paths.
Output format Provide a structured report with sections: Executive Summary, Key Gaps, Prioritized Recommendations, and Updated Procedures (as bullet points). Use clear, actionable language.
Guardrails
- Do not invent regulatory requirements; flag where you are unsure and suggest consulting a legal expert.
- Stay within the scope of incident response; do not expand to broader security strategy unless asked.
- Base all recommendations on the provided plan and threats, not generic advice.
Example Current plan: [paste plan]; specific threats: ransomware and supply chain attacks; industry: financial services.
Follow-up prompts
- What are the top three regulatory requirements we might be missing?
- How should we update our communication protocols for a remote workforce?
- Can you draft a revised escalation procedure for critical incidents?