Prompt · Cybersecurity Analysts
Design Incident Escalation Procedures
Use this when you need to create or refine escalation procedures for cybersecurity incidents, including severity criteria and communication paths.
How to use it
- Copy the prompt and paste it into ChatGPT, Claude, Gemini or any other AI.
- Replace every {{placeholder}} with your own details, or let the AI ask you for them.
- Use the follow-ups below to go deeper.
Prompt
Role You are an expert in cybersecurity incident management and organizational process design. Your goal is to help me build clear, actionable escalation procedures that ensure timely and appropriate responses.
Context you provide
- {{incident_types}}: the types of incidents your organization may face (e.g., phishing, malware, insider threat).
- {{organization_structure}}: team sizes, reporting lines, and available specialized teams.
- {{industry}}: your sector and any relevant regulations (e.g., healthcare, finance, government).
Instructions
- Ask for missing context if needed.
- Define severity levels (e.g., low, medium, high, critical) with clear criteria for each, tailored to the incident types provided.
- For each severity level, specify when to escalate (e.g., to management, specialized teams, external authorities) and the expected response time.
- Map out communication channels and escalation paths, including backup contacts and tools.
- Highlight legal and compliance considerations relevant to your industry, and suggest how to align procedures with regulations.
Output format A structured procedure document with sections: Severity Levels, Escalation Criteria, Communication Paths, Compliance Considerations. Use tables for clarity. Keep it practical and ready for adoption.
Guardrails
- Do not assume specific regulations; ask or flag if industry is not provided.
- Avoid generic advice; tailor all recommendations to the provided context.
- Stay focused on escalation procedures, not broader incident response planning.
Example
- {{incident_types}}: phishing, ransomware, data breach; {{organization_structure}}: 5-person security team, CISO reports to CIO; {{industry}}: financial services.
Follow-up prompts
- How can I test these procedures with a tabletop exercise?
- What metrics should I track to measure the effectiveness of my escalation process?
- Can you help me draft a one-page quick-reference guide for on-call staff?