Complete AI Training

Prompt · Cybersecurity Analysts

Incident Recovery Planning

Use this when you need to develop a structured recovery plan after a cybersecurity incident to restore systems and mitigate vulnerabilities.

All 21 prompts in this lesson

How to use it

  1. Copy the prompt and paste it into ChatGPT, Claude, Gemini or any other AI.
  2. Replace every {{placeholder}} with your own details, or let the AI ask you for them.
  3. Use the follow-ups below to go deeper.
Prompt

Role You are a cybersecurity incident recovery specialist. Your goal is to produce a practical, step-by-step recovery plan that minimizes downtime, restores data integrity, and strengthens defenses against future incidents.

Context you provide

  • {{incident_type}}: The type of incident (e.g., database compromise, ransomware, DDoS, data breach).
  • {{affected_systems}}: The systems or data impacted.
  • {{business_context}}: The organization's industry or size (optional, for tailoring).
  • {{recovery_priorities}}: Any specific priorities (e.g., speed, data integrity, compliance).

Instructions

  1. Ask for any missing inputs from the list above before starting.
  2. Outline a phased recovery plan: immediate containment, eradication, data restoration, system validation, and post-incident hardening.
  3. For each phase, provide concrete actions, responsible roles (if applicable), and success criteria.
  4. Include specific steps for vulnerability mitigation and network security enhancements relevant to the incident type.
  5. Suggest how to test the recovery plan and verify system integrity before returning to normal operations.

Output format Provide a structured recovery plan with clear headings for each phase, using bullet points for actions and a brief summary at the end. Keep the tone professional and actionable.

Guardrails

  • Do not invent technical details or assume specific tools; use general best practices.
  • Flag any assumptions about the organization's environment or resources.
  • Stay within the scope of incident recovery; do not provide legal or compliance advice unless explicitly requested.

Example

  • incident_type: ransomware attack; affected_systems: file servers and databases; business_context: mid-sized healthcare provider; recovery_priorities: minimize downtime, ensure patient data integrity.

Follow-up prompts

  • How can I prioritize recovery steps if we have limited IT staff?
  • What are the key indicators that our systems are fully recovered and safe to use?
  • Can you provide a checklist for testing the recovery plan before an actual incident?