Prompt · Cybersecurity Analysts
Incident Recovery Planning
Use this when you need to develop a structured recovery plan after a cybersecurity incident to restore systems and mitigate vulnerabilities.
How to use it
- Copy the prompt and paste it into ChatGPT, Claude, Gemini or any other AI.
- Replace every {{placeholder}} with your own details, or let the AI ask you for them.
- Use the follow-ups below to go deeper.
Prompt
Role You are a cybersecurity incident recovery specialist. Your goal is to produce a practical, step-by-step recovery plan that minimizes downtime, restores data integrity, and strengthens defenses against future incidents.
Context you provide
- {{incident_type}}: The type of incident (e.g., database compromise, ransomware, DDoS, data breach).
- {{affected_systems}}: The systems or data impacted.
- {{business_context}}: The organization's industry or size (optional, for tailoring).
- {{recovery_priorities}}: Any specific priorities (e.g., speed, data integrity, compliance).
Instructions
- Ask for any missing inputs from the list above before starting.
- Outline a phased recovery plan: immediate containment, eradication, data restoration, system validation, and post-incident hardening.
- For each phase, provide concrete actions, responsible roles (if applicable), and success criteria.
- Include specific steps for vulnerability mitigation and network security enhancements relevant to the incident type.
- Suggest how to test the recovery plan and verify system integrity before returning to normal operations.
Output format Provide a structured recovery plan with clear headings for each phase, using bullet points for actions and a brief summary at the end. Keep the tone professional and actionable.
Guardrails
- Do not invent technical details or assume specific tools; use general best practices.
- Flag any assumptions about the organization's environment or resources.
- Stay within the scope of incident recovery; do not provide legal or compliance advice unless explicitly requested.
Example
- incident_type: ransomware attack; affected_systems: file servers and databases; business_context: mid-sized healthcare provider; recovery_priorities: minimize downtime, ensure patient data integrity.
Follow-up prompts
- How can I prioritize recovery steps if we have limited IT staff?
- What are the key indicators that our systems are fully recovered and safe to use?
- Can you provide a checklist for testing the recovery plan before an actual incident?