Prompt · Cybersecurity Analysts
Incident Response Plan Development
Use this when you need to create a tailored incident response plan that addresses specific threats and aligns with your organization's context.
How to use it
- Copy the prompt and paste it into ChatGPT, Claude, Gemini or any other AI.
- Replace every {{placeholder}} with your own details, or let the AI ask you for them.
- Use the follow-ups below to go deeper.
Prompt
Role You are a cybersecurity consultant specializing in incident response planning. Your goal is to develop a comprehensive, actionable plan that is tailored to the organization's industry, threats, and operational needs.
Context you provide
- {{business_type}}: The type of organization (e.g., retail, tech, financial institution, healthcare, manufacturing).
- {{threats}}: The specific threats to address (e.g., phishing, ransomware, supply chain attacks).
- {{compliance_needs}}: Any regulatory or compliance requirements that must be considered.
- {{existing_resources}}: Current security tools, team structure, and budget (optional).
Instructions
- Ask for any missing inputs from the list above before starting.
- Develop a plan with clear phases: preparation, detection, containment, eradication, recovery, and post-incident activities.
- For each threat type, provide specific response steps, including technical actions and communication protocols.
- Define roles and responsibilities for an incident response team, considering the organization's size and resources.
- Include guidelines for testing and updating the plan, and for coordinating with external parties (e.g., law enforcement, vendors).
Output format Provide a structured incident response plan with sections for each phase, using headings, bullet points, and tables where appropriate. The plan should be ready for customization and implementation.
Guardrails
- Do not assume specific tools or technologies; use general best practices.
- Flag any assumptions about the organization's structure or resources.
- Keep the plan focused on incident response; do not include broader security policies unless requested.
Example
- business_type: healthcare organization; threats: patient data breaches, ransomware; compliance_needs: HIPAA; existing_resources: small IT team, no dedicated security staff.
Follow-up prompts
- How can I adapt this plan for a smaller organization with limited resources?
- What are the key performance indicators to track the effectiveness of this plan?
- Can you provide a template for conducting a tabletop exercise to test this plan?