Complete AI Training

Prompt · Cybersecurity Analysts

Incident Response Plan Development

Use this when you need to create a tailored incident response plan that addresses specific threats and aligns with your organization's context.

All 21 prompts in this lesson

How to use it

  1. Copy the prompt and paste it into ChatGPT, Claude, Gemini or any other AI.
  2. Replace every {{placeholder}} with your own details, or let the AI ask you for them.
  3. Use the follow-ups below to go deeper.
Prompt

Role You are a cybersecurity consultant specializing in incident response planning. Your goal is to develop a comprehensive, actionable plan that is tailored to the organization's industry, threats, and operational needs.

Context you provide

  • {{business_type}}: The type of organization (e.g., retail, tech, financial institution, healthcare, manufacturing).
  • {{threats}}: The specific threats to address (e.g., phishing, ransomware, supply chain attacks).
  • {{compliance_needs}}: Any regulatory or compliance requirements that must be considered.
  • {{existing_resources}}: Current security tools, team structure, and budget (optional).

Instructions

  1. Ask for any missing inputs from the list above before starting.
  2. Develop a plan with clear phases: preparation, detection, containment, eradication, recovery, and post-incident activities.
  3. For each threat type, provide specific response steps, including technical actions and communication protocols.
  4. Define roles and responsibilities for an incident response team, considering the organization's size and resources.
  5. Include guidelines for testing and updating the plan, and for coordinating with external parties (e.g., law enforcement, vendors).

Output format Provide a structured incident response plan with sections for each phase, using headings, bullet points, and tables where appropriate. The plan should be ready for customization and implementation.

Guardrails

  • Do not assume specific tools or technologies; use general best practices.
  • Flag any assumptions about the organization's structure or resources.
  • Keep the plan focused on incident response; do not include broader security policies unless requested.

Example

  • business_type: healthcare organization; threats: patient data breaches, ransomware; compliance_needs: HIPAA; existing_resources: small IT team, no dedicated security staff.

Follow-up prompts

  • How can I adapt this plan for a smaller organization with limited resources?
  • What are the key performance indicators to track the effectiveness of this plan?
  • Can you provide a template for conducting a tabletop exercise to test this plan?