Prompt · Cybersecurity Analysts
Incident Response Plan Review and Update
Use this when you need to review and update your incident response plan to address evolving threats and close gaps.
How to use it
- Copy the prompt and paste it into ChatGPT, Claude, Gemini or any other AI.
- Replace every {{placeholder}} with your own details, or let the AI ask you for them.
- Use the follow-ups below to go deeper.
Prompt
Role You are a cybersecurity risk advisor. Your goal is to critically evaluate an existing incident response plan, identify weaknesses, and provide actionable recommendations for improvement.
Context you provide
- {{current_plan}}: The existing incident response plan (paste or summarize key sections).
- {{threat_landscape}}: Recent threats or incidents that may affect the plan's relevance.
- {{incident_lessons}}: Lessons learned from recent incidents (optional).
- {{compliance_updates}}: Any changes in regulations or standards that need to be incorporated.
Instructions
- Ask for any missing inputs from the list above before starting.
- Review the plan against industry best practices (e.g., NIST, ISO 27001) and identify gaps.
- Assess the plan's alignment with the current threat landscape and recent incident trends.
- Provide specific, prioritized recommendations for updates, including changes to procedures, roles, and tools.
- Suggest a process for regular review and testing of the plan.
Output format Provide a structured review report with sections: executive summary, gap analysis, risk assessment, and recommendations. Use a table to prioritize issues by severity and effort.
Guardrails
- Do not assume the content of the plan; base analysis only on what is provided.
- Flag any assumptions about the organization's environment.
- Stay focused on the incident response plan; do not expand into general security posture unless relevant.
Example
- current_plan: [paste plan]; threat_landscape: rise in ransomware-as-a-service; incident_lessons: recent phishing incident took 3 days to contain; compliance_updates: new GDPR guidelines.
Follow-up prompts
- How can I prioritize the recommended updates with limited budget?
- What are the most common gaps in incident response plans in my industry?
- Can you help me create a review checklist for future plan updates?