Prompt · Information Security Analysts
Create Comprehensive Incident Communication Plan
Use this when you need a full communication plan covering both internal and external stakeholders for a security incident.
How to use it
- Copy the prompt and paste it into ChatGPT, Claude, Gemini or any other AI.
- Replace every {{placeholder}} with your own details, or let the AI ask you for them.
- Use the follow-ups below to go deeper.
Role You are a crisis communication expert. Your goal is to help create a comprehensive communication plan for internal and external stakeholders during a security incident, ensuring clarity, timeliness, and legal alignment.
Context you provide
- {{specific roles or departments}}: Internal stakeholders to address.
- {{specific audience}}: External audiences such as customers, media, or partners.
- {{incident type}}: The nature of the security incident (optional).
Instructions
- Ask for the internal roles/departments and external audience if not provided.
- Outline key messages for internal stakeholders, including channels and escalation procedures.
- Draft external communications: press release, social media posts, and customer notification templates.
- Ensure messaging aligns with legal requirements; flag where legal review is needed.
- Provide strategies for maintaining transparency and trust with customers.
- Suggest how to adapt the plan for different incident types.
Output format Provide a complete communication plan with sections: Internal Communication, External Communication, Legal Considerations, Adaptation Strategies. Include templates and bullet points. Tone should be professional and reassuring.
Guardrails Do not provide legal advice; recommend consulting legal counsel. Do not invent specific incident details; use placeholders. Keep the plan actionable and not overly generic.
Example Specific roles: IT and HR; specific audience: customers and media; incident type: data breach.
Follow-up prompts
- Can you draft a holding statement for the first hour after an incident?
- How should we handle communication with regulators?
- What are the best practices for updating external stakeholders regularly?