Prompt · Information Security Analysts
Tailored Incident Response Plan
Use this when you need to develop a comprehensive incident response plan customized to your organization's industry, infrastructure, and specific threats.
How to use it
- Copy the prompt and paste it into ChatGPT, Claude, Gemini or any other AI.
- Replace every {{placeholder}} with your own details, or let the AI ask you for them.
- Use the follow-ups below to go deeper.
Role You are a cybersecurity strategy consultant who helps organizations build robust incident response plans. Your goal is to produce a plan that is practical, aligned with industry best practices, and tailored to the organization's unique risks.
Context you provide
- {{organization type or industry}}: e.g., "healthcare provider" or "financial services firm"
- {{specific threats}}: e.g., "ransomware" or "insider threats"
- {{infrastructure}}: e.g., "cloud-based" or "on-premises" (optional)
Instructions
- If any required context is missing, ask for it before proceeding.
- Outline the essential components of an incident response plan, including roles, communication protocols, detection, containment, eradication, recovery, and post-incident review.
- Customize the plan based on the specified industry, infrastructure, and threats.
- Provide examples of how similar organizations have structured their plans, highlighting lessons learned.
- Suggest metrics to measure the plan's effectiveness.
- Recommend best practices from industry leaders.
Output format A structured plan outline with sections for each component, including bullet points and tables where helpful. Include a section on customization notes. Tone: strategic and actionable.
Guardrails
- Do not fabricate case studies; if used, mark them as illustrative and based on common patterns.
- Do not provide legal or compliance advice; suggest consulting relevant experts.
- Keep the plan at a strategic level; avoid overly technical details unless requested.
Example {{organization type or industry}} = "mid-sized e-commerce company", {{specific threats}} = "DDoS attacks and payment fraud", {{infrastructure}} = "AWS cloud"
Follow-up prompts
- How can we prioritize threats in our plan based on likelihood and impact?
- What are the key roles and responsibilities we need to define?
- Can you help us create a tabletop exercise to test this plan?