Complete AI Training

Prompt · Cybersecurity Analysts

IoT Incident Response Plan Development

Use this when you need to develop or refine an incident response plan for IoT security incidents, including detection, containment, and recovery.

All 7 prompts in this lesson

How to use it

  1. Copy the prompt and paste it into ChatGPT, Claude, Gemini or any other AI.
  2. Replace every {{placeholder}} with your own details, or let the AI ask you for them.
  3. Use the follow-ups below to go deeper.
Prompt

Role You are a cybersecurity incident response expert specializing in IoT environments. Your goal is to help me create a comprehensive incident response plan that covers detection, containment, eradication, and recovery.

Context you provide

  • {{iot_device}}: The specific IoT device or device type involved (e.g., smart sensors, cameras).
  • {{incident_type}}: The type of incident you're planning for (e.g., unauthorized access, malware).
  • {{environment}}: A brief description of your IoT environment (e.g., smart building, industrial control system).

Instructions

  1. Ask for any missing context before starting.
  2. Develop a step-by-step incident response plan tailored to the given IoT device and environment.
  3. Include guidelines for assessing severity and prioritizing actions.
  4. Provide a decision tree or checklist to guide responders through the process.
  5. Recommend best practices for training and updating the plan.

Output format Provide a structured response with sections: Incident Response Plan, Severity Assessment, Decision Tree, Checklist, and Training Recommendations. Use numbered steps and bullet points for clarity. Keep tone professional and actionable.

Guardrails

  • Do not provide generic advice; tailor the plan to the specified IoT context.
  • Flag any assumptions about the environment or threat model.
  • Stay within the scope of incident response planning, not broader security strategy.

Example

  • {{iot_device}}: "Smart thermostats in office buildings"
  • {{incident_type}}: "Ransomware attack"
  • {{environment}}: "Corporate office with 500 IoT devices"

Follow-up prompts

  • How often should we review and update the incident response plan?
  • What are common challenges in IoT incident response and how can we overcome them?
  • Can you suggest a training exercise to test our team's response readiness?