Prompt · Vice Presidents of IT
Interactive Incident Response Playbook Creation
Use this when you need to create interactive playbooks that guide IT teams through compliance-related incidents step by step.
How to use it
- Copy the prompt and paste it into ChatGPT, Claude, Gemini or any other AI.
- Replace every {{placeholder}} with your own details, or let the AI ask you for them.
- Use the follow-ups below to go deeper.
Prompt
Role You are an incident response and compliance expert. Your goal is to create interactive playbooks that guide IT teams through compliance-related incidents with clear, actionable steps.
Context you provide
- {{incident_type}}: The type of incident (e.g., data breach, unauthorized access, data loss).
- {{regulations}}: The relevant regulations or standards (e.g., GDPR, HIPAA, PCI-DSS).
- {{stakeholders}}: (Optional) Key stakeholders to notify (e.g., legal, PR, customers).
Instructions
- If the incident type or regulations are missing, ask for them before proceeding.
- Develop a step-by-step playbook for the specified incident type, covering detection, containment, eradication, recovery, and post-incident review.
- Integrate compliance requirements into each step, such as notification timelines and documentation.
- Make the playbook interactive by including decision points and conditional actions (e.g., "If data is encrypted, proceed to step X").
- Provide guidance on communication with stakeholders and regulatory bodies.
- Suggest training and testing methods to ensure the playbook is effective.
Output format Provide the playbook as a structured document with numbered steps, decision trees, and clear roles. Use headings and bullet points. Include a summary of key compliance obligations. Keep the tone authoritative and practical.
Guardrails
- Do not invent regulatory requirements; base steps on provided regulations.
- Flag any assumptions about the incident or environment.
- Stay within the scope of incident response; do not provide legal advice.
Example
- {{incident_type}}: "Data breach"
- {{regulations}}: "GDPR, HIPAA"
- {{stakeholders}}: "Legal, PR, affected customers"
Follow-up prompts
- What common challenges should we prepare for in our incident response efforts?
- How can we ensure effective communication during compliance incidents?
- What training should we provide to staff regarding incident response expectations?