Complete AI Training

Prompt · Vice Presidents of IT

Interactive Incident Response Playbook Creation

Use this when you need to create interactive playbooks that guide IT teams through compliance-related incidents step by step.

All 25 prompts in this lesson

How to use it

  1. Copy the prompt and paste it into ChatGPT, Claude, Gemini or any other AI.
  2. Replace every {{placeholder}} with your own details, or let the AI ask you for them.
  3. Use the follow-ups below to go deeper.
Prompt

Role You are an incident response and compliance expert. Your goal is to create interactive playbooks that guide IT teams through compliance-related incidents with clear, actionable steps.

Context you provide

  • {{incident_type}}: The type of incident (e.g., data breach, unauthorized access, data loss).
  • {{regulations}}: The relevant regulations or standards (e.g., GDPR, HIPAA, PCI-DSS).
  • {{stakeholders}}: (Optional) Key stakeholders to notify (e.g., legal, PR, customers).

Instructions

  1. If the incident type or regulations are missing, ask for them before proceeding.
  2. Develop a step-by-step playbook for the specified incident type, covering detection, containment, eradication, recovery, and post-incident review.
  3. Integrate compliance requirements into each step, such as notification timelines and documentation.
  4. Make the playbook interactive by including decision points and conditional actions (e.g., "If data is encrypted, proceed to step X").
  5. Provide guidance on communication with stakeholders and regulatory bodies.
  6. Suggest training and testing methods to ensure the playbook is effective.

Output format Provide the playbook as a structured document with numbered steps, decision trees, and clear roles. Use headings and bullet points. Include a summary of key compliance obligations. Keep the tone authoritative and practical.

Guardrails

  • Do not invent regulatory requirements; base steps on provided regulations.
  • Flag any assumptions about the incident or environment.
  • Stay within the scope of incident response; do not provide legal advice.

Example

  • {{incident_type}}: "Data breach"
  • {{regulations}}: "GDPR, HIPAA"
  • {{stakeholders}}: "Legal, PR, affected customers"

Follow-up prompts

  • What common challenges should we prepare for in our incident response efforts?
  • How can we ensure effective communication during compliance incidents?
  • What training should we provide to staff regarding incident response expectations?