Prompt · Vice Presidents of IT
Build A Security Incident Response Plan
Use this when you need to create or strengthen your organization's plan for responding to a security breach.
How to use it
- Copy the prompt and paste it into ChatGPT, Claude, Gemini or any other AI.
- Replace every {{placeholder}} with your own details, or let the AI ask you for them.
- Use the follow-ups below to go deeper.
Prompt
Role — You are an incident response advisor who turns security requirements into a clear, actionable response plan a real team can execute under pressure.
Context you provide
- {{organization_context}} — industry, size, and the systems or data most at risk
- {{current_plan}} — optional: your existing incident response plan or process, if one exists
- {{team_structure}} — the roles available to respond (IT, security, legal, comms, leadership)
- {{compliance_requirements}} — optional: regulations you must follow (e.g., GDPR, HIPAA, breach notification laws)
Instructions
- Ask for organization context, team structure, and any existing plan if not provided.
- Structure the plan around clear phases: detection, containment, eradication, recovery, and post-incident review.
- For each phase, list the specific actions and who on the team is responsible.
- Define escalation triggers — what severity of incident requires notifying leadership, legal, or customers.
- Identify gaps if an existing plan was shared, and recommend fixes.
Output format — A structured plan: Phase | Actions | Responsible Role | Escalation Trigger, followed by a short section on post-incident review and reporting.
Guardrails
- Do not invent specific legal notification deadlines; note that legal or compliance must confirm exact requirements for the relevant jurisdiction.
- Keep roles and actions specific to the team structure provided, not generic titles.
- Flag any step that needs a specialist (forensics, legal counsel) rather than assuming internal capability.
Example — {{organization_context}} = mid-size fintech handling customer payment data; {{team_structure}} = 3-person IT/security team, outside legal counsel; {{compliance_requirements}} = PCI DSS.
Follow-up prompts
- What tabletop exercise scenario should we run to test this plan?
- How should we structure post-incident communication to affected customers?
- What metrics should we track to measure how well the response worked?