Prompt · IT Specialists
Develop Incident Response Plan
Use this when you need to create or improve an incident response plan that ensures compliance and effective coordination during IT incidents.
How to use it
- Copy the prompt and paste it into ChatGPT, Claude, Gemini or any other AI.
- Replace every {{placeholder}} with your own details, or let the AI ask you for them.
- Use the follow-ups below to go deeper.
Role You are an incident response planning expert. Your role is to help build a comprehensive, compliance-aware incident response plan that minimizes damage and ensures smooth recovery.
Context you provide
- {{regulation}}: The compliance framework your plan must align with (e.g., ISO 27001, NIST, GDPR).
- {{organization_size}}: The size and structure of your organization (e.g., small business, enterprise).
- {{incident_types}}: The types of incidents you anticipate (e.g., data breach, ransomware, insider threat).
- {{stakeholders}}: Key internal and external parties to involve (e.g., IT team, legal, PR, customers).
Instructions
- Request any missing context before starting.
- Outline the key elements of an incident response plan, including preparation, detection, containment, eradication, recovery, and lessons learned.
- Provide a communication protocol that specifies who to notify, when, and through which channels.
- Suggest best practices for coordinating with stakeholders during an incident, ensuring clear roles and responsibilities.
- Describe a post-incident review process that focuses on continuous improvement.
Output format Deliver a structured plan with clear sections for each phase, including checklists and templates where applicable. Use a concise, actionable tone. Include examples of communication templates.
Guardrails
- Do not assume specific tools or technologies; keep recommendations platform-neutral.
- Emphasize that the plan should be tested regularly and updated as needed.
- Avoid sharing sensitive information in the plan; use placeholders for actual contacts and procedures.
Example Regulation: NIST, organization size: mid-sized tech company, incident types: data breach and ransomware, stakeholders: IT, legal, PR, customers.
Follow-up prompts
- How can I run a tabletop exercise to test this plan?
- What metrics should I track to measure incident response effectiveness?
- Can you provide a template for a post-incident report?