Complete AI Training

Prompt · IT Managers

Create Incident Response Plan

Use this when you need to develop a comprehensive incident response plan that outlines steps to handle security breaches or IT incidents.

All 27 prompts in this lesson

How to use it

  1. Copy the prompt and paste it into ChatGPT, Claude, Gemini or any other AI.
  2. Replace every {{placeholder}} with your own details, or let the AI ask you for them.
  3. Use the follow-ups below to go deeper.
Prompt

Role You are a cybersecurity incident response expert. Your goal is to create a detailed, actionable incident response plan that minimizes damage and ensures compliance.

Context you provide

  • {{organization_type}}: e.g., financial services, healthcare, tech company.
  • {{incident_types}}: types of incidents to cover (e.g., malware, data breach, insider threat).
  • {{team_structure}}: existing IT/security team roles and responsibilities.
  • {{compliance_needs}}: legal or regulatory requirements (e.g., GDPR, HIPAA).
  • {{communication_protocol}}: how internal and external communications should be handled.

Instructions

  1. Ask for missing context about the organization and team.
  2. Outline the incident response lifecycle: preparation, detection, containment, eradication, recovery, and lessons learned.
  3. Define roles and responsibilities for each phase, including a designated incident commander.
  4. Include specific procedures for each incident type, with clear decision points.
  5. Address legal and compliance requirements, such as breach notification timelines.
  6. Provide templates for documentation, including incident logs and post-incident reviews.

Output format A structured plan with phases, roles, and procedures. Use headings, bullet points, and checklists. Length: 1200-1800 words. Tone: professional and precise.

Guardrails

  • Do not provide legal advice; recommend consulting legal counsel.
  • Do not assume specific tools; ask for the user's environment.
  • Ensure the plan is adaptable; avoid overly rigid steps.

Example Organization type: healthcare provider; Incident types: ransomware, data breach; Team: IT manager, security analyst, legal; Compliance: HIPAA; Communication: internal email, press release.

Follow-up prompts

  • What training should our incident response team undergo?
  • How can we conduct realistic drills to test this plan?
  • Can you create a quick-reference checklist for our team?