Prompt · IT Managers
Create Incident Response Plan
Use this when you need to develop a comprehensive incident response plan that outlines steps to handle security breaches or IT incidents.
How to use it
- Copy the prompt and paste it into ChatGPT, Claude, Gemini or any other AI.
- Replace every {{placeholder}} with your own details, or let the AI ask you for them.
- Use the follow-ups below to go deeper.
Prompt
Role You are a cybersecurity incident response expert. Your goal is to create a detailed, actionable incident response plan that minimizes damage and ensures compliance.
Context you provide
- {{organization_type}}: e.g., financial services, healthcare, tech company.
- {{incident_types}}: types of incidents to cover (e.g., malware, data breach, insider threat).
- {{team_structure}}: existing IT/security team roles and responsibilities.
- {{compliance_needs}}: legal or regulatory requirements (e.g., GDPR, HIPAA).
- {{communication_protocol}}: how internal and external communications should be handled.
Instructions
- Ask for missing context about the organization and team.
- Outline the incident response lifecycle: preparation, detection, containment, eradication, recovery, and lessons learned.
- Define roles and responsibilities for each phase, including a designated incident commander.
- Include specific procedures for each incident type, with clear decision points.
- Address legal and compliance requirements, such as breach notification timelines.
- Provide templates for documentation, including incident logs and post-incident reviews.
Output format A structured plan with phases, roles, and procedures. Use headings, bullet points, and checklists. Length: 1200-1800 words. Tone: professional and precise.
Guardrails
- Do not provide legal advice; recommend consulting legal counsel.
- Do not assume specific tools; ask for the user's environment.
- Ensure the plan is adaptable; avoid overly rigid steps.
Example Organization type: healthcare provider; Incident types: ransomware, data breach; Team: IT manager, security analyst, legal; Compliance: HIPAA; Communication: internal email, press release.
Follow-up prompts
- What training should our incident response team undergo?
- How can we conduct realistic drills to test this plan?
- Can you create a quick-reference checklist for our team?