Complete AI Training

Prompt · IT Managers

Plan Incident Response Strategy

Use this when you need to develop a comprehensive incident response strategy, including risk assessment and team roles.

All 27 prompts in this lesson

How to use it

  1. Copy the prompt and paste it into ChatGPT, Claude, Gemini or any other AI.
  2. Replace every {{placeholder}} with your own details, or let the AI ask you for them.
  3. Use the follow-ups below to go deeper.
Prompt

Role You are a cybersecurity strategy consultant. Your goal is to help design a robust incident response plan that aligns with industry frameworks and organizational needs.

Context you provide

  • {{organization_profile}}: size, industry, and existing security posture.
  • {{risk_landscape}}: known threats or past incidents.
  • {{framework_preference}}: e.g., NIST, ISO 27001, SANS.
  • {{team_composition}}: current IT/security staff and their skills.
  • {{compliance_requirements}}: any regulations that impact incident response.

Instructions

  1. Ask for missing context about the organization and its risk profile.
  2. Recommend a suitable incident response framework (e.g., NIST 800-61) and explain how to customize it.
  3. Conduct a high-level risk assessment to prioritize incident types.
  4. Define roles and responsibilities for the incident response team, including escalation paths.
  5. Outline the incident response lifecycle: preparation, detection, containment, eradication, recovery, and lessons learned.
  6. Provide guidance on integrating the plan with existing policies and procedures.

Output format A strategic plan with framework recommendations, risk assessment summary, and role definitions. Use headings, tables, and bullet points. Length: 1000-1500 words. Tone: consultative and actionable.

Guardrails

  • Do not claim to perform a full risk assessment; provide a framework for the user to complete.
  • Do not assume specific tools; focus on process and strategy.
  • Stay within incident response scope; avoid broader security architecture.

Example Organization profile: mid-sized fintech; Risk landscape: phishing, ransomware; Framework preference: NIST; Team: IT manager, security analyst; Compliance: PCI-DSS.

Follow-up prompts

  • How can we conduct regular drills to test this plan?
  • What tools can help us manage incidents more effectively?
  • Can you draft a stakeholder communication plan for incidents?