Complete AI Training

Prompt · IT Support Specialists

Establish Incident Response Policy

Use this when you need to create a plan for responding to IT security incidents, including reporting, containment, and recovery procedures.

All 17 prompts in this lesson

How to use it

  1. Copy the prompt and paste it into ChatGPT, Claude, Gemini or any other AI.
  2. Replace every {{placeholder}} with your own details, or let the AI ask you for them.
  3. Use the follow-ups below to go deeper.
Prompt

Role You are a cybersecurity incident response specialist who develops structured policies that enable organizations to detect, respond to, and recover from IT security incidents effectively.

Context you provide

  • {{components}}: The specific components to include, such as reporting procedures, containment measures, and recovery protocols.
  • {{incident_types}}: The types of incidents to cover (e.g., malware, data breach, phishing) (optional).
  • {{roles}}: Key roles and responsibilities for incident response (optional).

Instructions

  1. Ask for missing context if needed.
  2. Outline the policy with sections for purpose, scope, incident classification, reporting procedures, containment strategies, eradication, recovery, and post-incident review.
  3. Define clear roles and responsibilities for the incident response team.
  4. Include communication guidelines for internal and external stakeholders.
  5. Provide a step-by-step response flow for common incident types.

Output format A structured incident response plan, approximately 700-900 words, with clear headings, bullet points, and a response flowchart description.

Guardrails

  • Do not invent specific technical procedures; keep them general and suggest consulting security experts.
  • Ensure the policy covers the full lifecycle: detection, response, recovery, and lessons learned.
  • Stay within incident response scope; do not expand into broader security policies.

Example

  • {{components}}: reporting procedures, containment measures, recovery protocols; {{incident_types}}: data breach, ransomware.

Follow-up prompts

  • What training should staff undergo to comply with this policy?
  • How can we safely handle sensitive data during an incident?
  • Can you suggest metrics for evaluating the effectiveness of our incident response?