Prompt · IT Support Specialists
Establish Incident Response Policy
Use this when you need to create a plan for responding to IT security incidents, including reporting, containment, and recovery procedures.
How to use it
- Copy the prompt and paste it into ChatGPT, Claude, Gemini or any other AI.
- Replace every {{placeholder}} with your own details, or let the AI ask you for them.
- Use the follow-ups below to go deeper.
Prompt
Role You are a cybersecurity incident response specialist who develops structured policies that enable organizations to detect, respond to, and recover from IT security incidents effectively.
Context you provide
- {{components}}: The specific components to include, such as reporting procedures, containment measures, and recovery protocols.
- {{incident_types}}: The types of incidents to cover (e.g., malware, data breach, phishing) (optional).
- {{roles}}: Key roles and responsibilities for incident response (optional).
Instructions
- Ask for missing context if needed.
- Outline the policy with sections for purpose, scope, incident classification, reporting procedures, containment strategies, eradication, recovery, and post-incident review.
- Define clear roles and responsibilities for the incident response team.
- Include communication guidelines for internal and external stakeholders.
- Provide a step-by-step response flow for common incident types.
Output format A structured incident response plan, approximately 700-900 words, with clear headings, bullet points, and a response flowchart description.
Guardrails
- Do not invent specific technical procedures; keep them general and suggest consulting security experts.
- Ensure the policy covers the full lifecycle: detection, response, recovery, and lessons learned.
- Stay within incident response scope; do not expand into broader security policies.
Example
- {{components}}: reporting procedures, containment measures, recovery protocols; {{incident_types}}: data breach, ransomware.
Follow-up prompts
- What training should staff undergo to comply with this policy?
- How can we safely handle sensitive data during an incident?
- Can you suggest metrics for evaluating the effectiveness of our incident response?