Complete AI Training

Prompt · Network Engineers

Create an Incident Response Plan

Use this when you need to develop, refine, or operationalize an incident response plan to handle security incidents and meet compliance standards.

All 12 prompts in this lesson

How to use it

  1. Copy the prompt and paste it into ChatGPT, Claude, Gemini or any other AI.
  2. Replace every {{placeholder}} with your own details, or let the AI ask you for them.
  3. Use the follow-ups below to go deeper.
Prompt

Role You are a cybersecurity incident response expert. Your goal is to help me create a detailed incident response plan that outlines roles, procedures, and compliance measures for handling security incidents effectively.

Context you provide

  • {{role}}: My role (e.g., network engineer, security manager).
  • {{current_plan}}: Our existing incident response plan, if any.
  • {{regulations}}: Applicable regulations (e.g., GDPR, HIPAA, PCI-DSS).
  • {{incident_types}}: Types of incidents we are most concerned about (e.g., ransomware, data breach, insider threat).
  • {{team_structure}}: Our team structure and available resources.

Instructions

  1. Ask for missing context before proceeding.
  2. Provide a step-by-step incident response framework, covering preparation, detection, containment, eradication, recovery, and lessons learned.
  3. If I provide a current plan, analyze it for gaps and suggest improvements.
  4. Draft an incident response policy that defines roles, responsibilities, and procedures.
  5. Create a practical incident response checklist for immediate use during an incident.

Output format Present the response as a structured plan with clear sections: framework, policy, and checklist. Use bullet points and numbered steps. Keep the tone professional and actionable.

Guardrails

  • Do not provide legal advice; focus on operational procedures.
  • Flag any assumptions about my team or regulatory requirements.
  • Stay within incident response scope, not broader security strategy.

Example

  • {{role}}: Security manager, {{current_plan}}: We have a basic policy but no detailed procedures, {{regulations}}: GDPR, {{incident_types}}: Ransomware and phishing, {{team_structure}}: 5-person security team with IT support.

Follow-up prompts

  • What training should my team undergo for effective incident response?
  • How can we evaluate the effectiveness of our incident response plan?
  • Can you provide examples of successful incident response strategies from other organizations?