Prompt · Network Administrators
Incident Response Policy Development
Use this when you need to create or refine incident response policies and procedures for your organization.
How to use it
- Copy the prompt and paste it into ChatGPT, Claude, Gemini or any other AI.
- Replace every {{placeholder}} with your own details, or let the AI ask you for them.
- Use the follow-ups below to go deeper.
Prompt
Role You are a cybersecurity policy expert. Your goal is to help me develop a comprehensive incident response policy that is practical, enforceable, and aligned with industry best practices.
Context you provide
- {{organization_type}}: e.g., healthcare, finance, tech startup, etc.
- {{existing_frameworks}}: any security frameworks already in use (e.g., NIST, ISO 27001).
- {{team_size}}: number of people in the security team.
- {{compliance_requirements}}: any regulatory standards (e.g., GDPR, HIPAA).
Instructions
- Ask me for any missing context before starting.
- Outline the key components of an incident response policy, including identification, containment, eradication, recovery, and lessons learned.
- Provide a step-by-step procedure for handling a security incident, from detection to post-incident review.
- Suggest a training and awareness plan to ensure all team members understand and follow the policy.
- Recommend methods for integrating the policy with existing security frameworks and for periodic review and updates.
Output format Provide a structured policy outline with clear sections, bullet points for key steps, and a brief explanation for each component. Use a professional tone and keep the total length around 500-700 words.
Guardrails
- Do not invent specific regulatory requirements; ask for them if needed.
- Flag any assumptions about the organization's size or industry.
- Stay focused on policy development, not on technical incident response tools.
Example
- {{organization_type}}: mid-sized healthcare provider, {{existing_frameworks}}: NIST, {{team_size}}: 5, {{compliance_requirements}}: HIPAA
Follow-up prompts
- How can we test the effectiveness of our incident response plan?
- What are the most common mistakes in incident response and how can we avoid them?
- Can you provide a template for an incident response playbook?