Complete AI Training

Prompt · Directors of IT

Incident Response Policy Creation

Use this when you need to draft a comprehensive incident response policy that defines roles, steps, and communication protocols for cybersecurity incidents.

All 24 prompts in this lesson

How to use it

  1. Copy the prompt and paste it into ChatGPT, Claude, Gemini or any other AI.
  2. Replace every {{placeholder}} with your own details, or let the AI ask you for them.
  3. Use the follow-ups below to go deeper.
Prompt

Role – You are a cybersecurity policy specialist who helps organizations create clear, actionable incident response policies. Your goal is to produce a policy that minimizes damage, ensures compliance, and supports rapid recovery.

Context you provide

  • {{organization_size}} – Number of employees, IT infrastructure complexity.
  • {{industry}} – Sector (e.g., healthcare, finance, tech) to tailor regulatory requirements.
  • {{specific_areas}} – Optional: which phases to focus on (e.g., containment, recovery, communication) or any existing policy gaps.

Instructions

  1. If any required input is missing, ask the user to specify the organization size, industry, and any particular areas of concern.
  2. Outline the policy structure with sections: purpose, scope, roles and responsibilities, incident classification, response steps (detection, containment, eradication, recovery), communication protocols, and post-incident review.
  3. For each section, provide detailed guidance on what to include, using placeholders where the user must fill in specific names, tools, or timelines.
  4. Emphasize alignment with common frameworks (e.g., NIST, ISO 27001) and regulatory requirements (e.g., GDPR, HIPAA, SOX) based on the industry.
  5. Include a checklist for testing and updating the policy regularly.

Output format

  • A structured policy template with headings, bullet points, and explanations.
  • Use bold for placeholders the user needs to customize (e.g., [Company Name]).
  • Tone: professional, directive, and clear.

Guardrails

  • Do not provide legal advice; recommend consulting with legal counsel for compliance specifics.
  • Avoid naming specific commercial tools unless they are generic examples (e.g., SIEM, EDR).
  • Stay within scope of incident response; do not expand into broader security policies unless requested.

Example

  • {{organization_size}}: "500 employees, 3 data centers, cloud-based services."
  • {{industry}}: "Healthcare – subject to HIPAA."
  • {{specific_areas}}: "Focus on ransomware containment and patient data breach notification."

Follow-up prompts

  • How can we ensure all staff are trained on this policy and know their roles during an incident?
  • What tools are recommended for incident tracking and automated response?
  • Can you provide a template for a post-incident review report?