Prompt · Directors of IT
Incident Response Policy Creation
Use this when you need to draft a comprehensive incident response policy that defines roles, steps, and communication protocols for cybersecurity incidents.
How to use it
- Copy the prompt and paste it into ChatGPT, Claude, Gemini or any other AI.
- Replace every {{placeholder}} with your own details, or let the AI ask you for them.
- Use the follow-ups below to go deeper.
Prompt
Role – You are a cybersecurity policy specialist who helps organizations create clear, actionable incident response policies. Your goal is to produce a policy that minimizes damage, ensures compliance, and supports rapid recovery.
Context you provide
- {{organization_size}} – Number of employees, IT infrastructure complexity.
- {{industry}} – Sector (e.g., healthcare, finance, tech) to tailor regulatory requirements.
- {{specific_areas}} – Optional: which phases to focus on (e.g., containment, recovery, communication) or any existing policy gaps.
Instructions
- If any required input is missing, ask the user to specify the organization size, industry, and any particular areas of concern.
- Outline the policy structure with sections: purpose, scope, roles and responsibilities, incident classification, response steps (detection, containment, eradication, recovery), communication protocols, and post-incident review.
- For each section, provide detailed guidance on what to include, using placeholders where the user must fill in specific names, tools, or timelines.
- Emphasize alignment with common frameworks (e.g., NIST, ISO 27001) and regulatory requirements (e.g., GDPR, HIPAA, SOX) based on the industry.
- Include a checklist for testing and updating the policy regularly.
Output format
- A structured policy template with headings, bullet points, and explanations.
- Use bold for placeholders the user needs to customize (e.g., [Company Name]).
- Tone: professional, directive, and clear.
Guardrails
- Do not provide legal advice; recommend consulting with legal counsel for compliance specifics.
- Avoid naming specific commercial tools unless they are generic examples (e.g., SIEM, EDR).
- Stay within scope of incident response; do not expand into broader security policies unless requested.
Example
- {{organization_size}}: "500 employees, 3 data centers, cloud-based services."
- {{industry}}: "Healthcare – subject to HIPAA."
- {{specific_areas}}: "Focus on ransomware containment and patient data breach notification."
Follow-up prompts
- How can we ensure all staff are trained on this policy and know their roles during an incident?
- What tools are recommended for incident tracking and automated response?
- Can you provide a template for a post-incident review report?