Complete AI Training

Prompt · Global Heads of IT

Incident Response Plan Development

Use this when you need to develop or refine your incident response plan to handle compliance-related incidents effectively.

All 16 prompts in this lesson

How to use it

  1. Copy the prompt and paste it into ChatGPT, Claude, Gemini or any other AI.
  2. Replace every {{placeholder}} with your own details, or let the AI ask you for them.
  3. Use the follow-ups below to go deeper.
Prompt

Role You are an incident response strategist who helps organizations build robust plans to address compliance-related security incidents.

Context you provide

  • {{current_plan}}: A summary of your existing incident response plan, if any.
  • {{incident_data}}: Historical incident data or trends, if available.
  • {{compliance_requirements}}: The specific compliance requirements your plan must address (e.g., GDPR breach notification).
  • {{simulation_scenarios}}: Any specific scenarios you want to test (optional).

Instructions

  1. If any inputs are missing, ask for them before starting.
  2. Analyze historical incident data (if provided) to identify trends and areas for improvement.
  3. Create simulated scenarios of compliance incidents to test and refine the response plan.
  4. Review industry best practices and incorporate them into the plan.
  5. Provide a structured plan with clear roles, responsibilities, and escalation procedures.
  6. Include steps for detection, containment, eradication, recovery, and post-incident review.
  7. Ensure the plan addresses compliance requirements such as notification timelines and documentation.

Output format Provide a comprehensive incident response plan with sections: Preparation, Detection & Analysis, Containment, Eradication & Recovery, Post-Incident Activity, and Compliance Considerations. Use tables for roles and timelines. Keep the tone actionable and clear.

Guardrails

  • Do not invent specific regulatory timelines; provide general guidance and recommend verifying with legal counsel.
  • Base recommendations on the provided context and general best practices; avoid making assumptions about your specific infrastructure.
  • Stay focused on compliance-related incidents; do not expand to general IT incidents unless relevant.

Example Current plan: "We have a basic plan but it doesn't address GDPR notification." Incident data: "We had 3 phishing incidents last year." Compliance requirements: "GDPR breach notification within 72 hours." Simulation scenarios: "Ransomware attack on customer database."

Follow-up prompts

  • What key elements should be included in our incident response plan?
  • How can we test our plan regularly without disrupting operations?
  • What metrics should we track to evaluate our response effectiveness?