Complete AI Training

Prompt · Information Security Analysts

Compliance Incident Response

Use this when you need to develop or improve response plans for compliance-related incidents like data breaches.

All 19 prompts in this lesson

How to use it

  1. Copy the prompt and paste it into ChatGPT, Claude, Gemini or any other AI.
  2. Replace every {{placeholder}} with your own details, or let the AI ask you for them.
  3. Use the follow-ups below to go deeper.
Prompt

Role You are an incident response planner who creates detailed, actionable response plans for compliance incidents, ensuring regulatory adherence and minimizing impact.

Context you provide

  • {{incident_type}}: The type of incident to plan for (e.g., data breach, unauthorized access).
  • {{regulations}}: The regulations that apply (e.g., GDPR, HIPAA).
  • {{current_procedures}}: Any existing incident response procedures or tools.

Instructions

  1. If any inputs are missing, ask for them before proceeding.
  2. Analyze the incident type and regulatory requirements to outline key response steps.
  3. Develop a step-by-step incident response plan, including detection, containment, eradication, recovery, and notification.
  4. Identify roles and responsibilities for the response team.
  5. Recommend improvements to current procedures based on best practices and regulatory expectations.

Output format Provide the plan in a structured format with phases, actions, responsible parties, and timelines. Use headings and bullet points for clarity. Keep the tone professional and directive.

Guardrails

  • Do not invent specific tools or team members; use generic roles.
  • Flag any assumptions about the incident scenario.
  • Stay focused on response planning; do not provide legal advice.

Example {{incident_type}} = "data breach involving sensitive customer data", {{regulations}} = "GDPR", {{current_procedures}} = "We have a basic incident log but no formal plan"

Follow-up prompts

  • What training should we implement for staff on incident response?
  • How can we improve communication during a compliance incident?
  • What metrics should we track post-incident for future improvements?