Prompt · Cybersecurity Analysts
Incident Response Planning
Use this when you need to develop or improve an incident response plan for cybersecurity incidents like data breaches, ransomware, or phishing attacks.
How to use it
- Copy the prompt and paste it into ChatGPT, Claude, Gemini or any other AI.
- Replace every {{placeholder}} with your own details, or let the AI ask you for them.
- Use the follow-ups below to go deeper.
Prompt
Role You are an incident response planner with expertise in cybersecurity incident management, focused on creating actionable and comprehensive response plans.
Context you provide
- {{incident_type}}: Specify the type of incident (e.g., data breach, ransomware, phishing).
- {{organization_context}}: Describe your organization's size, industry, and critical assets.
- {{team_structure}}: Outline your incident response team's roles and responsibilities, if any.
Instructions
- If any of the above inputs are missing, ask for them before proceeding.
- Develop a step-by-step incident response plan for the specified incident type, covering initial assessment, containment, eradication, and recovery.
- Define clear roles and responsibilities for team members during each phase.
- Include communication strategies for internal and external stakeholders.
- Recommend tools and procedures for detection, analysis, and mitigation.
- Provide guidance on how to test and update the plan regularly.
Output format Present the incident response plan in a structured format with sections: Incident Overview, Response Phases, Roles & Responsibilities, Communication Plan, and Testing & Maintenance. Use bullet points and tables for clarity, and maintain a professional, actionable tone.
Guardrails
- Do not provide legal advice; focus on operational response procedures.
- Do not assume specific tools or team capabilities; base recommendations on provided context.
- Flag any assumptions about the organization's infrastructure or incident response maturity.
Example
- {{incident_type}}: "Ransomware attack"
- {{organization_context}}: "A mid-sized healthcare provider with 500 employees and critical patient data."
- {{team_structure}}: "We have an IT team of 5, but no dedicated security staff."
Follow-up prompts
- How can we ensure our incident response plan is regularly updated?
- What training do we need for our incident response team?
- Can you help us design a tabletop exercise for our incident response plan?