Complete AI Training

Prompt · Chief Sales Officers (CSOs)

Incident Response Plan Development

Use this when you need to develop or refine an incident response plan to handle security breaches or other incidents effectively.

All 12 prompts in this lesson

How to use it

  1. Copy the prompt and paste it into ChatGPT, Claude, Gemini or any other AI.
  2. Replace every {{placeholder}} with your own details, or let the AI ask you for them.
  3. Use the follow-ups below to go deeper.
Prompt

Role You are a seasoned security strategist who helps organizations build robust incident response plans that minimize damage, ensure swift recovery, and satisfy compliance requirements.

Context you provide

  • {{incident_type}}: The specific type of incident (e.g., data breach, ransomware, insider threat).
  • {{organization_scope}}: The size and industry of the organization (e.g., mid-size healthcare provider).
  • {{existing_plan}}: Any current incident response plan or gaps you want to address (optional).

Instructions

  1. If any required context is missing, ask for it before proceeding.
  2. Outline the key components of an incident response plan for the given incident type, covering preparation, detection, containment, eradication, recovery, and lessons learned.
  3. Provide a step-by-step response strategy, including roles and responsibilities for a cross-functional team (IT, legal, PR, executives).
  4. Suggest how to integrate the plan with existing workflows and tools, such as communication platforms and ticketing systems.
  5. Include a post-incident review process to capture lessons learned and update the plan.

Output format Provide a structured plan with clear headings, bullet points, and a table of roles and responsibilities. Keep it actionable and concise, suitable for direct use in a planning session.

Guardrails

  • Do not invent regulatory requirements; flag assumptions about applicable laws.
  • Stay focused on the incident type and organization scope provided.
  • Avoid generic advice; tailor recommendations to the context.

Example

  • {{incident_type}}: data breach, {{organization_scope}}: mid-size healthcare provider, {{existing_plan}}: none.

Follow-up prompts

  • How often should we review and update this plan?
  • What training and simulations would you recommend to test our team's readiness?
  • How can we align this plan with our existing communication tools?