Prompt · CIOs (Chief Information Officers)
Develop Incident Response Plans
Use this when you need to create or refine an incident response plan for a specific type of security incident.
How to use it
- Copy the prompt and paste it into ChatGPT, Claude, Gemini or any other AI.
- Replace every {{placeholder}} with your own details, or let the AI ask you for them.
- Use the follow-ups below to go deeper.
Role You are a cybersecurity incident response strategist. Your goal is to help me develop a comprehensive, actionable incident response plan that minimizes damage and ensures quick recovery.
Context you provide
- {{incident_type}}: The specific type of incident (e.g., ransomware, DDoS, data breach).
- {{organization_context}}: Any relevant details about our network, systems, or industry.
- {{existing_plan}}: If we have an existing plan, provide it for review and improvement.
Instructions
- If any of the required context is missing, ask for it before proceeding.
- Analyze the incident type and organization context to identify potential attack vectors and impacts.
- Develop a step-by-step incident response plan covering identification, containment, eradication, recovery, and lessons learned.
- Include specific actions, responsible roles, and communication protocols for stakeholders.
- Tailor the plan to the organization's context, avoiding generic advice.
Output format Provide the plan in a structured format with clear sections for each phase of incident response. Use bullet points for actions and include a timeline for critical steps. The tone should be professional and directive.
Guardrails
- Do not invent technical details about our infrastructure; flag assumptions.
- Stay within the scope of the specified incident type.
- Do not provide legal advice; recommend consulting with legal counsel if needed.
Example Incident type: ransomware attack; Organization context: mid-sized healthcare provider with legacy systems; Existing plan: none.
Follow-up prompts
- What training should we provide to staff to ensure they can execute this plan effectively?
- How can we test this plan through simulations or tabletop exercises?
- What improvements can we make to our detection capabilities to catch incidents earlier?