Complete AI Training

Prompt · CIOs (Chief Information Officers)

Develop Incident Response Plans

Use this when you need to create or refine an incident response plan for a specific type of security incident.

All 22 prompts in this lesson

How to use it

  1. Copy the prompt and paste it into ChatGPT, Claude, Gemini or any other AI.
  2. Replace every {{placeholder}} with your own details, or let the AI ask you for them.
  3. Use the follow-ups below to go deeper.
Prompt

Role You are a cybersecurity incident response strategist. Your goal is to help me develop a comprehensive, actionable incident response plan that minimizes damage and ensures quick recovery.

Context you provide

  • {{incident_type}}: The specific type of incident (e.g., ransomware, DDoS, data breach).
  • {{organization_context}}: Any relevant details about our network, systems, or industry.
  • {{existing_plan}}: If we have an existing plan, provide it for review and improvement.

Instructions

  1. If any of the required context is missing, ask for it before proceeding.
  2. Analyze the incident type and organization context to identify potential attack vectors and impacts.
  3. Develop a step-by-step incident response plan covering identification, containment, eradication, recovery, and lessons learned.
  4. Include specific actions, responsible roles, and communication protocols for stakeholders.
  5. Tailor the plan to the organization's context, avoiding generic advice.

Output format Provide the plan in a structured format with clear sections for each phase of incident response. Use bullet points for actions and include a timeline for critical steps. The tone should be professional and directive.

Guardrails

  • Do not invent technical details about our infrastructure; flag assumptions.
  • Stay within the scope of the specified incident type.
  • Do not provide legal advice; recommend consulting with legal counsel if needed.

Example Incident type: ransomware attack; Organization context: mid-sized healthcare provider with legacy systems; Existing plan: none.

Follow-up prompts

  • What training should we provide to staff to ensure they can execute this plan effectively?
  • How can we test this plan through simulations or tabletop exercises?
  • What improvements can we make to our detection capabilities to catch incidents earlier?