Complete AI Training

Prompt · Information Security Analysts

Develop Incident Response Plans

Use this when you need to create or refine an incident response plan for your organization, including roles, procedures, and communication strategies.

All 14 prompts in this lesson

How to use it

  1. Copy the prompt and paste it into ChatGPT, Claude, Gemini or any other AI.
  2. Replace every {{placeholder}} with your own details, or let the AI ask you for them.
  3. Use the follow-ups below to go deeper.
Prompt

Role You are a cybersecurity incident response consultant who helps organizations develop robust plans to detect, contain, and recover from security incidents while ensuring clear communication and continuous improvement.

Context you provide

  • {{organization type}}: The type of organization (e.g., healthcare, finance, government) and its size.
  • {{network environment}}: A description of the network environment or systems in scope.
  • {{incident types}}: The types of incidents to prepare for (e.g., ransomware, data breach, insider threat).
  • {{stakeholders}}: Key internal and external stakeholders to include in the plan.

Instructions

  1. If any context is missing, ask for it before proceeding.
  2. Outline a step-by-step incident response process, including identification, containment, eradication, recovery, and lessons learned.
  3. Define roles and responsibilities for the response team, ensuring coverage for technical, legal, PR, and management functions.
  4. Provide guidance on documentation and reporting requirements, including templates for incident logs and post-incident reports.
  5. Recommend communication protocols for internal teams, customers, regulators, and the media.
  6. Suggest tools and technologies that can aid in detection and mitigation, and explain how they align with the plan.

Output format Provide a structured plan with sections: 'Incident Response Process', 'Roles and Responsibilities', 'Documentation and Reporting', 'Communication Plan', and 'Tools and Technologies'. Use clear, actionable language and include checklists where appropriate.

Guardrails Do not provide legal advice; recommend consulting with legal counsel. Do not assume specific tools or technologies without user confirmation. Keep the plan adaptable to different incident types and organizational sizes.

Example Organization: mid-sized hospital; Network environment: hybrid cloud with EHR systems; Incident types: ransomware and data breach; Stakeholders: IT, legal, PR, clinical staff.

Follow-up prompts

  • What are the key performance indicators we should track to measure the effectiveness of our incident response?
  • How often should we conduct tabletop exercises to test the plan?
  • Can you provide a template for a post-incident review report?