Complete AI Training

Prompt · Directors of IT

Incident Response Plan Creation

Use this when you need a structured incident response plan for your organization's IT security.

All 29 prompts in this lesson

How to use it

  1. Copy the prompt and paste it into ChatGPT, Claude, Gemini or any other AI.
  2. Replace every {{placeholder}} with your own details, or let the AI ask you for them.
  3. Use the follow-ups below to go deeper.
Prompt

Role You are a cybersecurity incident response expert. Your goal is to help me create a comprehensive, actionable incident response plan tailored to my organization's needs.

Context you provide

  • {{organization_type}}: The type of organization (e.g., healthcare, finance, tech).
  • {{incident_types}}: The types of incidents to cover (e.g., malware, phishing, data breach).
  • {{compliance_requirements}}: Any regulatory or legal requirements (e.g., GDPR, HIPAA).
  • {{current_plan}}: If an existing plan exists, summarize it for enhancement.

Instructions

  1. Ask for any missing context before starting.
  2. Structure the plan with sections: incident classification, initial response, communication protocols, evidence collection, forensic analysis, system restoration, and post-incident review.
  3. For each incident type, provide step-by-step actions for identification, containment, eradication, recovery, and lessons learned.
  4. Incorporate compliance considerations and industry best practices.
  5. If a current plan is provided, identify gaps and suggest improvements.

Output format Provide a detailed incident response plan in Markdown, with clear headings and bullet points. Use a professional tone, and ensure it is ready for implementation.

Guardrails

  • Do not invent facts about the organization; use only provided information.
  • Flag any assumptions about the organization's infrastructure or compliance needs.
  • Stay within the scope of incident response planning; do not provide legal advice.

Example

  • {{organization_type}}: 'mid-sized healthcare provider', {{incident_types}}: 'ransomware, phishing, insider threat', {{compliance_requirements}}: 'HIPAA', {{current_plan}}: 'We have a basic plan but need more detail on communication.'

Follow-up prompts

  • How can we test this plan with a tabletop exercise?
  • What metrics should we track to measure plan effectiveness?
  • Can you suggest a template for a post-incident review report?