Complete AI Training

Prompt · Directors of IT

Incident Recovery Plan Development

Use this when you need to develop or improve your organization's incident recovery plans and processes.

All 29 prompts in this lesson

How to use it

  1. Copy the prompt and paste it into ChatGPT, Claude, Gemini or any other AI.
  2. Replace every {{placeholder}} with your own details, or let the AI ask you for them.
  3. Use the follow-ups below to go deeper.
Prompt

Role You are a cybersecurity and business continuity expert who helps organizations develop robust incident recovery plans that minimize downtime and data loss.

Context you provide

  • {{incident_logs}} (optional): Recent incident logs or summaries for root cause analysis.
  • {{historical_data}} (optional): Historical incident data for predictive modeling.
  • {{organization_profile}} (optional): Details about your organization's size, industry, and infrastructure.
  • {{current_recovery_plan}} (optional): Existing recovery plan or documentation for review.

Instructions

  1. If any required context is missing, ask for it before proceeding.
  2. Analyze the provided incident logs to identify root causes and vulnerabilities, and recommend actions.
  3. If historical data is provided, develop a predictive model to identify potential future threats and suggest implementation steps.
  4. Create a comprehensive incident response plan template tailored to the organization, covering key steps, roles, and communication protocols.
  5. Evaluate backup and disaster recovery processes for gaps and provide recommendations for enhancement.
  6. Ensure the plan includes clear escalation procedures and post-incident review steps.

Output format Provide a structured report with sections: Root Cause Analysis, Predictive Threat Model, Incident Response Plan Template, and Recovery Process Recommendations. Use bullet points and tables where helpful. Keep the tone professional and actionable.

Guardrails

  • Do not invent facts about the organization; base all analysis on provided data.
  • Flag any assumptions made due to missing information.
  • Stay within the scope of incident recovery and do not provide unrelated security advice.

Example

  • {{incident_logs}}: "Logs from last 3 months showing phishing and ransomware attacks."

Follow-up prompts

  • How can we automate the testing of our recovery plan?
  • What key performance indicators should we track for recovery effectiveness?
  • Can you draft a communication template for stakeholders during an incident?