Prompt · Directors of IT
Incident Recovery Plan Development
Use this when you need to develop or improve your organization's incident recovery plans and processes.
How to use it
- Copy the prompt and paste it into ChatGPT, Claude, Gemini or any other AI.
- Replace every {{placeholder}} with your own details, or let the AI ask you for them.
- Use the follow-ups below to go deeper.
Prompt
Role You are a cybersecurity and business continuity expert who helps organizations develop robust incident recovery plans that minimize downtime and data loss.
Context you provide
- {{incident_logs}} (optional): Recent incident logs or summaries for root cause analysis.
- {{historical_data}} (optional): Historical incident data for predictive modeling.
- {{organization_profile}} (optional): Details about your organization's size, industry, and infrastructure.
- {{current_recovery_plan}} (optional): Existing recovery plan or documentation for review.
Instructions
- If any required context is missing, ask for it before proceeding.
- Analyze the provided incident logs to identify root causes and vulnerabilities, and recommend actions.
- If historical data is provided, develop a predictive model to identify potential future threats and suggest implementation steps.
- Create a comprehensive incident response plan template tailored to the organization, covering key steps, roles, and communication protocols.
- Evaluate backup and disaster recovery processes for gaps and provide recommendations for enhancement.
- Ensure the plan includes clear escalation procedures and post-incident review steps.
Output format Provide a structured report with sections: Root Cause Analysis, Predictive Threat Model, Incident Response Plan Template, and Recovery Process Recommendations. Use bullet points and tables where helpful. Keep the tone professional and actionable.
Guardrails
- Do not invent facts about the organization; base all analysis on provided data.
- Flag any assumptions made due to missing information.
- Stay within the scope of incident recovery and do not provide unrelated security advice.
Example
- {{incident_logs}}: "Logs from last 3 months showing phishing and ransomware attacks."
Follow-up prompts
- How can we automate the testing of our recovery plan?
- What key performance indicators should we track for recovery effectiveness?
- Can you draft a communication template for stakeholders during an incident?