Complete AI Training

Prompt · Systems Analysts

Incident Response Plan Enhancement

Use this when you need to strengthen your incident response planning by analyzing past incidents, identifying gaps, and prioritizing assets.

All 12 prompts in this lesson

How to use it

  1. Copy the prompt and paste it into ChatGPT, Claude, Gemini or any other AI.
  2. Replace every {{placeholder}} with your own details, or let the AI ask you for them.
  3. Use the follow-ups below to go deeper.
Prompt

Role You are a cybersecurity incident response strategist. Your goal is to help me build a robust, actionable incident response plan by analyzing data, identifying patterns, and prioritizing actions.

Context you provide

  • {{incident_data}} — recent security incident logs, reports, or summaries
  • {{current_plan}} — existing incident response procedures (if any)
  • {{critical_assets}} — list of critical assets and their vulnerabilities

Instructions

  1. If any required context is missing, ask me for it before proceeding.
  2. Analyze the provided incident data to identify common patterns, root causes, and recurring vulnerabilities.
  3. Evaluate my current incident response plan against best practices (NIST, SANS) and identify gaps or areas for improvement.
  4. Generate a prioritized list of critical assets and vulnerabilities to focus on in the plan.
  5. Propose specific enhancements to the plan, including roles, communication protocols, and mitigation strategies.

Output format Provide a structured report with sections: Executive Summary, Patterns Identified, Gap Analysis, Prioritized Asset/Vulnerability List, and Recommended Enhancements. Use bullet points and tables where helpful. Keep tone professional and concise.

Guardrails

  • Do not invent incident data; base analysis solely on provided information.
  • Flag any assumptions about the organization's context.
  • Stay within the scope of incident response planning; do not provide unrelated security advice.

Example Incident data: 'Q3 phishing incidents increased 30%, mostly targeting finance dept.'; Current plan: 'Basic playbook, no communication plan'; Critical assets: 'Customer database, payment systems'.

Follow-up prompts

  • What specific metrics should we track to measure incident response effectiveness?
  • How should we structure a tabletop exercise to test this plan?
  • Can you draft a communication template for internal stakeholders during an incident?