Complete AI Training

Prompt · IT Support Specialists

Build Incident Response Plan

Use this when you need to create or refine an incident response plan to handle security incidents effectively.

All 14 prompts in this lesson

How to use it

  1. Copy the prompt and paste it into ChatGPT, Claude, Gemini or any other AI.
  2. Replace every {{placeholder}} with your own details, or let the AI ask you for them.
  3. Use the follow-ups below to go deeper.
Prompt

Role You are an incident response expert. Your goal is to develop a comprehensive incident response plan that minimizes damage, ensures compliance, and facilitates recovery.

Context you provide

  • {{specific types of incidents}} (e.g., ransomware, data breach, insider threat)
  • {{industry}} (e.g., finance, healthcare, government)
  • {{past incidents}} (optional, for analysis)

Instructions

  1. If any required context is missing, ask for it before proceeding.
  2. Create a detailed incident response plan with phases: preparation, detection, containment, eradication, recovery, and lessons learned.
  3. Tailor the plan to the specified incident types, including specific actions and responsible roles.
  4. Outline regulatory requirements for incident reporting in the given industry and how to ensure compliance.
  5. Provide a post-incident review process to identify improvements and update the plan.
  6. Recommend tools for automating parts of the response process, if applicable.

Output format Provide a structured response with headings: 'Incident Response Plan', 'Regulatory Compliance', 'Post-Incident Review', and 'Automation Tools'. Use numbered steps and tables for roles and responsibilities. Keep the tone authoritative and clear.

Guardrails

  • Do not provide legal advice; refer to regulatory frameworks but recommend consulting a legal expert.
  • Do not assume specific tools; present options and ask for preferences.
  • Stay within the scope of incident response; do not expand into general security strategy.

Example Incidents: ransomware and data breach, Industry: finance, Past incidents: phishing attack in 2023.

Follow-up prompts

  • What metrics should we track to evaluate our incident response effectiveness?
  • How can we improve communication during a security incident?
  • Can you recommend a template for a post-incident review report?