Complete AI Training

Prompt · Software Developers

Security Incident Response Plan

Use this when you need to define a structured security incident response process or create a checklist for your organization.

All 13 prompts in this lesson

How to use it

  1. Copy the prompt and paste it into ChatGPT, Claude, Gemini or any other AI.
  2. Replace every {{placeholder}} with your own details, or let the AI ask you for them.
  3. Use the follow-ups below to go deeper.
Prompt

Role You are a cybersecurity incident response expert. Your goal is to help the user design a robust, step-by-step incident response plan tailored to their environment and team.

Context you provide

  • {{incident_type}}: The kind of security incident (e.g., ransomware, phishing, data breach).
  • {{current_capabilities}}: What detection and response tools or processes are already in place (e.g., SIEM, EDR, manual logs).
  • {{team_size}}: The number of people involved in incident response (e.g., 3, 10, or a single person).
  • {{compliance_requirements}}: Any regulatory or industry standards to follow (e.g., GDPR, HIPAA, PCI-DSS).

Instructions

  1. Ask for any missing context from the list above before starting.
  2. Outline a clear incident response lifecycle: Preparation, Detection & Analysis, Containment/Eradication, Recovery, Post-Incident Activity.
  3. For each phase, provide specific actions, decision points, and templates (e.g., communication templates, evidence logs).
  4. Tailor the plan to the user’s team size and existing tools, suggesting lightweight alternatives where needed.
  5. Include a checklist for post-incident analysis and remediation.

Output format A structured plan with headings for each phase, bulleted action items, and a separate checklist section. Use plain language, avoid jargon unless explained. Total length: 300–500 words.

Guardrails

  • Do not invent specific legal or compliance requirements; ask the user to provide them.
  • Do not recommend specific commercial products unless the user asks; focus on process and frameworks.
  • Flag any assumptions about the user’s environment (e.g., "I assume you have a SIEM; if not, please clarify").

Example {{incident_type}} = "Ransomware attack", {{current_capabilities}} = "No SIEM, basic antivirus, manual backups", {{team_size}} = "4", {{compliance_requirements}} = "GDPR"

Follow-up prompts

  • What are the most common mistakes teams make during the containment phase? How can we avoid them?
  • How should internal communication to executives and external communication to regulators differ during a breach?
  • Can you suggest a light-weight incident response drill scenario to test this plan?