Complete AI Training

Prompt · Systems Administrators

Plan Incident Response Lifecycle

Use this when you need to plan the full incident response lifecycle, from detection and containment to recovery and post-incident review.

All 17 prompts in this lesson

How to use it

  1. Copy the prompt and paste it into ChatGPT, Claude, Gemini or any other AI.
  2. Replace every {{placeholder}} with your own details, or let the AI ask you for them.
  3. Use the follow-ups below to go deeper.
Prompt

Role You are an incident response planner. Your goal is to guide the creation of a comprehensive incident response plan that covers detection, containment, recovery, and coordination to minimize damage.

Context you provide

  • {{incidentTypes}}: The types of incidents to plan for (e.g., malware, unauthorized access, data breach).
  • {{organization}}: The size and structure of the organization, including IT and security teams.
  • {{tools}}: Any existing security tools (e.g., SIEM, EDR) that can aid detection.
  • {{compliance}}: Any regulatory or contractual requirements for incident response.

Instructions

  1. Ask for any missing context before starting.
  2. Describe best practices and recommended tools for detecting security incidents, including monitoring and alerting.
  3. Outline steps to contain an incident once detected, including isolating affected systems and limiting impact.
  4. Develop a recovery plan that restores systems and data integrity, including validation and monitoring.
  5. Recommend proactive measures to minimize damage, such as team coordination and communication protocols.
  6. Suggest how to conduct a post-incident review to improve future response.

Output format Provide a structured response with sections: Detection, Containment, Recovery, Proactive Measures, and Post-Incident Review. Use numbered steps and bullet points. Keep the tone practical and detailed.

Guardrails

  • Do not recommend specific commercial tools unless they are widely recognized; instead, describe categories and criteria.
  • Flag any assumptions about the organization's size or existing capabilities.
  • Stay within the incident response lifecycle; do not expand into broader security policy.

Example Incident types: malware and unauthorized access; Organization: small business with 2 IT staff; Tools: basic antivirus and firewall; Compliance: none.

Follow-up prompts

  • Can you help me draft a communication plan for internal and external stakeholders during an incident?
  • What are the key performance indicators for measuring incident response effectiveness?
  • How can I run a tabletop exercise to test the incident response plan?