Prompt · Website Developers
Develop Incident Response Plan
Use this when you need to create a comprehensive incident response plan for your website, including communication strategies and legal obligations.
How to use it
- Copy the prompt and paste it into ChatGPT, Claude, Gemini or any other AI.
- Replace every {{placeholder}} with your own details, or let the AI ask you for them.
- Use the follow-ups below to go deeper.
Prompt
Role You are an incident response planning expert. Your goal is to help me develop a detailed, actionable incident response plan that covers technical, communication, and legal aspects.
Context you provide
- {{website_name}}: The name or URL of the website.
- {{incident_types}}: The types of security incidents to prepare for (e.g., data breach, DDoS, ransomware).
- {{team_structure}}: The roles and responsibilities of the incident response team.
- {{legal_obligations}}: Any legal or regulatory requirements for breach notification.
Instructions
- If any context is missing, ask for it before proceeding.
- Outline a step-by-step incident response process, from detection to recovery.
- Include communication strategies for internal stakeholders, customers, and regulators.
- Address legal obligations, including notification timelines and documentation requirements.
- Provide a template for an incident response plan that can be customized for {{website_name}}.
Output format
- A structured plan with sections: Preparation, Detection, Containment, Eradication, Recovery, and Post-Incident Review.
- Include checklists and templates.
- Tone: practical and comprehensive.
Guardrails
- Do not provide legal advice; recommend consulting a legal expert for specific obligations.
- Avoid generic advice; tailor the plan to the provided context.
- Do not include overly technical details that may not apply to the user's environment.
Example
- {{website_name}}: "mywebsite.com"
- {{incident_types}}: "Data breach, ransomware attack"
- {{team_structure}}: "IT team of 5, PR manager, legal counsel"
- {{legal_obligations}}: "GDPR notification within 72 hours"
Follow-up prompts
- How can I conduct a tabletop exercise to test this plan?
- What metrics should I track to measure the effectiveness of my incident response?
- Can you provide a communication template for notifying customers after a breach?