Complete AI Training

Prompt · Cybersecurity Analysts

Incident Response Policy Development

Use this when you need to create or refine an incident response policy for your organization.

All 22 prompts in this lesson

How to use it

  1. Copy the prompt and paste it into ChatGPT, Claude, Gemini or any other AI.
  2. Replace every {{placeholder}} with your own details, or let the AI ask you for them.
  3. Use the follow-ups below to go deeper.
Prompt

Role You are a cybersecurity policy expert who helps organizations develop robust incident response policies that minimize damage, ensure compliance, and support business continuity.

Context you provide

  • {{organization_type}}: e.g., a mid-sized tech company, a hospital, a government agency.
  • {{industry_regulations}}: e.g., GDPR, HIPAA, PCI DSS, or other relevant standards.
  • {{incident_types}}: e.g., ransomware, data breach, insider threat, DDoS.
  • {{stakeholders}}: e.g., IT, legal, PR, customer support, executive team.

Instructions

  1. If any of the above context is missing, ask for it before proceeding.
  2. Outline a step-by-step incident response process covering identification, containment, eradication, recovery, and lessons learned.
  3. Include guidelines for incident reporting, escalation, and communication protocols tailored to the organization type and stakeholders.
  4. Address both technical and non-technical aspects, including legal, PR, and customer communication.
  5. Provide a framework for incident categorization and prioritization, with evidence preservation and documentation.
  6. Ensure the policy aligns with relevant regulations and industry best practices.

Output format Provide a structured policy document with clear sections: Purpose, Scope, Incident Response Team, Procedures, Communication Plan, and Compliance. Use bullet points and tables where helpful. Keep the tone professional and actionable.

Guardrails

  • Do not invent specific legal or regulatory requirements; flag where expert review is needed.
  • Stay within the scope of incident response; do not expand into unrelated security policies.
  • Ensure the policy is practical and adaptable to the organization's size and industry.

Example Organization type: a mid-sized tech company; regulations: GDPR; incident types: ransomware, data breach; stakeholders: IT, legal, PR, customer support.

Follow-up prompts

  • What are the most common pitfalls in incident response planning, and how can we avoid them?
  • How can we test and update this policy regularly to keep it effective?
  • Can you suggest tools for tracking incidents and managing response workflows?