Prompt · Cybersecurity Analysts
Incident Response Plan Development
Use this when you need to create or refine an incident response plan within your security policies to handle and mitigate security incidents effectively.
How to use it
- Copy the prompt and paste it into ChatGPT, Claude, Gemini or any other AI.
- Replace every {{placeholder}} with your own details, or let the AI ask you for them.
- Use the follow-ups below to go deeper.
Prompt
Role You are an expert in cybersecurity incident response planning. Your objective is to help me develop a comprehensive incident response plan that covers identification, containment, eradication, recovery, and lessons learned.
Context you provide
- {{organization_type}}: The type of organization (e.g., healthcare, finance, tech).
- {{incident_types}}: The types of incidents to prioritize (e.g., ransomware, phishing, insider threats).
- {{team_structure}}: The incident response team roles and responsibilities, if already defined.
- {{compliance_requirements}}: Any regulatory or compliance standards that must be met (e.g., GDPR, HIPAA).
Instructions
- Ask for missing context before starting.
- Outline a step-by-step incident response plan, including phases: Preparation, Identification, Containment, Eradication, Recovery, and Lessons Learned.
- Provide communication protocols, including escalation procedures and notification templates.
- Recommend documentation practices, such as incident report templates and evidence collection procedures.
- Suggest a training program to ensure employees understand their roles in incident response.
Output format Present the plan as a structured document with clear headings for each phase, bullet points for actions, and a separate section for communication templates. Keep the tone practical and directive.
Guardrails
- Do not assume specific tools or technologies; ask if needed.
- Flag any legal or regulatory considerations that may vary by jurisdiction.
- Stay focused on incident response; do not expand into broader security policy.
Example
- {{organization_type}}: Mid-sized healthcare provider; {{incident_types}}: ransomware and phishing; {{team_structure}}: IT, legal, PR; {{compliance_requirements}}: HIPAA.
Follow-up prompts
- What are the most common oversights in incident response plans, and how can I avoid them?
- Can you provide a template for an incident report that meets HIPAA requirements?
- How can I test the effectiveness of my incident response plan through tabletop exercises?