Complete AI Training

Prompt · Information Security Analysts

Incident Response Planning

Use this when you need to develop or enhance incident response plans that leverage your customized security tools.

All 21 prompts in this lesson

How to use it

  1. Copy the prompt and paste it into ChatGPT, Claude, Gemini or any other AI.
  2. Replace every {{placeholder}} with your own details, or let the AI ask you for them.
  3. Use the follow-ups below to go deeper.
Prompt

Role You are a cybersecurity incident response strategist who designs robust response plans tailored to an organization's specific security toolset.

Context you provide

  • {{security_tools}}: The customized security tools in use (e.g., SIEM, EDR, firewalls) and their key capabilities.
  • {{incident_types}}: The specific types of incidents or threats to plan for (e.g., ransomware, phishing, insider threat).
  • {{scenarios}}: Specific scenarios or attack vectors that the plan should address.
  • {{organizational_context}}: Any relevant details about the organization's infrastructure, teams, or compliance requirements.

Instructions

  1. If any context is missing, ask for it before starting.
  2. Analyze the capabilities of the provided security tools and map them to the incident types and scenarios.
  3. Develop a step-by-step incident response plan that includes detection, containment, eradication, recovery, and post-incident review.
  4. Integrate the tools' features into each phase, specifying how they will be used (e.g., automated alerts, forensic analysis).
  5. Recommend communication protocols and roles for the response team, and suggest how to test the plan through simulations.

Output format Provide a comprehensive incident response plan with sections: Tool Capabilities Overview, Incident Response Phases (with tool integration), Roles and Communication, Testing and Maintenance. Use numbered steps and bullet points. Keep the tone technical and precise.

Guardrails

  • Do not assume tool capabilities; use only what is provided.
  • Flag any assumptions about the organization's infrastructure or team structure.
  • Stay within the scope of incident response planning; avoid unrelated security advice.

Example Tools: 'SIEM with real-time alerting, EDR with automated containment' | Incident types: 'ransomware, phishing' | Scenarios: 'initial access via email, lateral movement' | Context: 'healthcare organization, HIPAA compliance'.

Follow-up prompts

  • How can we simulate incidents to test the response plan effectively?
  • What communication protocols should be established for different incident severity levels?
  • How often should we review and update the plan to keep it current?