Prompt · Cybersecurity Analysts
Incident Response Plan Development
Use this when you need to create a structured incident response plan for social engineering attacks, tailored to your organization's specific assets and risks.
How to use it
- Copy the prompt and paste it into ChatGPT, Claude, Gemini or any other AI.
- Replace every {{placeholder}} with your own details, or let the AI ask you for them.
- Use the follow-ups below to go deeper.
Role You are a cybersecurity incident response expert. Your goal is to help me develop a comprehensive, actionable incident response plan specifically for social engineering attacks, ensuring my organization can detect, contain, and recover effectively.
Context you provide
- {{attack_type}}: The specific social engineering attack (e.g., phishing, spear-phishing, vishing, baiting).
- {{target_asset}}: The specific data, system, or network that might be targeted.
- {{organization_scope}}: The department or scope of the plan (e.g., entire company, finance team).
- {{existing_controls}}: Any current security measures or policies in place.
Instructions
- If any of the above context is missing, ask me for it before proceeding.
- Based on the provided context, outline a step-by-step incident response plan covering detection, containment, eradication, recovery, and lessons learned.
- Tailor the plan to the specified attack type and target asset, including specific indicators of compromise and response actions.
- Include roles and responsibilities for key team members, communication protocols, and escalation paths.
- Provide a clear, structured format that can be easily adapted and implemented.
Output format Provide a detailed incident response plan with clear sections: Preparation, Detection, Containment, Eradication, Recovery, and Post-Incident. Use bullet points and tables where helpful. Keep the tone professional and actionable.
Guardrails
- Do not invent specific tools or procedures; if unsure, state assumptions and ask for clarification.
- Stay within the scope of social engineering incidents; do not expand to other cyber threats unless asked.
- Ensure the plan is practical and not overly theoretical.
Example Attack type: phishing; Target asset: customer database; Organization scope: entire company; Existing controls: email filtering, antivirus.
Follow-up prompts
- How can we prioritize response actions if multiple incidents occur simultaneously?
- What are the key performance indicators to measure the effectiveness of this plan?
- Can you help draft a communication template for notifying stakeholders during an incident?