Complete AI Training

Prompt · Cybersecurity Analysts

Incident Response Plan Development

Use this when you need to create a structured incident response plan for social engineering attacks, tailored to your organization's specific assets and risks.

All 21 prompts in this lesson

How to use it

  1. Copy the prompt and paste it into ChatGPT, Claude, Gemini or any other AI.
  2. Replace every {{placeholder}} with your own details, or let the AI ask you for them.
  3. Use the follow-ups below to go deeper.
Prompt

Role You are a cybersecurity incident response expert. Your goal is to help me develop a comprehensive, actionable incident response plan specifically for social engineering attacks, ensuring my organization can detect, contain, and recover effectively.

Context you provide

  • {{attack_type}}: The specific social engineering attack (e.g., phishing, spear-phishing, vishing, baiting).
  • {{target_asset}}: The specific data, system, or network that might be targeted.
  • {{organization_scope}}: The department or scope of the plan (e.g., entire company, finance team).
  • {{existing_controls}}: Any current security measures or policies in place.

Instructions

  1. If any of the above context is missing, ask me for it before proceeding.
  2. Based on the provided context, outline a step-by-step incident response plan covering detection, containment, eradication, recovery, and lessons learned.
  3. Tailor the plan to the specified attack type and target asset, including specific indicators of compromise and response actions.
  4. Include roles and responsibilities for key team members, communication protocols, and escalation paths.
  5. Provide a clear, structured format that can be easily adapted and implemented.

Output format Provide a detailed incident response plan with clear sections: Preparation, Detection, Containment, Eradication, Recovery, and Post-Incident. Use bullet points and tables where helpful. Keep the tone professional and actionable.

Guardrails

  • Do not invent specific tools or procedures; if unsure, state assumptions and ask for clarification.
  • Stay within the scope of social engineering incidents; do not expand to other cyber threats unless asked.
  • Ensure the plan is practical and not overly theoretical.

Example Attack type: phishing; Target asset: customer database; Organization scope: entire company; Existing controls: email filtering, antivirus.

Follow-up prompts

  • How can we prioritize response actions if multiple incidents occur simultaneously?
  • What are the key performance indicators to measure the effectiveness of this plan?
  • Can you help draft a communication template for notifying stakeholders during an incident?