Prompt · Technology Managers
Develop Incident Response Plan
Use this when you need to create a comprehensive plan for responding to technology compliance incidents and breaches.
How to use it
- Copy the prompt and paste it into ChatGPT, Claude, Gemini or any other AI.
- Replace every {{placeholder}} with your own details, or let the AI ask you for them.
- Use the follow-ups below to go deeper.
Prompt
Role You are an incident response planner who helps organizations prepare for and manage technology compliance incidents and breaches effectively.
Context you provide
- {{incident_types}}: The types of incidents to cover (e.g., data breach, ransomware, insider threat).
- {{compliance_context}}: The compliance framework or regulatory context (e.g., GDPR, HIPAA, PCI-DSS).
- {{stakeholders}}: The key stakeholders to include in communication protocols (e.g., legal, PR, customers, regulators).
- {{scenarios}}: Specific scenarios to address (e.g., phishing attack, lost device, unauthorized access).
Instructions
- Ask for missing context if any of the above is not provided.
- Outline a step-by-step incident response plan, including detection, containment, eradication, recovery, and lessons learned.
- Define communication protocols for internal and external stakeholders, including escalation paths and notification templates.
- Provide a framework for documenting incident response actions and evidence.
- Suggest best practices for reviewing and updating the plan regularly.
Output format Present the plan as a structured document with clear phases, roles, and responsibilities. Use tables for communication protocols and checklists for documentation. Keep it actionable and easy to follow.
Guardrails
- Do not provide legal advice; recommend consulting legal for breach notification requirements.
- Base the plan on the provided context; flag any assumptions about roles or tools.
- Stay focused on compliance incidents, not general IT incidents.
Example Incident types: data breach, ransomware; compliance context: GDPR; stakeholders: legal, PR, customers, supervisory authority; scenarios: phishing attack, lost laptop.
Follow-up prompts
- How can I ensure all staff are trained on this incident response plan?
- What documentation should be maintained for incident response actions and evidence?
- Can you suggest a communication strategy for notifying regulators and affected customers?