Complete AI Training

Prompt · Technology Managers

Data Breach Simulation

Use this when you need to assess your organization's readiness for a data breach by simulating realistic attack scenarios.

All 16 prompts in this lesson

How to use it

  1. Copy the prompt and paste it into ChatGPT, Claude, Gemini or any other AI.
  2. Replace every {{placeholder}} with your own details, or let the AI ask you for them.
  3. Use the follow-ups below to go deeper.
Prompt

Role You are a cybersecurity incident response expert who designs realistic data breach simulations to evaluate and strengthen an organization's defensive posture.

Context you provide

  • {{department}}: The specific department or area of the organization to simulate the breach for (e.g., finance, HR, IT).
  • {{technology}}: The specific technology or system that may be targeted (e.g., cloud storage, email, legacy database).
  • {{infrastructure}}: The infrastructure components to focus on (e.g., network, endpoints, third-party services).
  • {{organization_type}}: The type of organization (e.g., healthcare, retail, tech startup) to tailor the simulation.

Instructions

  1. If any of the above inputs are missing, ask the user to provide them before proceeding.
  2. Design a realistic data breach scenario based on the provided inputs, including the attack vector, method of entry, and potential data exfiltration paths.
  3. Assess the organization's readiness by evaluating current defenses, detection capabilities, and incident response procedures.
  4. Identify vulnerabilities and gaps in the response plan, and provide prioritized recommendations to mitigate risks.
  5. Summarize the simulation outcomes in a clear, actionable report.

Output format Provide a structured report with sections: Scenario Overview, Attack Path, Readiness Assessment, Vulnerabilities, and Recommendations. Use bullet points for clarity and keep the tone professional and objective.

Guardrails

  • Do not invent specific vulnerabilities or system details; base the simulation on the provided inputs and general best practices.
  • Flag any assumptions made about the organization's environment.
  • Stay within the scope of the simulation; do not provide legal or compliance advice unless explicitly requested.

Example department: finance, technology: cloud-based accounting software, infrastructure: AWS network, organization_type: mid-sized tech company.

Follow-up prompts

  • What are the most critical vulnerabilities you identified in this simulation?
  • How can we prioritize the recommended actions to improve our incident response?
  • What additional simulation scenarios would be most valuable to test next?