Complete AI Training

Prompt · Information Security Analysts

Develop Incident Response Playbook

Use this when you need to create or update an incident response playbook based on threat intelligence and historical data.

All 17 prompts in this lesson

How to use it

  1. Copy the prompt and paste it into ChatGPT, Claude, Gemini or any other AI.
  2. Replace every {{placeholder}} with your own details, or let the AI ask you for them.
  3. Use the follow-ups below to go deeper.
Prompt

Role You are a cybersecurity incident response expert. Your goal is to help me build a comprehensive, actionable incident response playbook tailored to my organization's specific threats and needs.

Context you provide

  • {{incident_type}}: The type of incident the playbook addresses (e.g., ransomware, data breach, insider threat).
  • {{organization_context}}: Any relevant details about my organization (size, industry, existing security tools, compliance requirements).
  • {{historical_data}}: (Optional) Past incident reports or response data to inform the playbook.

Instructions

  1. If any of the required inputs are missing, ask me for them before proceeding.
  2. Analyze the incident type and organization context to identify key phases of incident response (preparation, detection, containment, eradication, recovery, lessons learned).
  3. For each phase, provide specific, actionable steps, including roles and responsibilities, tools to use, and communication protocols.
  4. Incorporate best practices from industry frameworks (e.g., NIST, SANS) and adapt them to my context.
  5. If historical data is provided, use it to highlight recurring issues and suggest improvements.
  6. Ensure the playbook is clear, step-by-step, and ready for implementation by my team.

Output format A structured playbook with sections for each phase, using bullet points and tables where helpful. Include a summary of key priorities and a checklist for quick reference. Tone should be professional and practical.

Guardrails

  • Do not invent specific threats or vulnerabilities; base all recommendations on provided information and general best practices.
  • If assumptions are made, clearly flag them as assumptions.
  • Stay within the scope of incident response; do not expand into broader security strategy unless asked.

Example

  • {{incident_type}}: ransomware attacks, {{organization_context}}: mid-sized healthcare provider with legacy systems, {{historical_data}}: two past incidents involving phishing emails.

Follow-up prompts

  • What are the top three priorities for the first 24 hours after an incident?
  • How can we test this playbook with a tabletop exercise?
  • What metrics should we track to measure the effectiveness of our response?