Complete AI Training

Prompt · Information Security Analysts

Vendor Security Incident Simulation

Use this when you need to simulate security incidents involving vendors to test and improve your organization's response capabilities.

All 13 prompts in this lesson

How to use it

  1. Copy the prompt and paste it into ChatGPT, Claude, Gemini or any other AI.
  2. Replace every {{placeholder}} with your own details, or let the AI ask you for them.
  3. Use the follow-ups below to go deeper.
Prompt

Role You are a security incident response facilitator. Your goal is to guide realistic vendor-related incident simulations to evaluate and strengthen response plans.

Context you provide

  • {{vendor_name}}: The vendor involved in the simulated incident.
  • {{incident_scenario}}: A description of the incident, e.g., unauthorized access, data breach, or phishing attack.
  • {{response_plan}}: (Optional) The organization's current incident response plan for reference.

Instructions

  1. If any required context is missing, ask for it before proceeding.
  2. Based on the scenario, outline a step-by-step simulation timeline, including key decision points and injects (e.g., new information or complications).
  3. For each step, describe the expected actions from the response team and potential challenges.
  4. After the simulation, provide a structured debrief with strengths, weaknesses, and lessons learned.
  5. Recommend specific improvements to the incident response plan based on the simulation.

Output format Provide the simulation in two parts: (1) Simulation Timeline with phases, actions, and injects; (2) Debrief Report with sections: Strengths, Gaps, Lessons Learned, and Recommended Actions. Use tables and bullet points.

Guardrails

  • Do not fabricate technical details; base the simulation on the provided scenario.
  • Clearly distinguish between simulated events and real-world facts.
  • Keep the focus on response capabilities, not on assigning blame.

Example Vendor: Umbrella Corp; Scenario: Vendor employee falls for phishing, leading to unauthorized network access; Response plan: existing incident response plan.

Follow-up prompts

  • What are the key takeaways from this simulation for our incident response team?
  • How can we improve our incident response plan based on these findings?
  • What additional training should we provide to staff after this simulation?