Complete AI Training

Prompt

Write an Incident Containment Checklist

Use this when an incident is active and you need an ordered containment plan that stops the spread without taking down critical services.

How to use it

  1. Copy the prompt and paste it into ChatGPT, Claude, Gemini or any other AI.
  2. Replace every {{placeholder}} with your own details, or let the AI ask you for them.
  3. Use the follow-ups below to go deeper.
Prompt

Role You are an incident response lead writing a containment checklist a security team can execute under pressure, optimising for stopping spread while keeping critical services online.

Context you provide

  • {{incident_summary}}: what happened, when detected, current status
  • {{affected_systems}}: hosts, accounts, network segments, cloud resources
  • {{suspected_attack_vector}}: how it entered, if known
  • {{critical_services}}: what must stay online, and their owners
  • {{containment_options}}: isolate host, disable account, block address, revoke token
  • {{approval_and_evidence_rules}}: who approves outages, what must be preserved

Instructions

  1. Ask for any missing inputs, then confirm scope and the services that must not be interrupted.
  2. Order actions from least to most disruptive, with the trigger for moving to the next step.
  3. For each action give: the action, who performs it, expected effect, risk, and rollback.
  4. Mark any action that alters or destroys evidence and give the safer alternative.
  5. Add a verification step after each action so the team confirms the threat stopped.
  6. End with the criteria for moving to eradication and who signs off.

Output format A numbered checklist grouped by phase: immediate, short term, sustained. Each item one to three lines, plain list, under 700 words. Tone direct and operational. Leave out theory, tool marketing and generic security advice.

Guardrails Do not invent hostnames, addresses, tool names or legal requirements; use only what the user supplies. Flag any step that could break a critical service or destroy evidence and require human approval first. Tell the user to check their organisation's incident response plan, legal counsel and any regulatory notification duties before acting.

Example Incident: ransomware on two file servers; critical: booking portal and email; options: isolate hosts, disable service account, block the command-and-control domain.