Create detailed incident response playbooks for various security incident types with automated runbook steps and communication templates.
You are a security operations expert. Generate incident response playbooks for the following scenario. ## Configuration - **Incident Type**: [INCIDENT e.g. ransomware / data breach / DDoS / insider threat / phishing / supply chain compromise] - **Organization Size**: [SIZE e.g. startup / mid-market / enterprise] - **Industry**: [INDUSTRY e.g. finance / healthcare / technology / government] - **Regulatory Requirements**: [REGS e.g. GDPR, HIPAA, PCI-DSS, SEC] - **Cloud Environment**: [CLOUD e.g. AWS / Azure / hybrid] ## Playbook Structure ### Phase 1: Preparation - Roles and responsibilities matrix (Incident Commander, Technical Lead, Legal, PR, Executive Sponsor) - Communication channels (primary and backup) - Tool inventory: SIEM, EDR, forensic tools, ticketing - Runbook access and authentication in crisis - Contact list: internal teams, legal counsel, law enforcement, regulators, cyber insurance - Retainer details: forensic firm, crisis PR, legal ### Phase 2: Detection & Analysis - **Indicators of Compromise (IoCs)** specific to [INCIDENT]: - Network indicators: suspicious IPs, domains, traffic patterns - Host indicators: file hashes, registry changes, processes - Application indicators: failed logins, privilege escalation, data access anomalies - **Severity Classification**: - SEV-1 (Critical): [criteria for INCIDENT type] - SEV-2 (High): [criteria] - SEV-3 (Medium): [criteria] - SEV-4 (Low): [criteria] - **Initial Triage Steps** (numbered, executable): 1. Confirm incident is real (rule out false positive) 2. Determine scope: affected systems, users, data 3. Assess business impact 4. Escalate to appropriate severity level 5. Activate incident response team ### Phase 3: Containment - **Short-term containment**: immediate actions to limit spread - **Long-term containment**: sustainable controls while investigation continues - **Evidence preservation**: forensic image acquisition steps - **[CLOUD]-specific containment**: snapshot instances, isolate VPCs, revoke credentials - Decision tree: contain vs. monitor for intelligence gathering ### Phase 4: Eradication - Root cause identification procedures - Malware removal and system cleaning - Vulnerability patching - Credential reset scope and process - Verification that threat is eliminated ### Phase 5: Recovery - System restoration from clean backups - Phased service restoration plan - Enhanced monitoring during recovery - User communication and access restoration - Business continuity activation if needed ### Phase 6: Post-Incident - Lessons learned meeting (within 5 business days) - Incident report template - Metrics: MTTD, MTTR, scope, cost - Control improvements and action items - Regulatory notification timeline for [REGS] ### Communication Templates - Internal stakeholder notification - Customer/user notification - Regulatory notification - Media/press statement - Law enforcement report Generate the complete playbook with all steps, decision trees, and templates.
Free to copy and use. Compatible with Claude 4 Opus, GPT-5, Gemini 2.5 Pro.
Select the incident type most relevant to your risk profile. Customize the roles, tools, and contacts for your organization. Conduct tabletop exercises using the playbook to validate procedures. Review and update quarterly.
Initial release
Sign in and download this prompt to leave a review.