All prompts

Draft

Draft the first-72-hours breach response one-pager

Turns your company profile and a specific incident scenario into a single page of named owners, hour-stamped actions, and notification decisions: the thing you can actually run at 2 a.m.

About 15 minintermediateIn-house, Privacy

Your prompt5,259 characters

Still to fill in: Company profile, Regimes and clocks

RoleYou are an in-house counsel who has run incident response for real and learned that an eighty-page IR plan is a document nobody opens at 2 a.m. You write for the person who has been awake nineteen hours, so every line is an action with an owner and a clock, or a decision with a named decider. You never write "the team should consider," and you never let a deadline sit in a paragraph.What I needDraft the one-page first-72-hours brief for Suspected data exfiltration via a compromised credential at Company profile, under Regimes and clocks, honoring Insurance and vendor constraints. Assign every action to a person from Named people and phone numbers.InputsCompany profile: Company profile Scenario: Suspected data exfiltration via a compromised credential Regimes and clocks: Regimes and clocks Named people: Named people and phone numbers Insurance and vendor limits: Insurance and vendor constraintsHow to work this1. Write the activation trigger in one sentence: the observable fact that opens this playbook. Vague triggers mean nobody starts the clock. 2. Build the roster from Named people and phone numbers: every role gets a name and a number. Where I gave none, leave a blank marked [FILL BEFORE PUBLISHING] rather than inventing a person. 3. Write each window: 0–6 contain and preserve, 6–24 assess and decide, 24–72 notify and remediate, as numbered actions, each with a named owner and an elapsed-hour deadline. Imaging before analysis and the litigation-hold directive belong in hour 0–6. 4. Build the notification matrix: audience, trigger, clock and what starts it, decider, draft owner. Cover every regime in Regimes and clocks plus customers, carrier, and board. Where a clock runs from "awareness," name who fixes that moment. 5. Tailor containment and evidence to Suspected data exfiltration via a compromised credential. Ransomware, insider theft, and vendor breach do not share a first hour. 6. Write the do-not-do list: three to five items, each a mistake people actually make under pressure.Close with these four sections, every time, without being askedAssumptions I made. Every assumption about which regimes apply, notification clocks, carrier conditions, contractual notice obligations, and who holds which role. Mark each [verify] or [safe]. Flag any deadline you inferred rather than took from my inputs. Where this is weakest. The two or three steps most likely to fail under real conditions: the action with no named owner, the deadline that turns on a determination nobody has made, the step that assumes a vendor answers at 3 a.m. Name the step. What only you can decide. The judgment calls I left to you, each as options with tradeoffs. At minimum: engage outside counsel in hour one (strongest privilege over the forensics, satisfies most carrier conditions, but you spend money before you know this is real) or run it in-house until scope is known (cheaper and quieter, weaker privilege over early triage, and late retention can complicate coverage); and notify the carrier on thin facts inside the notice window (protects coverage, may lock you into panel counsel) or wait for scope (cleaner report, risks a late-notice fight). What would make this materially better. The document or decision that would most improve the next pass: the policy's notice condition and panel list, the breach-notice clauses in your top five customer contracts, the on-call roster, or which authority is lead. Rank by impact.Output formatOne page headed INCIDENT RESPONSE - FIRST 72 HOURS: Activate (one sentence); Roles (name and number); Hour 0–6, Hour 6–24, Hour 24–72 (numbered actions with owner and elapsed-hour deadline); Notification matrix (audience, trigger, clock, decider, draft owner); Do not (three to five items); the one number to call in any doubt. Then the four closing sections.Never do this- If this brief would work at any company under any regime, it is too generic. Name this company's data, this scenario's first move, these regulators. - No hedging filler. Cut "arguably," "it should be noted," and "as appropriate." Do not tell me to consult an attorney. I am the one running this at 2 a.m. - Every statutory clock, regulator name, and policy condition must come from my inputs or carry [UNVERIFIED - confirm before relying]. Never invent a notification deadline; a wrong one is worse than a blank. - Where you do not know whether a regime applies or when its clock starts, say you do not know and name who decides. Do not smooth over it with fluent prose. - Do not pad. If a window has four actions, write four. Length is not value. Every extra line pushes a real instruction off the page.Before you answer- Is every action owned by a named person with a number, or did a committee slip in? - Does every deadline have a clock and a stated starting event? - Is the brief itself actually one page? - Is every regulator, statute, and policy condition from my inputs or marked unverified? - Would this brief be useless at another company facing another scenario? It should be.

Adds driver's-seat tunes: options instead of answers, questions before work, every citation flagged. Your values come with it.

2

Pressure-test it

Makes the AI switch hats and attack its own answer.

The call comes at 2 a.m. to outside privacy counsel, who has never seen this company before and has only this brief. Read it as the partner who has to give advice before dawn. Name the three places the brief leaves you unable to advise in the first thirty minutes: the fact you would have to ask for, the decision with no owner, the clock with no start date. Then rewrite those sections so a partner walking in cold can act immediately, and tell me which single missing input costs the most time.
3

Go deeper

Pushes the work further once the basics are right.

Sending the notices comes next, and none of them exist yet. Build the notification drafts this brief points to: a supervisory-authority notice skeleton with the required content fields, a B2B customer notice matching a 48-hour contractual commitment, and the carrier notice in the form the policy requires. Each as a fill-in-the-blank template with the fields that must be verified before sending marked clearly.

Before you run it

What to gather first

  • Industry, headcount, and what data the company actually holds
  • Which privacy, sector, and securities regimes reach the company
  • Cyber insurance carrier, policy notice window, and whether panel counsel is required
  • Whether outside privacy counsel and a forensic firm are already retained
  • Contractual breach-notification commitments in your customer agreements

Watch for

  • Notification clocks usually run from awareness, not from the incident, and awareness is a legal determination someone has to make and document. Fix the moment in writing when you make it.
  • Cyber policies commonly require notice within a short window and may condition coverage on using panel counsel and pre-approved forensics. Read the policy before you retain anyone.
  • Do not investigate on original media. Image first and analyze the image, or you will lose evidence and the ability to prove what happened.
  • Public-company disclosure obligations run on a different and shorter track than privacy notification. If your company is public or has public debt, that analysis starts on day one.
  • This brief is a plan, not advice for a live incident. Once something real is happening, engage counsel and forensics rather than following a document the model wrote in advance.

What comes back

A one-page brief: activation trigger in one sentence, named roles with phone numbers, three hour-stamped action blocks (0–6, 6–24, 24–72) each action carrying an owner and an elapsed-hour deadline, a notification matrix with audience, trigger, clock, decider and draft owner, a three-to-five item do-not-do list, and a single escalation number. Followed by assumptions, the steps most likely to fail, the calls left to you, and what would improve the next pass.

See an example of what you’ll get
INCIDENT RESPONSE - FIRST 72 HOURS (Fanstop, Inc.) Activate: Any credible indication that a valid credential was used from an unrecognized source to access systems holding retailer-customer personal data. Roles: IC: M. Patel, VP Security, +1-555-0101. Legal: J. Lin, GC, +1-555-0110. Technical: A. Ortiz, CISO, +1-555-0122. Communications: R. Kim, +1-555-0130. Executive sponsor: D. Chen, CEO. Outside counsel: M. Reyes, +1-555-0142. Forensics: retained firm, +1-555-0188. Broker: Marsh, [FILL BEFORE PUBLISHING]. Hour 0–6: contain and preserve 1. Patel opens the incident channel, renames it #ir-0412, restricts membership, and applies the privileged header. (IC, 0:30) 2. Ortiz disables the suspect credential, forces a tenant-wide session revocation, and preserves authentication and egress logs to cold storage before any analysis. (CISO, 1:30) 3. Ortiz images any endpoint associated with the credential. No investigation on original media. (CISO, 2:00) 4. Lin issues the preservation directive: no deletion of logs, endpoints, mailboxes, or chat; auto-deletion policies suspended tenant-wide. (Legal, 1:00) 5. Lin engages Reyes and retains forensics through counsel, so the investigation is directed by counsel from the start. (Legal, 2:00) 6. Patel and Ortiz produce the first scope note: what we know, what we do not, what is running. One page. (IC + CISO, 4:00) Hour 6–24: assess and decide 7. Reyes and Lin fix the moment of awareness in writing. This starts the GDPR clock and the contractual 48-hour clocks. (Outside counsel + Legal, 8:00) 8. Lin notifies the carrier through Marsh within the 48-hour policy condition and confirms whether panel counsel and approved forensics are required. (Legal + Broker, 10:00) 9. Ortiz and forensics deliver preliminary findings: entry vector, dwell time, systems reached, and whether there is evidence of exfiltration as opposed to access. (CISO + Forensics, 18:00) 10. Lin pulls breach-notice clauses from the top enterprise MSAs and builds the customer notification list. (Legal, 18:00) 11. Patel briefs Chen; Chen decides whether to stand up the full crisis team. (IC to CEO, 20:00) Hour 24–72: notify and remediate 12. Reyes and Lin finalize the Irish DPC notification if the risk threshold is met; UK ICO in parallel if UK data subjects are affected. (Legal, by 72:00 from awareness) 13. Lin and the account team send customer notices per contract; enterprise MSAs run 48 hours from awareness, so several will land before the regulator notice. (Legal + CSM, 48:00) 14. Kim drafts a holding statement. Not released without Lin and Chen approval. (Comms, 30:00) 15. Ortiz executes remediation: credential rotation, MFA enforcement on the affected path, egress monitoring, and closure of the entry vector. (CISO, ongoing) 16. Lin and Chen brief the board if the incident is material to the business. (Legal + CEO, 72:00) Notification matrix | Audience | Trigger | Clock | Decider | Draft owner | |---|---|---|---|---| | Irish DPC (lead) | Personal data breach with risk to individuals | 72 hr from awareness | Lin + Reyes | Reyes | | UK ICO | Same, UK data subjects affected | 72 hr from awareness | Lin + Reyes | Reyes | | EU/UK data subjects | High risk to rights and freedoms | Without undue delay | Lin + Reyes | Reyes | | California and other US states | Statutory definition met | Varies by state [UNVERIFIED - confirm current state clocks] | Lin | Outside counsel | | Enterprise customers | Contractual breach-notice clause | 48 hr from awareness in most MSAs | Lin | Lin + CSM | | Cyber carrier | Any covered event | 48 hr policy condition | Lin | Broker | | Board | Material to the business | As soon as assessed | Chen + Lin | Lin | Do not: issue any public statement before the facts hold; run forensics on original media; restore from backup before images are preserved; discuss the incident outside the IR channel or over personal accounts; delete or rotate a log source to "clean things up." Any doubt about scope, severity, or whether to escalate: call M. Reyes, +1-555-0142. --- Assumptions I made. GDPR, UK GDPR, and CCPA apply based on your profile [safe]. The 48-hour carrier condition and the 48-hour customer MSA clock came from your inputs [safe]. State-by-state US clocks are not in my inputs and are marked unverified in the matrix [verify]. I assumed the Irish DPC is lead because you named it; that depends on your main establishment [verify]. Where this is weakest. Step 7 is the load-bearing step and the one most likely to be skipped: nobody wants to fix the moment of awareness while the facts are still moving, but every clock in the matrix runs from it. Step 13 is second: the 48-hour customer notices land before you will have forensic scope, which means notifying customers of something you cannot yet describe. What only you can decide. Whether Reyes gets engaged in hour one or hour twelve. Hour one gives you the strongest privilege posture over the forensic work and satisfies most carrier conditions, but you are spending money and signaling escalation before you know this is real. Hour twelve is cheaper and quieter, but the early triage work sits outside privilege and a late retention can complicate the coverage conversation. Separately: whether to notify the carrier at hour 10 on thin facts: protects coverage but may lock you into panel counsel and approved forensics rather than the firm you already trust, or wait for scope, which gives a cleaner first report at the risk of a late-notice dispute. What would make this materially better. (1) The actual cyber policy notice condition and panel list: it changes steps 5 and 8 and possibly who runs the investigation. (2) The breach-notice clauses from your five largest customer contracts, so step 13 has real deadlines instead of one assumed number. (3) The current on-call roster with after-hours numbers, which is the difference between this brief working at 2 a.m. and not.
Why this prompt is built the way it is
## Framework 1. **One page or it does not get read.** Anything that is not an action, an owner, a clock, or a decision comes out. 2. **Three windows.** Hour 0–6 contain and preserve. Hour 6–24 assess and decide. Hour 24–72 notify and remediate. 3. **Named people, not functions.** "Security team" owns nothing. One incident commander, one legal lead, one technical lead, one communications lead, one executive sponsor. 4. **Privilege from minute one.** Investigation directed by counsel, outside counsel engaged early, forensics retained through counsel, written work product labeled. 5. **Preservation before analysis.** Image before you investigate. Suspend deletion on logs, endpoints, mailboxes, and chat before anyone touches anything. 6. **Notification is a decision, not an autopilot.** Each audience gets a trigger, a clock, a decider, and a draft owner. The clock usually runs from awareness, which is itself a legal determination. 7. **Insurance is a deadline too.** Carrier notice windows are short and coverage can turn on them, as can the requirement to use panel counsel and approved forensics. 8. **Say nothing publicly until the facts hold.** A retracted statement is worse than silence.