All prompts
Draft
Draft the first-72-hours breach response one-pager
Turns your company profile and a specific incident scenario into a single page of named owners, hour-stamped actions, and notification decisions: the thing you can actually run at 2 a.m.
Your prompt
2
Pressure-test it
3
Go deeper
Before you run it
What to gather first
Watch for
What comes back
See an example of what you’ll get
INCIDENT RESPONSE - FIRST 72 HOURS (Fanstop, Inc.)
Activate: Any credible indication that a valid credential was used from an unrecognized source to access systems holding retailer-customer personal data.
Roles: IC: M. Patel, VP Security, +1-555-0101. Legal: J. Lin, GC, +1-555-0110. Technical: A. Ortiz, CISO, +1-555-0122. Communications: R. Kim, +1-555-0130. Executive sponsor: D. Chen, CEO. Outside counsel: M. Reyes, +1-555-0142. Forensics: retained firm, +1-555-0188. Broker: Marsh, [FILL BEFORE PUBLISHING].
Hour 0–6: contain and preserve
1. Patel opens the incident channel, renames it #ir-0412, restricts membership, and applies the privileged header. (IC, 0:30)
2. Ortiz disables the suspect credential, forces a tenant-wide session revocation, and preserves authentication and egress logs to cold storage before any analysis. (CISO, 1:30)
3. Ortiz images any endpoint associated with the credential. No investigation on original media. (CISO, 2:00)
4. Lin issues the preservation directive: no deletion of logs, endpoints, mailboxes, or chat; auto-deletion policies suspended tenant-wide. (Legal, 1:00)
5. Lin engages Reyes and retains forensics through counsel, so the investigation is directed by counsel from the start. (Legal, 2:00)
6. Patel and Ortiz produce the first scope note: what we know, what we do not, what is running. One page. (IC + CISO, 4:00)
Hour 6–24: assess and decide
7. Reyes and Lin fix the moment of awareness in writing. This starts the GDPR clock and the contractual 48-hour clocks. (Outside counsel + Legal, 8:00)
8. Lin notifies the carrier through Marsh within the 48-hour policy condition and confirms whether panel counsel and approved forensics are required. (Legal + Broker, 10:00)
9. Ortiz and forensics deliver preliminary findings: entry vector, dwell time, systems reached, and whether there is evidence of exfiltration as opposed to access. (CISO + Forensics, 18:00)
10. Lin pulls breach-notice clauses from the top enterprise MSAs and builds the customer notification list. (Legal, 18:00)
11. Patel briefs Chen; Chen decides whether to stand up the full crisis team. (IC to CEO, 20:00)
Hour 24–72: notify and remediate
12. Reyes and Lin finalize the Irish DPC notification if the risk threshold is met; UK ICO in parallel if UK data subjects are affected. (Legal, by 72:00 from awareness)
13. Lin and the account team send customer notices per contract; enterprise MSAs run 48 hours from awareness, so several will land before the regulator notice. (Legal + CSM, 48:00)
14. Kim drafts a holding statement. Not released without Lin and Chen approval. (Comms, 30:00)
15. Ortiz executes remediation: credential rotation, MFA enforcement on the affected path, egress monitoring, and closure of the entry vector. (CISO, ongoing)
16. Lin and Chen brief the board if the incident is material to the business. (Legal + CEO, 72:00)
Notification matrix
| Audience | Trigger | Clock | Decider | Draft owner |
|---|---|---|---|---|
| Irish DPC (lead) | Personal data breach with risk to individuals | 72 hr from awareness | Lin + Reyes | Reyes |
| UK ICO | Same, UK data subjects affected | 72 hr from awareness | Lin + Reyes | Reyes |
| EU/UK data subjects | High risk to rights and freedoms | Without undue delay | Lin + Reyes | Reyes |
| California and other US states | Statutory definition met | Varies by state [UNVERIFIED - confirm current state clocks] | Lin | Outside counsel |
| Enterprise customers | Contractual breach-notice clause | 48 hr from awareness in most MSAs | Lin | Lin + CSM |
| Cyber carrier | Any covered event | 48 hr policy condition | Lin | Broker |
| Board | Material to the business | As soon as assessed | Chen + Lin | Lin |
Do not: issue any public statement before the facts hold; run forensics on original media; restore from backup before images are preserved; discuss the incident outside the IR channel or over personal accounts; delete or rotate a log source to "clean things up."
Any doubt about scope, severity, or whether to escalate: call M. Reyes, +1-555-0142.
---
Assumptions I made. GDPR, UK GDPR, and CCPA apply based on your profile [safe]. The 48-hour carrier condition and the 48-hour customer MSA clock came from your inputs [safe]. State-by-state US clocks are not in my inputs and are marked unverified in the matrix [verify]. I assumed the Irish DPC is lead because you named it; that depends on your main establishment [verify].
Where this is weakest. Step 7 is the load-bearing step and the one most likely to be skipped: nobody wants to fix the moment of awareness while the facts are still moving, but every clock in the matrix runs from it. Step 13 is second: the 48-hour customer notices land before you will have forensic scope, which means notifying customers of something you cannot yet describe.
What only you can decide. Whether Reyes gets engaged in hour one or hour twelve. Hour one gives you the strongest privilege posture over the forensic work and satisfies most carrier conditions, but you are spending money and signaling escalation before you know this is real. Hour twelve is cheaper and quieter, but the early triage work sits outside privilege and a late retention can complicate the coverage conversation. Separately: whether to notify the carrier at hour 10 on thin facts: protects coverage but may lock you into panel counsel and approved forensics rather than the firm you already trust, or wait for scope, which gives a cleaner first report at the risk of a late-notice dispute.
What would make this materially better. (1) The actual cyber policy notice condition and panel list: it changes steps 5 and 8 and possibly who runs the investigation. (2) The breach-notice clauses from your five largest customer contracts, so step 13 has real deadlines instead of one assumed number. (3) The current on-call roster with after-hours numbers, which is the difference between this brief working at 2 a.m. and not.
Why this prompt is built the way it is
## Framework
1. **One page or it does not get read.** Anything that is not an action, an owner, a clock, or a decision comes out.
2. **Three windows.** Hour 0–6 contain and preserve. Hour 6–24 assess and decide. Hour 24–72 notify and remediate.
3. **Named people, not functions.** "Security team" owns nothing. One incident commander, one legal lead, one technical lead, one communications lead, one executive sponsor.
4. **Privilege from minute one.** Investigation directed by counsel, outside counsel engaged early, forensics retained through counsel, written work product labeled.
5. **Preservation before analysis.** Image before you investigate. Suspend deletion on logs, endpoints, mailboxes, and chat before anyone touches anything.
6. **Notification is a decision, not an autopilot.** Each audience gets a trigger, a clock, a decider, and a draft owner. The clock usually runs from awareness, which is itself a legal determination.
7. **Insurance is a deadline too.** Carrier notice windows are short and coverage can turn on them, as can the requirement to use panel counsel and approved forensics.
8. **Say nothing publicly until the facts hold.** A retracted statement is worse than silence.