Prompt Details
Model
Chat - (gpt-5.5)
Token size
493
Example input
[ORGANIZATION TYPE AND CRISIS]: a mid-sized e-commerce skincare brand discovering a data breach affecting customer names emails and encrypted payment data for 8,000 customers
[KEY STAKEHOLDERS]: affected customers investors and payment card industry data security standard regulators
[COMMUNICATION CHANNELS]: email to all affected customers website announcement Instagram Facebook and press release to beauty media
Example output
Crisis Communication Package
Scenario: A mid-sized e-commerce skincare brand has discovered unauthorized access to customer names, email addresses, and encrypted payment information affecting approximately 8,000 customers.
---
1. Crisis Assessment Framework
Crisis Severity Classification
Severity: 4/5 (High)
Reason:
Customer personal information exposed.
Potential financial and privacy concerns.
Regulatory implications.
High social media sharing potential.
Significant reputational risk.
Business operations can continue.
---
Stakeholder Impact Map
Stakeholder Impact Priority
Affected customers Very High Critical
Future customers High High
Employees Medium High
Investors High High
PCI DSS stakeholders High Critical
Payment processor High Critical
Media High High
---
Media Escalation Risk
Current Risk: High
Potential headlines include:
"Skincare Brand Exposes Customer Data"
"Thousands of Customer Records Accessed"
Escalation triggers:
Delay in notifying customers
Evidence of negligence
Conflicting statements
Customers reporting fraud
Regulatory investigation
---
Social Media Monitoring Protocol
Monitor every 30 minutes during first 48 hours.
Track:
Company name
Brand hashtags
"data breach"
"hack"
"credit card"
"customer data"
CEO name
Product names
Monitor:
Instagram comments
Facebook comments
Reddit
Beauty communities
X (Twitter)
TikTok
Escalate immediately if:
Influencers begin discussing incident
Major news outlet posts
Evidence of fraud emerges
Customers share suspicious emails
---
Legal & Regulatory Checklist
✔ Outside legal counsel engaged
✔ Cybersecurity incident response activated
✔ Preserve forensic evidence
✔ Notify payment processor
✔ Assess PCI DSS obligations
✔ Determine applicable privacy notification requirements
✔ Review cyber insurance policy
✔ Coordinate legal approval before public release
---
First 24-Hour Priorities
Hour 1-4
Contain breach
Secure systems
Preserve logs
Begin forensic investigation
Hour 4-8
Assemble crisis team
Brief executives
Draft customer communication
Notify legal counsel
Hour 8-12
Notify payment processor
Prepare FAQs
Prepare press statement
Train spokesperson
Hour 12-24
Notify customers
Publish website notice
Issue press release
Begin social monitoring
---
2. Crisis Response Strategy
Core Crisis Narrative
"Our customers trusted us with their information. We take that responsibility seriously. After discovering unauthorized access, we immediately secured our systems, launched an independent forensic investigation, notified appropriate parties, and are communicating openly with affected customers while providing practical guidance and continued updates."
---
Three Core Messages
Message 1
Customer security is our highest priority.
---
Message 2
We acted immediately to contain the incident and investigate.
---
Message 3
We are committed to transparency and will continue updating customers as we learn more.
---
What To Say
✓ We discovered unauthorized access.
✓ We immediately secured affected systems.
✓ Investigation is ongoing.
✓ We are working with cybersecurity experts.
✓ We will continue providing updates.
✓ Customer protection remains our priority.
---
What NOT To Say
✗ "Everything is safe."
✗ "No one will experience fraud."
✗ "This was a sophisticated attack so we're not responsible."
✗ "Nothing important was stolen."
✗ "Only a few customers were affected."
✗ Speculate about attackers.
✗ Guess investigation outcomes.
---
Spokesperson Guide
Primary:
CEO
Supporting:
Head of Security
Customer Support Director
Preparation:
Know:
Timeline
Confirmed facts
Unknowns
Customer support process
Next update timing
Avoid:
Guessing
Technical jargon
Assigning blame
---
Communication Timing
1. Employees informed first.
2. Customers notified immediately after.
3. Website announcement.
4. Press release.
5. Social media.
6. Investor communication.
7. Ongoing updates every 24 hours initially.
---
Silence vs Proactive Response
Respond immediately if:
Customer information involved
Media aware
Customers affected
Investigation confirms breach
Delay only if:
Incident not yet verified
Premature communication would mislead customers
---
3. Stakeholder Communication Templates
Customer Email (Minor)
Dear Customer,
We recently identified unauthorized access involving a limited portion of our systems. We acted quickly to secure the issue and began an investigation with independent cybersecurity experts.
Based on what we know today, your account may have been affected. The information involved may include your name, email address, and encrypted payment information. At this time, there is no confirmed evidence of misuse of your information.
As a precaution, we recommend remaining alert for unexpected emails, monitoring your financial accounts, and using strong, unique passwords.
Protecting your information is one of our highest priorities. We will continue to keep you informed as our investigation progresses.
Thank you for your trust and patience.
Sincerely,
The Security Response TeamCustomer Email (Moderate)
Dear Customer,
We are writing to inform you about a security incident involving unauthorized access to certain customer information.
After detecting suspicious activity, we immediately secured the affected systems, engaged independent cybersecurity specialists, and launched a comprehensive investigation.
Our current findings indicate that your name, email address, and encrypted payment information may have been accessed.
Although encrypted payment information is significantly more difficult to use than unencrypted data, we encourage you to monitor your financial accounts and remain cautious of phishing emails or messages claiming to represent our company.
We deeply regret this incident and understand the concern it may cause. We are strengthening our security measures and will continue to provide updates as our investigation progresses.
Thank you for your continued trust.
Sincerely,
The Security Response TeamCustomer Email (Major)
Dear Customer,
We are contacting you regarding a cybersecurity incident involving unauthorized access to customer information.
Upon discovering the incident, we immediately contained the affected systems, began a forensic investigation with independent cybersecurity experts, and notified the appropriate parties.
Our investigation indicates that your name, email address, and encrypted payment information may have been accessed.
While encrypted payment data is designed to provide additional protection, we strongly recommend that you monitor your financial accounts, be alert for phishing attempts, and promptly report any suspicious activity to your financial institution.
We sincerely apologize for this incident. We understand that trust must be earned, and we are committed to transparency, strengthening our security controls, and keeping you informed as new information becomes available.
Thank you for your patience and understanding.
Sincerely,
The Security Response TeamSocial Media Statement
X / Instagram / Facebook
> We recently identified unauthorized access involving some customer information. We immediately secured our systems, launched an investigation with independent cybersecurity experts, and are notifying affected customers directly. Protecting customer information is our highest priority. Updates and support resources are available on our website.
---
Press Release Structure
Headline
Summary
Timeline
What happened
Information affected
Immediate response
Expert investigation
Customer guidance
Executive quote
Contact information
---
Employee Communication
Explain:
Known facts
Approved talking points
Customer support process
Media referral process
Confidentiality expectations
Daily updates
---
Board & Investor Briefing
Include:
Timeline
Scope
Financial exposure
Regulatory exposure
Customer impact
Response actions
Communication plan
Recovery milestones
---
Partner Notification
Explain:
Nature of incident
Systems secured
Investigation underway
Business continuity status
Expected updates
Point of contact
---
Regulator Notification
Include:
Discovery date
Incident description
Categories of affected information
Number of affected individuals
Containment actions
Investigation status
Contact information
---
4. Media & Social Media Management
Media Inquiry Protocol
1. Acknowledge inquiry promptly.
2. Use only verified facts.
3. Do not speculate.
4. Direct technical questions to designated experts.
5. Commit to providing updates as information is confirmed.
---
Press Conference Preparation
Prepare:
2-minute opening statement.
Timeline of events.
Key facts.
Customer support resources.
Anticipated questions.
Clear closing message focused on accountability and next steps.
---
Anticipated Journalist Questions
1. What happened?
2. When did you discover it?
3. How many customers were affected?
4. What data was accessed?
5. Was payment information exposed?
6. Were passwords affected?
7. Who carried out the attack?
8. Why wasn't it prevented?
9. Why should customers trust you?
10. Have regulators been notified?
11. Are customers receiving assistance?
12. Has the breach been contained?
13. Are operations affected?
14. Will executives be held accountable?
15. What changes are being made?
Answer framework: State the verified fact, explain the action taken, acknowledge any uncertainty where applicable, and describe the next step.
---
Social Media Response Guide
Respond with empathy.
Avoid discussing individual accounts publicly.
Invite affected customers to contact support through secure channels.
Correct misinformation with verified facts.
Hide or report abusive or malicious content according to moderation policies.
---
Negative Review Responses
1. Acknowledge concern and apologize.
2. Thank customer for feedback.
3. Confirm investigation is underway.
4. Direct customer to support.
5. Commit to continued updates.
---
Monitoring Keywords
Brand name
Brand + breach
Brand + hacked
Brand + scam
Brand + data leak
Customer data
Credit card
Phishing
Identity theft
Security
---
5. Legal & Ethical Considerations
Admit
Unauthorized access occurred.
Investigation underway.
Systems secured.
Customer notification initiated.
Investigate Before Stating
Exact attacker identity.
Root cause.
Full scope.
Financial losses.
Attribution of responsibility.
---
Legal Review Checklist
No speculation.
Accurate timelines.
Consistent figures.
Regulatory compliance.
Executive approval.
Counsel review.
---
Document Preservation
Preserve:
System logs.
Security alerts.
Emails.
Incident reports.
Investigation notes.
Internal decisions.
Communication drafts.
---
Insurance
Notify:
Cyber insurer.
Directors and Officers insurer if appropriate.
Breach response vendors as required by policy.
---
Regulatory Reporting
Review all applicable privacy and payment card notification requirements, including obligations related to PCI DSS and any jurisdictions where affected customers reside.
---
Avoid Increasing Liability
Avoid:
Absolute guarantees.
Assigning blame before investigation.
Minimizing customer concerns.
Destroying records.
Contradicting earlier statements.
---
6. Reputation Recovery Roadmap
Week 1
Daily updates.
Dedicated customer support.
FAQ page.
Visible executive leadership.
Ongoing forensic investigation.
---
Months 1–3
Publish investigation findings where appropriate.
Implement enhanced security measures.
Communicate improvements transparently.
Share independent security assessments if available.
Re-engage customers with educational content on account security.
---
Months 3–12
Strengthen governance and incident response.
Conduct regular security audits.
Provide annual transparency reporting.
Reinforce brand values through consistent customer service and accountability.
---
Customer Win-Back Framework
Personalized outreach to affected customers.
Clear explanation of security improvements.
Goodwill gesture (for example, a discount or loyalty reward where appropriate).
Reinforce commitment to protecting customer information.
---
Culture & Process Change Communication
Communicate improvements such as:
Enhanced cybersecurity training.
Stronger access controls.
Continuous security monitoring.
Regular penetration testing.
Independent security reviews.
---
Progress Update Schedule
Day 1: Initial notification.
Day 2–7: Daily updates if there are material developments.
Week 2: Investigation progress update.
Month 1: Summary of findings and improvements.
Months 2–3: Security enhancement updates.
Quarterly (through Month 12): Progress reports on security, governance, and customer trust initiatives.
A successful response should prioritize speed, factual accuracy, empathy, accountability, and transparency while ensuring all public communications are coordinated with legal counsel and cybersecurity experts to maintain credibility and comply with applicable laws and regulations.
Or get it with Select10 Select prompts/mo — under $2 each
Learn moreBy purchasing this prompt, you agree to our terms of service
GPT-5.5
An AI-powered crisis communication meta prompt designed to help business owners and PR managers prepare and respond to brand crises — with complete response frameworks, stakeholder communication templates, and reputation recovery strategies for any industry.
...more
Added over 1 month ago
