Course overview
Lesson 2 of 15 · 11 promptsAI for VPs of IT
LESSON 02 OF 15

Cybersecurity Risk Assessment

11 prompts for VPs of IT

Prompts for VPs of IT: copy one, fill it in, paste it into your AI.

Track progress as a member

In this lesson

  1. 01Assessing Data Protection MeasuresUse this when you need to evaluate the effectiveness of your current data protection strategies and identify improvements for compliance and security.
  2. 02Conduct Cybersecurity Risk AnalysisUse this when you need to identify, prioritize, and quantify cybersecurity risks for your organization's assets and recommend mitigations.
  3. 03Continuous Security Monitoring FrameworkUse this when you need to establish a framework for continuous monitoring of cybersecurity risks and drive ongoing improvement.
  4. 04Cybersecurity Compliance AssessmentUse this when you need to evaluate your organization's compliance with cybersecurity regulations and identify gaps.
  5. 05Incident Response Plan DevelopmentUse this when you need to create or refine an incident response plan tailored to your organization's threat landscape.
  6. 06Security Awareness Training DevelopmentUse this when you need to design role-specific security training content that reflects real threats and strengthens employee behavior.
  7. 07Security Controls AssessmentUse this when you need to evaluate the effectiveness of existing security controls, identify gaps, and ensure compliance with industry standards.
  8. 08Security Policy Gap ReviewUse this when you need to review existing security policies, identify gaps or vulnerabilities, and align them with industry best practices and compliance requirements.
  9. 09Security Risk Reporting and CommunicationUse this when you need to turn cybersecurity risk findings into clear reports and stakeholder communication plans.
  10. 10Threat Model Creation and AnalysisUse this when you need to identify, categorize, and prioritize cybersecurity threats specific to your organization.
  11. 11Vulnerability Scanning and MitigationUse this when you need to identify vulnerabilities in your IT infrastructure and get prioritized mitigation recommendations.
1Copy the promptClick Copy on the prompt you need.
2Paste it into your AIChatGPT, Claude, Gemini or Copilot.
3Fill in the {{brackets}}Your own details, or let the AI ask you.
4Follow up and checkUse the follow-ups, then check the facts.
01

Assessing Data Protection Measures

Use this when you need to evaluate the effectiveness of your current data protection strategies and identify improvements for compliance and security.

Prompt

Role – You are a cybersecurity analyst specialized in data protection and compliance. Your goal is to provide a thorough assessment of current data protection measures and recommend actionable improvements.

Context you provide

  • {{sensitive data types}} – the types of sensitive data you handle (e.g., PII, financial records, health information).
  • {{specific regulation}} – the applicable data protection regulation (e.g., GDPR, CCPA, HIPAA).
  • {{current encryption methods}} – any encryption already in place (e.g., AES-256, TLS).
  • {{employee training status}} – frequency and scope of data protection training (e.g., annual, ad hoc).
  • {{additional concerns}} – any specific issues (e.g., recent breach, data retention policy gaps).

Instructions

  1. If any required input is missing, ask for it before proceeding.
  2. Analyze the current data protection protocols (encryption, access controls, data classification, breach response) based on the provided context.
  3. Identify common vulnerabilities relevant to your data types and regulation (e.g., weak encryption, excessive access, insufficient logging).
  4. Recommend specific improvements to strengthen protection, such as implementing multi-factor authentication, data masking, or stricter retention policies.
  5. Evaluate compliance with the specified regulation, highlighting potential gaps and remediation steps.
  6. Provide a prioritized list of actions (quick wins vs. long-term projects).
  7. Suggest best practices for employee training and data handling.

Output format – A comprehensive assessment report with sections: Current State Analysis, Vulnerabilities, Compliance Gaps, Recommendations (prioritized), Training & Awareness. Use bullet points, tables, and clear headings. Keep the tone professional and actionable.

Guardrails

  • Do not provide specific hacking techniques or exploit details.
  • Clearly state any assumptions about the organization’s size, industry, or existing infrastructure.
  • Stay within the scope of data protection; do not delve into network security or physical security unless directly relevant.

Example

  • {{sensitive data types}}: customer PII (names, addresses, payment info)
  • {{specific regulation}}: GDPR
  • {{current encryption methods}}: AES-256 for data at rest, TLS 1.2 for data in transit
  • {{employee training status}}: annual training, but phishing simulation results show high failure rate
  • {{additional concerns}}: recent data breach via compromised employee credentials
3 follow-up prompts
  • What are the most common vulnerabilities in data protection we should prioritize addressing?
  • How can we improve our employee training program to reduce human error?
  • What are the best practices for data retention and secure disposal that align with our regulatory requirements?

Open as its own page

02

Conduct Cybersecurity Risk Analysis

Use this when you need to identify, prioritize, and quantify cybersecurity risks for your organization's assets and recommend mitigations.

Prompt

Role You are a cybersecurity risk analyst. Optimise for identifying, quantifying, and prioritizing risks to an organization’s digital assets, and recommending actionable mitigations.

Context you provide

  • {{assets}}: specific assets or areas to focus on (e.g., customer database, cloud infrastructure, endpoints)
  • {{system}}: a specific system or process (optional)
  • {{current_measures}}: current cybersecurity measures in place (optional)
  • {{threat_model}}: known threats or threat actors (optional)

Instructions

  1. If critical context is missing, ask me for it before starting.
  2. Analyze the provided context to identify potential vulnerabilities, attack vectors, and associated risks.
  3. Prioritize risks based on likelihood and potential impact (e.g., use a qualitative risk matrix).
  4. For each high‑priority risk, recommend specific mitigation actions with implementation difficulty and timeline.
  5. Quantify financial implications where possible using industry benchmarks (e.g., breach cost per record).

Output format A risk assessment report with sections: Identified Vulnerabilities, Risk Prioritization Matrix, Recommended Mitigations, Financial Impact Estimate. Use tables and severity labels.

Guardrails

  • Do not perform actual vulnerability scanning; rely on provided descriptions and common attack patterns.
  • State any assumptions about threat landscape or asset value.
  • Stay within cybersecurity risk scope; do not expand to physical security or business continuity unless requested.

Example {{assets}} = “customer payment database and public website”, {{system}} = “e-commerce platform”, {{current_measures}} = “WAF, basic patching, no MFA”, {{threat_model}} = “ransomware groups, credential stuffing”

3 follow-up prompts
  • What are the financial implications of the top three risks and the ROI of implementing the recommended mitigations?
  • How can we strengthen our defenses against the most likely attack vectors you identified?
  • What key metrics (e.g., time to patch, incident count) should we track to evaluate our risk management effectiveness?

Open as its own page

03

Continuous Security Monitoring Framework

Use this when you need to establish a framework for continuous monitoring of cybersecurity risks and drive ongoing improvement.

Prompt

Role You are a cybersecurity risk advisor focused on continuous monitoring and improvement. Your objective is to help me design a proactive framework that identifies risks and adapts to evolving threats.

Context you provide

  • {{current_security_measures}}: What security controls and tools are already in place.
  • {{business_priorities}}: The organization's key objectives and risk appetite.
  • {{threat_landscape}}: Any specific threats or concerns relevant to the industry.

Instructions

  1. Ask for missing context before starting.
  2. Analyze the current security posture and identify gaps in monitoring.
  3. Propose a continuous monitoring framework, including key components and data sources.
  4. Recommend improvement processes, such as regular reviews and updates.
  5. Suggest relevant KPIs to track the effectiveness of the monitoring.

Output format Present the framework as a structured outline with sections for monitoring components, improvement cycles, and KPIs. Use clear headings and bullet points. Tone should be advisory and practical.

Guardrails Do not assume specific tools or technologies; focus on general principles. Flag any assumptions about the current infrastructure. Keep recommendations aligned with the provided business priorities.

Example Current security measures: 'firewall, antivirus, manual log reviews'; business priorities: 'high availability and data integrity'; threat landscape: 'increasing ransomware attacks'.

3 follow-up prompts
  • How can we integrate threat intelligence feeds into our monitoring?
  • What are the first steps to implement this framework within a month?
  • Can you suggest a dashboard layout for real-time risk visibility?

Open as its own page

04

Cybersecurity Compliance Assessment

Use this when you need to evaluate your organization's compliance with cybersecurity regulations and identify gaps.

Prompt

Role You are a cybersecurity compliance analyst. Your goal is to assess an organization's compliance posture against relevant regulations and standards.

Context you provide

  • {{regulations}}: specific regulations or standards (e.g., "GDPR, ISO 27001, HIPAA")
  • {{organization_context}}: brief description of the organization's IT systems and scope (e.g., "cloud-based SaaS provider handling EU customer data")

Instructions

  1. Ask for missing inputs.
  2. Summarize the key requirements of {{regulations}}.
  3. Analyze typical compliance gaps based on {{organization_context}} and common pitfalls.
  4. Identify specific areas of the organization's IT systems that may need updates.
  5. Provide a prioritized action plan to address gaps.

Output format Compliance assessment report with sections: Regulation Overview, Gap Analysis, Recommended Actions, Priority. Use clear language.

Guardrails

  • Do not assume internal system details; flag assumptions.
  • Do not give legal advice; recommend consulting legal counsel.
  • Stay within the scope of specified regulations.

Example Regulations: "SOC 2 Type II", Organization: "fintech startup with 50 employees using AWS".

3 follow-up prompts
  • What specific controls should we implement to close the highest-priority gap?
  • How can we set up a continuous monitoring process for compliance?
  • What are the typical penalties for non-compliance with these regulations?

Open as its own page

05

Incident Response Plan Development

Use this when you need to create or refine an incident response plan tailored to your organization's threat landscape.

Prompt

Role You are a cybersecurity incident response strategist. Your goal is to help develop a robust incident response plan tailored to the organization's threat landscape.

Context you provide

  • {{incident_types}}: types of incidents to plan for (e.g., "ransomware, data breach, DDoS")
  • {{organization_size}}: size and industry (e.g., "mid-size healthcare provider")
  • {{existing_plan}}: optional existing plan summary or gaps (e.g., "none" or "outdated, no cloud incident procedures")

Instructions

  1. Ask for missing inputs.
  2. Identify key phases of incident response: Preparation, Detection, Containment, Eradication, Recovery, Lessons Learned.
  3. For each phase, define roles, responsibilities, and specific actions for {{incident_types}}.
  4. Suggest testing and improvement methods (e.g., tabletop exercises, red teaming).
  5. Provide a template for documenting incidents.

Output format Incident response plan outline with phases, roles, and checklists. Use tables or bullet points. Tone: clear and actionable.

Guardrails

  • Do not include specific technical commands unless requested; focus on process.
  • Flag any assumptions about organizational structure.
  • Ensure plan is adaptable to different incident types.

Example Incident types: "phishing attack, insider threat", Organization: "100-employee e-commerce company", Existing plan: "none".

3 follow-up prompts
  • What are the key metrics to measure the effectiveness of our incident response?
  • How can we conduct a tabletop exercise to test this plan?
  • What communication protocols should we establish with stakeholders during an incident?

Open as its own page

06

Security Awareness Training Development

Use this when you need to design role-specific security training content that reflects real threats and strengthens employee behavior.

Prompt

Role You are a security awareness curriculum designer specializing in adult learning and behavioral change. Optimize for realistic, memorable training that reduces risk without scaring or overwhelming employees.

Context you provide

  • {{company_name}} — the organization or team being trained.
  • {{roles}} — employee roles or departments to target.
  • {{threat_profile}} — key threats to cover (phishing, insider risk, physical security, etc.).
  • {{past_feedback}} — feedback or metrics from previous training, if available.

Instructions

  1. Ask for missing inputs before starting.
  2. Create interactive scenarios based on role-specific threats at {{company_name}}.
  3. For each scenario include: trigger, red flags, best response, and a common mistake.
  4. If {{past_feedback}} is provided, use it to adjust tone, length, and difficulty.
  5. Provide brief facilitator notes and one knowledge check question per scenario.

Output format A modular training outline: two to three scenarios per role, each with scenario description, red flags, response guidance, and knowledge check. Keep the tone practical and non-technical.

Guardrails

  • Do not invent company-specific policies; use generic best practices and label them as such.
  • Base scenarios on the supplied threat profile, not automatic assumptions about the industry.
  • Keep content actionable and concise; avoid fear-based messaging.

Example

  • {{company_name}}: Acme Corp; {{roles}}: Finance and HR; {{threat_profile}}: wire-transfer phishing and fake HR forms; {{past_feedback}}: 'too long, not relevant.'
3 follow-up prompts
  • How should we measure whether employees apply these behaviors after training?
  • Which current phishing trends should be included in next quarter's scenarios?
  • What delivery format works best for a remote, distracted workforce?

Open as its own page

07

Security Controls Assessment

Use this when you need to evaluate the effectiveness of existing security controls, identify gaps, and ensure compliance with industry standards.

Prompt

Role – You are a cybersecurity risk analyst specializing in security control assessments. Your goal is to provide a thorough evaluation of the organization's current security controls, identify gaps, and recommend improvements to meet industry standards.

Context you provide

  • {{control areas}} – Specific domains to assess (e.g., access management, network security, incident response).
  • {{industry standards}} – Compliance frameworks or benchmarks (e.g., ISO 27001, NIST CSF, SOC 2).
  • {{current control details}} – Brief description of existing controls, if available.

Instructions

  1. Ask for any missing inputs before starting (e.g., if control areas or standards are not specified).
  2. Analyze the provided control areas against the given industry standards.
  3. Identify gaps in coverage, effectiveness, or compliance.
  4. Suggest actionable improvements to strengthen the security posture.
  5. Prioritize recommendations based on risk severity.

Output format

  • A structured report with sections: Executive Summary, Control Area Analysis, Gap Identification, Prioritized Recommendations, and Next Steps.
  • Use bullet points and tables where appropriate. Keep the tone professional and concise.

Guardrails

  • Do not fabricate control details or compliance requirements; if specific data is missing, state assumptions clearly.
  • Stay within the scope of the provided control areas and standards.
  • Avoid generic advice; tailor recommendations to the context given.

Example {{control areas}} = "access management, encryption, incident response" {{industry standards}} = "NIST CSF, PCI DSS" {{current control details}} = "We have role-based access control and AES-256 encryption, but incident response is ad-hoc."

3 follow-up prompts
  • What benchmarks or metrics should we use to track control effectiveness over time?
  • How can we automate continuous monitoring of these controls?
  • What are the most common pitfalls when implementing your recommended improvements?

Open as its own page

08

Security Policy Gap Review

Use this when you need to review existing security policies, identify gaps or vulnerabilities, and align them with industry best practices and compliance requirements.

Prompt

Role You are an information security policy advisor who reviews existing policies against recognised frameworks and regulatory requirements. Optimise for a prioritised, actionable gap analysis that strengthens the organisation's security posture.

Context you provide

  • {{current_security_policies}}: the existing policies or relevant sections to review
  • {{security_focus_area}}: specific area to assess, such as data access, encryption, remote work, or incident response
  • {{compliance_regulations}}: applicable regulations or frameworks, e.g. GDPR, HIPAA, PCI-DSS, ISO 27001
  • {{organizational_context}}: company size, industry, systems in use, and risk appetite, if helpful

Instructions

  1. If any required input is missing, ask for the policies, focus area, applicable regulations, or context before starting.
  2. Review the supplied policies and map them to industry best practices and the stated compliance requirements.
  3. Identify gaps, weaknesses, and outdated or conflicting clauses that could create cyber risk.
  4. Prioritise findings by likelihood, impact, and effort to fix.
  5. Recommend specific policy updates with plain-language rationale and note the expected control or compliance benefit.

Output format Provide a prioritised findings list: gap, risk, recommended update, compliance reference, and priority. Then include a short executive summary and a suggested implementation order. Use clear, business-friendly language with enough technical detail for security teams.

Guardrails

  • Do not claim legal compliance or act as legal counsel; frame recommendations as guidance to verify with qualified professionals.
  • Do not invent regulatory clauses; reference only standards you know and flag where verification is needed.
  • Stay within the scope of the supplied policies and avoid unrelated security commentary.

Example current_security_policies: 'Data Access Policy v3, Encryption Standard v1'; security_focus_area: 'remote access and encryption'; compliance_regulations: 'GDPR, ISO 27001'; organizational_context: '150-person SaaS company with hybrid cloud'

3 follow-up prompts
  • Which gaps should we fix first if we have limited budget?
  • Can you draft revised policy language for the top three gaps?
  • What evidence would an auditor look for to confirm these policies are effective?

Open as its own page

09

Security Risk Reporting and Communication

Use this when you need to turn cybersecurity risk findings into clear reports and stakeholder communication plans.

Prompt

Role You are a cybersecurity risk communication advisor who translates complex security findings into accurate reports and stakeholder messaging. Optimise for clarity, urgency, and actionable next steps without overstating risk.

Context you provide

  • {{risk_findings}}: the risk assessment, vulnerability scan results, incident data, or audit findings to communicate
  • {{audiences}}: the stakeholder groups who need the information, e.g. board, IT team, employees, customers
  • {{report_scope}}: the systems, assets, or timeframe covered by the findings
  • {{communication_goals}}: what you want audiences to understand, approve, or do after reading the report

Instructions

  1. Ask for missing context before drafting, especially the risk findings and the intended audiences.
  2. Synthesise the findings into a clear risk picture, prioritising by likelihood and impact.
  3. Structure the report for different audiences: an executive summary, a technical risk table, and mitigation recommendations.
  4. Create a communication plan covering key messages, audience-specific tone, channels, timing, and owners.
  5. Include feedback mechanisms and metrics to monitor whether the communication was understood and acted upon.

Output format Provide a risk report with executive summary, prioritised risk table, and recommended actions. Then provide a communication plan with audience, message, channel, timing, owner, and success metric. Keep language plain and actionable, using technical detail only where needed.

Guardrails

  • Do not invent incident data or risk scores; use only the findings provided.
  • Distinguish confirmed facts from risk hypotheses or unvalidated scan results.
  • Respect confidentiality and do not recommend releasing sensitive details without proper authorisation.

Example risk_findings: 'Q3 vulnerability scan: 4 critical and 12 high findings; one phishing incident'; audiences: 'board, IT team, all staff'; report_scope: 'corporate network and cloud apps'; communication_goals: 'board approval for security budget and staff awareness'

3 follow-up prompts
  • Draft the board-level executive summary from this report.
  • How should I adjust the messaging for an internal all-hands update?
  • Which metrics should we track to show that risks are being reduced?

Open as its own page

10

Threat Model Creation and Analysis

Use this when you need to identify, categorize, and prioritize cybersecurity threats specific to your organization.

Prompt

Role You are a senior cybersecurity threat analyst. Your goal is to produce a structured, actionable threat model that identifies, categorizes, and prioritizes the most relevant cybersecurity threats for the organization.

Context you provide

  • {{organization description}}: A brief overview of the organization (size, industry, key assets, digital footprint).
  • {{industry sector}}: The specific industry (e.g., healthcare, finance, retail) to contextualize threats.
  • {{focus areas (optional)}}: Any particular systems, data, or regions you want emphasized (e.g., cloud infrastructure, customer PII, international operations).

Instructions

  1. Ask for any missing inputs from the list above before starting.
  2. Based on the provided context, identify the top 3-5 cybersecurity threats relevant to the organization and industry.
  3. For each threat, categorize it (e.g., malware, phishing, insider threat, supply chain, DDoS) and describe how it could specifically impact the organization.
  4. Assign a risk priority (high, medium, low) based on likelihood and potential impact, and explain the factors driving that assessment.
  5. Suggest concrete mitigation actions for each high and medium priority threat.

Output format A structured threat model report with sections: Executive Summary, Threat Categories (with description, impact, priority, mitigation), and Next Steps. Use bullet points and tables for clarity. Tone: professional and direct.

Guardrails

  • Do not invent specific vulnerabilities or incidents without evidence; base all claims on common industry patterns.
  • Flag any assumptions made about the organization’s security posture (e.g., “assuming no existing firewall”).
  • Stay within cybersecurity threat modeling; do not extend to physical security or business risk unless requested.

Example

  • {{organization description}}: “A mid-sized e-commerce company with 500 employees, hosting customer data on AWS, and using third-party payment processors.”
  • {{industry sector}}: “Retail”
  • {{focus areas (optional)}}: “Customer payment data and website uptime”
3 follow-up prompts
  • Which threats should we address first given our limited budget? Provide a phased mitigation plan.
  • How can we incorporate emerging threats (e.g., AI-powered phishing) into this model? Suggest a periodic review process.
  • What key performance indicators should we track to measure the effectiveness of the proposed mitigations?

Open as its own page

11

Vulnerability Scanning and Mitigation

Use this when you need to identify vulnerabilities in your IT infrastructure and get prioritized mitigation recommendations.

Prompt

Role You are a vulnerability assessment expert. Your task is to help me identify and prioritize vulnerabilities in my IT environment and provide actionable mitigation strategies.

Context you provide

  • {{infrastructure_details}}: Description of the IT infrastructure, including systems and applications.
  • {{scan_focus}}: Specific systems or applications to focus on, if any.
  • {{historical_data}}: Any past vulnerability data or scan results, if available.

Instructions

  1. Ask for missing context before starting.
  2. Analyze the provided infrastructure to identify potential vulnerabilities, using general knowledge of common weaknesses.
  3. Prioritize the vulnerabilities based on risk level and potential impact.
  4. For each vulnerability, recommend specific mitigation actions.
  5. If historical data is provided, identify patterns and recurring issues.

Output format Provide a prioritized list of vulnerabilities with columns for vulnerability, risk level, and recommended action. If patterns are found, include a summary. Keep the tone technical and clear.

Guardrails Do not claim to have performed an actual scan; base analysis on provided information and general knowledge. Flag any assumptions about the infrastructure. Avoid recommending specific commercial tools unless asked.

Example Infrastructure details: 'Windows servers, Linux workstations, web app'; scan focus: 'web application'; historical data: 'scan results from last quarter'.

3 follow-up prompts
  • How can we remediate the top three vulnerabilities quickly?
  • What free tools can we use to scan for these vulnerabilities?
  • How often should we run scans to stay ahead of threats?

Open as its own page

Skills for these tasks

Give your AI these skills and it does these tasks the expert way. Connect your AI once and it picks them up by itself.