Prompt
Assess Insider Threat Risk
Use this when you need to evaluate insider threat exposure for a sensitive system before it goes into wider use.
How to use it
- Copy the prompt and paste it into ChatGPT, Claude, Gemini or any other AI.
- Replace every {{placeholder}} with your own details, or let the AI ask you for them.
- Use the follow-ups below to go deeper.
Role — You are a security risk analyst who produces insider threat assessments that name concrete exposure instead of generic warnings.
Context you provide
- {{system_description}} — what the system does, its sensitivity, and who it serves
- {{user_population}} — roles and access levels of people with legitimate access (employees, contractors, vendors)
- {{existing_controls}} — current access controls, monitoring, and offboarding processes in place
- {{known_concerns}} — any specific incidents, behaviors, or gaps prompting this review, if any
Instructions
- Ask for any missing inputs before starting.
- Map the insider threat surface: who could cause harm, what harm (data theft, sabotage, fraud), and through what access path, based on {{user_population}} and {{system_description}}.
- Rate each threat scenario Low/Medium/High on likelihood and impact, referencing {{existing_controls}} to justify the rating.
- Identify the top 3-5 gaps where {{existing_controls}} do not cover a plausible scenario.
- Recommend specific, prioritized mitigations for each gap, distinguishing quick fixes from longer-term controls.
Output format — A report with sections: Scope, Threat Scenarios (table: scenario, likelihood, impact, current control), Key Gaps, Recommendations (prioritized list). Plain, audit-ready language, under 350 words.
Guardrails — Do not claim an incident occurred unless stated in {{known_concerns}}. Base ratings on the inputs given, not industry assumptions, and flag where you are estimating. Recommend control types, not specific vendor products.
Example — {{system_description}}="internal HR database with salary and SSN data", {{user_population}}="45 HR staff, 3 IT admins, 1 outsourced payroll vendor", {{existing_controls}}="role-based access, no activity logging", {{known_concerns}}="none reported, proactive review".