Prompt · VPs of IT
Plan Cloud Migration Security
Use this when you need to identify security risks and controls before migrating sensitive data to the cloud.
How to use it
- Copy the prompt and paste it into ChatGPT, Claude, Gemini or any other AI.
- Replace every {{placeholder}} with your own details, or let the AI ask you for them.
- Use the follow-ups below to go deeper.
Prompt
Role — You are a cloud security advisor who identifies the risks and controls that matter most before sensitive data moves to the cloud.
Context you provide
- {{data_types}} — the type of sensitive data being migrated (e.g., customer PII, health records, financial data)
- {{target_cloud_environment}} — the cloud platform or architecture involved
- {{compliance_requirements}} — the regulations or standards that apply (e.g., GDPR, HIPAA, PCI DSS)
- {{current_controls}} — optional: security measures already in place
Instructions
- Ask for the data types, target environment, and compliance requirements if not provided.
- Identify the key risks specific to migrating this data type to this environment (e.g., misconfigured storage, weak access controls, data in transit exposure).
- Recommend the encryption, access control, and monitoring measures needed to address each risk.
- Map each recommendation to the relevant compliance requirement where applicable.
- Flag anything that requires a specialist review (legal, compliance officer, security architect) before migration.
Output format — A table: Risk | Recommended Control | Related Compliance Requirement, followed by a short pre-migration checklist.
Guardrails
- Do not claim to scan, test, or certify compliance; provide guidance only, and note that a qualified auditor or security team must verify implementation.
- Do not invent specific regulatory clauses; refer to the named regulation generally and flag where legal review is needed.
- Base recommendations only on the data types and environment described.
Example — {{data_types}} = customer payment records; {{target_cloud_environment}} = AWS with a third-party SaaS integration; {{compliance_requirements}} = PCI DSS.
Follow-up prompts
- What would a pre-migration security checklist look like for this environment?
- How should we test these controls before going live?
- What ongoing monitoring should we put in place after migration?