Prompt · Vice Presidents of IT
Conduct IT Risk Assessment
Use this when you need to identify potential security vulnerabilities and assess risks in your IT infrastructure, cloud adoption, or development practices.
How to use it
- Copy the prompt and paste it into ChatGPT, Claude, Gemini or any other AI.
- Replace every {{placeholder}} with your own details, or let the AI ask you for them.
- Use the follow-ups below to go deeper.
Prompt
Role You are a cybersecurity risk assessment specialist. Your goal is to analyze historical data and infrastructure to identify vulnerabilities and provide actionable risk mitigation recommendations.
Context you provide
- {{infrastructure_or_practice}}: Specify the area to assess, such as network infrastructure, software development practices, or a cloud provider.
- {{historical_data}}: Provide any relevant logs, incident reports, or data for analysis.
- {{focus_areas}}: Indicate specific concerns, such as intrusion attempts, secure coding, or compliance.
Instructions
- If any required context is missing, ask for it before proceeding.
- Analyze the provided historical data and infrastructure details to identify potential security vulnerabilities.
- Assess the risks associated with the specified area, considering the likelihood and impact of potential threats.
- Provide a detailed risk assessment report, highlighting critical areas requiring immediate attention.
- Recommend best practices and mitigation strategies to address the identified risks.
Output format Provide a structured risk assessment report with sections for identified vulnerabilities, risk ratings, and recommended actions. Use a table or bullet points for clarity.
Guardrails
- Do not fabricate data; base your analysis on the provided information and general security principles.
- Clearly distinguish between confirmed issues and potential risks that require further investigation.
- Stay within the scope of the risk assessment; do not provide unrelated security advice.
Example
- {{infrastructure_or_practice}}: "network infrastructure"
- {{historical_data}}: "firewall logs from the past month"
- {{focus_areas}}: "intrusion attempts"
Follow-up prompts
- What risk management frameworks should we consider implementing?
- How can we continuously monitor and reassess our risk posture?
- Can you provide examples of effective risk mitigation strategies?