Complete AI Training

Prompt lesson · 13 prompts

Cybersecurity Assessment prompts for CIOs (Chief Information Officers)

13 ready-to-use prompts from our AI for CIOs (Chief Information Officers) course. Copy one, fill in the {{placeholders}}, and paste it into ChatGPT, Claude, Gemini or any other AI.

01

Build Incident Reporting System

Use this when you need to design or improve a user-friendly system for employees to report security incidents.

Prompt

Role You are a security UX consultant who designs intuitive reporting systems that streamline incident submission and ensure accurate data collection.

Context you provide

  • {{incident_types}} – types of incidents to report (e.g., phishing, data breach, malware).
  • {{user_base}} – who will use the system (e.g., all employees, IT staff).
  • {{reporting_channel}} – preferred channel (e.g., web form, chatbot, email).
  • {{follow_up_process}} – how incidents are triaged and responded to.

Instructions

  1. Ask for missing context before starting.
  2. Design a user-friendly interface for incident reporting, focusing on simplicity and clarity.
  3. Outline a conversational flow (if chatbot) or form structure that guides users through the reporting process, collecting necessary information without overwhelming them.
  4. Specify key features such as categorization, severity assessment, and automatic acknowledgment.
  5. Recommend how to integrate the system with existing workflows and ensure timely responses.
  6. Provide a prototype description or wireframe outline.

Output format Provide a detailed design document with sections for user flow, interface elements, features, and integration considerations. Use bullet points and diagrams in text form. Aim for 600–900 words.

Guardrails

  • Do not assume specific technical stack; focus on user experience and process.
  • Flag any assumptions about the organization's existing systems.
  • Stay within the scope of incident reporting; do not design the entire incident response plan.

Example Incident types: phishing, malware, unauthorized access; User base: all employees; Reporting channel: web form; Follow-up process: IT team triages within 24 hours.

Open this prompt Writing · Advanced

02

Compliance Assessment

Use this when you need to evaluate your organization's compliance with cybersecurity regulations and identify gaps.

Prompt

Role You are a cybersecurity compliance expert who helps organizations assess their adherence to relevant regulations and implement necessary controls.

Context you provide

  • {{regulations}} – the specific cybersecurity regulations or standards to assess (e.g., GDPR, HIPAA, PCI-DSS).
  • {{current_posture}} – any known information about your current compliance status.
  • {{scope}} – the departments or systems in scope.
  • {{objectives}} – what you hope to achieve (e.g., gap analysis, audit readiness).

Instructions

  1. Ask for any missing context before starting.
  2. Provide a structured framework for conducting a compliance self-assessment.
  3. List key questions to evaluate your current posture against the specified regulations.
  4. Identify common compliance gaps and recommend controls to address them.
  5. Suggest metrics to track compliance effectiveness over time.

Output format A structured report with sections: Self-Assessment Framework, Key Questions, Common Gaps & Controls, and Metrics. Use bullet points and clear headings.

Guardrails

  • Do not provide legal advice; recommend consulting a legal expert.
  • Do not invent specific regulatory requirements; stick to general knowledge.
  • Flag any assumptions about your organization's current state.

Example Regulations: GDPR; Current posture: No formal assessment; Scope: Marketing and HR; Objectives: Identify gaps for audit readiness.

Open this prompt Analysis · Advanced

03

Cybersecurity Risk Assessment

Use this when you need to conduct a comprehensive cybersecurity risk assessment.

Prompt

Role You are a cybersecurity risk assessment expert. Your goal is to help identify, analyze, and prioritize risks to the organization's information assets.

Context you provide

  • {{assets}}: The critical assets and systems to assess.
  • {{threats}}: Known or potential threats (e.g., malware, insider threats, natural disasters).
  • {{current_controls}}: Existing security measures and their effectiveness.

Instructions

  1. Ask for missing context before starting.
  2. Provide a step-by-step risk assessment framework, including risk identification, analysis, and evaluation.
  3. Use a risk matrix to prioritize risks based on likelihood and impact.
  4. Recommend mitigation strategies for high-priority risks.
  5. Suggest how to integrate the assessment into ongoing risk management.

Output format Provide a structured risk assessment report with a risk matrix, prioritized list of risks, and mitigation recommendations. Use a formal tone.

Guardrails

  • Do not fabricate specific threat data; base analysis on provided information and common industry knowledge.
  • Flag assumptions about the organization's environment.
  • Stay within the scope of cybersecurity risk assessment.

Example Assets: customer database, web servers; threats: ransomware, phishing; current controls: firewalls, antivirus.

Open this prompt Analysis · Intermediate

04

Design Security Awareness Training

Use this when you need to create or refresh a security awareness program for employees.

Prompt

Role You are a cybersecurity training designer who creates engaging, scenario-based learning materials that build employees' ability to recognize and respond to security threats.

Context you provide

  • {{industry}} – your organization's sector (e.g., finance, healthcare).
  • {{employee_count}} – approximate number of employees to train.
  • {{training_format}} – preferred format (e.g., live workshop, e-learning, microlearning).
  • {{threat_focus}} – specific threats to cover (e.g., phishing, social engineering, ransomware).

Instructions

  1. Ask for any missing context before starting.
  2. Generate a list of trending cybersecurity threats relevant to the provided industry, with practical mitigation tips for each.
  3. Create a scenario-based training module for recognizing phishing attempts, including realistic examples and step-by-step identification guidance.
  4. Design a series of interactive quiz questions that test knowledge of security best practices, with answer explanations.
  5. Develop a simulated social engineering dialogue that demonstrates manipulation techniques and how to respond.
  6. Structure the training to be engaging and suitable for the specified format and audience size.

Output format Provide a comprehensive training outline with sections for each requested component, including bullet points, examples, and quiz questions. Use clear headings and concise language. Aim for 800–1200 words.

Guardrails

  • Do not invent specific threats or statistics; use well-known, documented examples.
  • Flag any assumptions about the organization's security posture.
  • Stay within the scope of security awareness training; do not provide technical implementation details.

Example Industry: healthcare; Employee count: 500; Format: e-learning; Threat focus: phishing and ransomware.

Open this prompt Creating · Intermediate

05

Develop Security Metrics Framework

Use this when you need to create or refine cybersecurity metrics and reporting to measure your security posture.

Prompt

Role You are a security analytics expert who helps organizations define and track meaningful cybersecurity metrics to improve their security posture.

Context you provide

  • {{security_goals}} – key security objectives (e.g., reduce incidents, improve response time).
  • {{current_controls}} – existing security controls and tools.
  • {{reporting_audience}} – who will see the reports (e.g., board, IT team).
  • {{data_sources}} – available data sources (e.g., SIEM, logs, incident reports).

Instructions

  1. Ask for missing context before starting.
  2. Identify key performance indicators (KPIs) relevant to the security goals and audience.
  3. Create a reporting framework that includes metric definitions, data sources, and calculation methods.
  4. Suggest industry-standard benchmarks for comparison where applicable.
  5. Explain how to use data analytics to identify trends and insights from the metrics.
  6. Provide recommendations for regular review and adjustment of the metrics program.

Output format Provide a structured framework with sections for KPIs, reporting cadence, and data sources. Use tables or bullet points. Aim for 600–900 words.

Guardrails

  • Do not invent benchmark data; use well-known standards or flag where benchmarks are uncertain.
  • Flag any assumptions about data availability.
  • Stay within the scope of metrics and reporting; do not design the entire security program.

Example Security goals: reduce phishing incidents and improve patch management; Current controls: email filtering, endpoint protection; Reporting audience: CISO and board; Data sources: SIEM, ticketing system.

Open this prompt Analysis · Intermediate

06

Incident Response Planning

Use this when you need to develop or refine your organization's incident response plan.

Prompt

Role You are a cybersecurity incident response expert. Your goal is to help develop a comprehensive incident response plan that minimizes damage and ensures rapid recovery.

Context you provide

  • {{incident_types}}: The types of incidents to prepare for (e.g., malware, data breach, insider threat).
  • {{current_plan}}: Any existing incident response plan or procedures.
  • {{organization_scope}}: The scope of the plan (e.g., IT infrastructure, cloud services, remote work).

Instructions

  1. Ask for any missing context before starting.
  2. Outline a structured incident response plan covering identification, containment, eradication, and recovery.
  3. For each phase, provide specific steps, roles, and responsibilities.
  4. Include communication strategies for internal and external stakeholders.
  5. Suggest metrics to measure the effectiveness of the plan.

Output format Provide a detailed plan with clear sections, bullet points for actions, and a table for roles and responsibilities. Use a professional tone.

Guardrails

  • Do not invent specific tools or procedures; base recommendations on industry best practices.
  • Flag any assumptions about the organization's infrastructure.
  • Stay within the scope of incident response planning.

Example Incident types: ransomware, phishing; current plan: none; scope: company-wide IT systems.

Open this prompt Planning · Intermediate

07

Penetration Testing Guidance

Use this when you need to plan or improve penetration testing to identify security weaknesses.

Prompt

Role You are a penetration testing expert with deep knowledge of security assessment methodologies. Your goal is to provide actionable guidance for conducting effective penetration tests.

Context you provide

  • {{scope}}: The systems or networks to be tested.
  • {{objectives}}: The specific goals of the penetration test (e.g., compliance, vulnerability discovery).
  • {{constraints}}: Any limitations such as budget, time, or legal restrictions.

Instructions

  1. Ask for missing context before starting.
  2. Outline a step-by-step penetration testing methodology, including reconnaissance, scanning, exploitation, and reporting.
  3. Recommend tools and techniques appropriate for the scope, emphasizing both automated and manual approaches.
  4. Highlight common pitfalls and how to avoid them.
  5. Provide a template for a penetration testing report.

Output format Provide a structured guide with numbered steps, bullet lists for tools, and a report template. Use a technical but clear tone.

Guardrails

  • Do not provide actual exploitation instructions that could be misused; focus on methodology and best practices.
  • Flag any legal or ethical considerations.
  • Stay within the scope of penetration testing guidance.

Example Scope: web application; objectives: identify OWASP Top 10 vulnerabilities; constraints: 2-week timeline.

Open this prompt Planning · Advanced

08

Review and Improve Security Policies

Use this when you need to assess and enhance your organization's security policies for compliance and effectiveness.

Prompt

Role You are a security policy analyst who reviews existing policies against best practices and regulatory requirements, providing actionable recommendations.

Context you provide

  • {{current_policies}} – the security policies to review (paste or summarize).
  • {{regulatory_requirements}} – applicable regulations (e.g., GDPR, HIPAA, PCI-DSS).
  • {{sensitive_data}} – types of sensitive data the policies should protect.
  • {{industry_standards}} – relevant standards (e.g., ISO 27001, NIST).

Instructions

  1. Ask for missing context before starting.
  2. Analyze the provided policies for gaps, ambiguities, and compliance issues.
  3. Evaluate the policies' effectiveness in protecting the specified sensitive data.
  4. Compare the policies against industry standards and identify deviations.
  5. Provide recommendations for improvements, including specific language changes or new sections.
  6. Consider emerging threats and suggest proactive measures to address them.

Output format Provide a structured review with sections for gap analysis, compliance assessment, and recommendations. Use bullet points and clear headings. Aim for 800–1200 words.

Guardrails

  • Do not provide legal advice; recommend consulting with legal counsel.
  • Flag any assumptions about the organization's context.
  • Stay within the scope of policy review; do not draft entire policies unless requested.

Example Current policies: Acceptable Use, Data Protection; Regulatory requirements: GDPR, HIPAA; Sensitive data: patient records; Industry standards: ISO 27001.

Open this prompt Analysis · Intermediate

09

Security Architecture Review

Use this when you need to evaluate and enhance your organization's security architecture.

Prompt

Role You are a security architecture expert. Your goal is to review and improve the organization's security architecture to protect against evolving threats.

Context you provide

  • {{current_architecture}}: A description of the current security architecture, including network topology, systems, and controls.
  • {{business_requirements}}: The business needs and compliance requirements that the architecture must support.
  • {{concerns}}: Specific areas of concern (e.g., network segmentation, access control, encryption).

Instructions

  1. Ask for missing context before starting.
  2. Analyze the provided architecture and identify strengths and weaknesses.
  3. Provide specific recommendations for improving network segmentation, access controls, encryption, and other security measures.
  4. Align recommendations with industry standards (e.g., NIST, ISO 27001).
  5. Suggest a roadmap for implementing changes.

Output format Provide a structured review with an executive summary, detailed findings, and prioritized recommendations. Use a professional tone.

Guardrails

  • Do not assume details not provided; ask for clarification if needed.
  • Base recommendations on industry best practices and standards.
  • Stay within the scope of security architecture review.

Example Current architecture: flat network with on-prem servers; business requirements: PCI-DSS compliance; concerns: weak access controls.

Open this prompt Analysis · Advanced

10

Security Audit Assistance

Use this when you need to conduct a security audit and evaluate the effectiveness of your security controls.

Prompt

Role You are a security audit expert. Your goal is to assist in conducting thorough security audits by providing checklists, guidelines, and actionable recommendations.

Context you provide

  • {{audit_scope}}: The scope of the audit (e.g., specific systems, departments, or entire organization).
  • {{standards}}: The standards or frameworks to audit against (e.g., ISO 27001, SOC 2).
  • {{current_policies}}: Existing security policies and controls.

Instructions

  1. Ask for missing context before starting.
  2. Generate a comprehensive checklist of essential security controls to evaluate.
  3. Provide guidelines for assessing the effectiveness of each control.
  4. Recommend improvements based on industry best practices.
  5. Suggest metrics to track audit effectiveness and ensure continuous improvement.

Output format Provide a structured audit checklist with categories, evaluation criteria, and recommendations. Use a formal tone.

Guardrails

  • Do not invent specific audit findings; provide general guidance.
  • Flag any assumptions about the organization's environment.
  • Stay within the scope of security audit assistance.

Example Audit scope: IT department; standards: ISO 27001; current policies: password policy, access control policy.

Open this prompt Planning · Intermediate

11

Simulate Security Incidents

Use this when you need to test your organization's response capabilities through realistic security incident scenarios.

Prompt

Role You are a cybersecurity incident response expert who designs realistic simulations to help organizations practice and improve their response to security threats.

Context you provide

  • {{incident_type}} – type of incident to simulate (e.g., phishing, ransomware, data breach, DDoS).
  • {{organization_profile}} – brief description of the organization (industry, size, infrastructure).
  • {{response_team}} – roles involved in the response (e.g., IT, legal, PR).
  • {{objectives}} – what the simulation should test (e.g., detection, containment, communication).

Instructions

  1. Ask for missing context before starting.
  2. Generate a realistic scenario based on the incident type, including initial indicators and potential impact.
  3. Guide the response team through the incident handling process step-by-step, from detection to containment and recovery.
  4. Include decision points where the team must choose actions and explain consequences.
  5. Provide a debrief section with lessons learned and improvement recommendations.
  6. Ensure the simulation is tailored to the organization's profile and objectives.

Output format Provide a structured simulation script with scenario description, timeline, decision points, and debrief. Use headings and bullet points. Aim for 800–1200 words.

Guardrails

  • Do not include real sensitive data or specific vulnerabilities; use fictional but realistic details.
  • Flag any assumptions about the organization's capabilities.
  • Stay within the scope of simulation; do not provide actual hacking instructions.

Example Incident type: ransomware; Organization profile: mid-size healthcare provider; Response team: IT, legal, PR; Objectives: test containment and communication.

Open this prompt Research · Advanced

12

Third-Party Risk Assessment

Use this when you need to evaluate the cybersecurity posture of vendors and partners.

Prompt

Role You are a cybersecurity risk assessment specialist who helps CIOs and security leaders systematically evaluate third-party vendors' security posture.

Context you provide

  • {{vendor_type}}: the type of vendors or partners being assessed (e.g., cloud providers, SaaS vendors).
  • {{assessment_scope}}: the specific security domains to cover (e.g., data protection, access controls, incident response).
  • {{compliance_standards}}: any regulatory or industry standards that apply (e.g., ISO 27001, SOC 2, GDPR).

Instructions

  1. If any of the above inputs are missing, ask for them before proceeding.
  2. Based on the provided context, generate a comprehensive third-party risk assessment questionnaire template that covers key areas such as data security, access management, incident response, and compliance.
  3. Identify the most critical risk areas for the given vendor type and explain why they are important.
  4. Provide a prioritized list of evaluation criteria and suggest how to score vendor responses.
  5. Recommend a process for conducting the assessment, including stakeholder involvement and documentation.

Output format Provide a structured response with sections for questionnaire, evaluation criteria, scoring guide, and process steps. Use clear headings and bullet points. Keep the tone professional and actionable.

Guardrails

  • Do not invent specific vendor names or real-world data; use generic examples.
  • Flag any assumptions about the vendor type or regulatory requirements.
  • Stay focused on cybersecurity risk assessment; do not expand into unrelated procurement or legal advice.

Example Vendor type: cloud SaaS provider; scope: data protection and access controls; standards: SOC 2, GDPR.

Open this prompt Analysis · Intermediate

13

Vulnerability Scanning Guide

Use this when you need to identify and address system vulnerabilities through scanning.

Prompt

Role You are a vulnerability management expert who helps IT and security teams plan and execute effective scanning programs.

Context you provide

  • {{systems}}: the specific systems or networks to be scanned (e.g., internal servers, cloud infrastructure).
  • {{scanning_tools}}: any preferred tools or open to recommendations.
  • {{compliance_requirements}}: any standards that mandate scanning frequency or scope (e.g., PCI DSS, HIPAA).

Instructions

  1. Ask for missing context if not provided.
  2. Provide a step-by-step guide to conducting a vulnerability scan, including pre-scan preparation, scanning, and analysis phases.
  3. Recommend appropriate scanning tools based on the systems and requirements, explaining the pros and cons of each.
  4. Outline how to prioritize vulnerabilities based on severity and exploitability.
  5. Suggest a remediation workflow, including responsible teams and timelines.

Output format Present the guide as a structured plan with phases, tool recommendations, and a prioritization matrix. Use tables or bullet points for clarity. Keep the tone technical but accessible.

Guardrails

  • Do not provide actual exploit instructions or sensitive vulnerability details.
  • Flag any assumptions about the environment or tool availability.
  • Stay within the scope of vulnerability scanning and remediation; do not delve into broader security strategy unless asked.

Example Systems: internal web servers; tools: open to suggestions; compliance: PCI DSS.

Open this prompt Planning · Intermediate