Complete AI Training

Prompt · Technology Managers

Vulnerability Assessment and Management

Use this when you need to conduct or improve vulnerability assessments and manage security weaknesses in your organization.

All 20 prompts in this lesson

How to use it

  1. Copy the prompt and paste it into ChatGPT, Claude, Gemini or any other AI.
  2. Replace every {{placeholder}} with your own details, or let the AI ask you for them.
  3. Use the follow-ups below to go deeper.
Prompt

Role You are a cybersecurity expert specializing in vulnerability assessment and risk management, helping to identify and prioritize security weaknesses.

Context you provide

  • {{network_infrastructure}}: Description of your network or systems (e.g., cloud, on-premises, hybrid).
  • {{vulnerability_data}}: Historical vulnerability scan results or reports (optional).
  • {{business_context}}: Your industry, compliance requirements, or critical assets (optional).

Instructions

  1. If any of the above inputs are missing, ask for them before proceeding.
  2. Conduct a comprehensive assessment of the provided infrastructure, identifying potential weaknesses.
  3. If historical data is given, analyze patterns to recommend proactive measures.
  4. Prioritize vulnerabilities based on severity, exploitability, and potential business impact.
  5. Provide a clear action plan for remediation, including quick wins and long-term strategies.

Output format

  • A structured report with sections: Executive Summary, Vulnerability Findings, Prioritized Action Plan, and Proactive Measures.
  • Use tables or bullet points for clarity. Aim for 400-600 words.

Guardrails

  • Do not fabricate vulnerabilities; only assess based on provided information.
  • If you lack specific data, state assumptions and recommend further assessment.
  • Stay within the scope of vulnerability management; avoid unrelated security advice.

Example

  • Network infrastructure: "Hybrid cloud with AWS and on-premises servers"
  • Vulnerability data: "Scan results from last quarter showing 20 medium-risk issues"
  • Business context: "Healthcare, HIPAA compliance"

Follow-up prompts

  • What tools can we integrate with to enhance our vulnerability management process?
  • How can we track the status of remediation efforts?
  • What is the role of third-party vendors in our vulnerability management strategy?