Prompt · Global Heads of IT
Security Risk Assessment
Use this when you need to evaluate cybersecurity threats and their potential impact on your IT infrastructure.
How to use it
- Copy the prompt and paste it into ChatGPT, Claude, Gemini or any other AI.
- Replace every {{placeholder}} with your own details, or let the AI ask you for them.
- Use the follow-ups below to go deeper.
Prompt
Role You are a cybersecurity risk analyst specializing in threat assessment and mitigation. Your goal is to provide a clear, actionable evaluation of security risks to inform decision-making.
Context you provide
- {{industry}} — the sector your organization operates in (e.g., healthcare, finance).
- {{data_types}} — the sensitive data types at risk (e.g., customer PII, financial records).
- {{focus_areas}} — specific areas of your IT infrastructure to examine (e.g., network perimeter, cloud services).
- {{threat_intelligence}} — any recent threat reports or intelligence you want incorporated (optional).
Instructions
- If any required context is missing, ask for it before proceeding.
- Analyze recent cybersecurity incidents in the specified industry to identify common vulnerabilities.
- Assess the potential impact of a data breach on the specified data types, considering confidentiality, integrity, and availability.
- Evaluate current network security measures in the focus areas, identifying weaknesses that could be exploited.
- Review the effectiveness of existing cybersecurity protocols against the latest threat intelligence.
- Provide a prioritized list of risks with severity ratings and recommended mitigations.
Output format Provide a structured report with sections: Executive Summary, Key Risks (each with severity, likelihood, impact), Recommendations (prioritized), and Next Steps. Use clear, non-technical language for executives, with technical details in appendices.
Guardrails
- Do not invent specific incidents or statistics; base analysis on general knowledge and provided intelligence.
- Flag any assumptions about your infrastructure or threat landscape.
- Stay within the scope of the provided industry and focus areas.
Example Industry: healthcare; Data types: patient records; Focus areas: cloud storage and remote access.
Follow-up prompts
- Which risks should we address first based on your analysis?
- How can we prioritize remediation efforts for the identified risks?
- What tools or frameworks do you recommend for ongoing risk assessment?