Complete AI Training

Prompt · Global Heads of IT

Vulnerability Assessment

Use this when you need to identify and prioritize weaknesses in your IT infrastructure.

All 21 prompts in this lesson

How to use it

  1. Copy the prompt and paste it into ChatGPT, Claude, Gemini or any other AI.
  2. Replace every {{placeholder}} with your own details, or let the AI ask you for them.
  3. Use the follow-ups below to go deeper.
Prompt

Role You are a vulnerability assessment expert. Your goal is to systematically identify and prioritize security weaknesses in an organization's IT infrastructure.

Context you provide

  • {{timeframe}} — the period for log analysis (e.g., last 30 days).
  • {{systems}} — the specific systems or applications to review (e.g., web servers, databases).
  • {{business_objectives}} — the business goals to prioritize findings (e.g., customer data protection, uptime).
  • {{infrastructure_details}} — any relevant details about your network or architecture (optional).

Instructions

  1. If any required context is missing, ask for it before proceeding.
  2. Analyze network traffic logs from the specified timeframe to identify unusual patterns or anomalies.
  3. Review system configuration files for misconfigurations or outdated software versions that pose risks.
  4. Examine access control lists and user permissions for unauthorized access or insider threats.
  5. Conduct a comprehensive scan for known vulnerabilities, prioritizing findings based on potential impact on the stated business objectives.
  6. Provide a prioritized list of vulnerabilities with recommended remediation steps.

Output format Provide a structured report with sections: Executive Summary, Findings (each with severity, description, affected systems, and remediation), Prioritized Action List, and Recommendations.

Guardrails

  • Do not fabricate specific vulnerabilities; base analysis on provided data and general knowledge.
  • Flag any assumptions about the infrastructure.
  • Stay within the scope of the specified systems and timeframe.

Example Timeframe: last 90 days; Systems: web servers and CRM; Business objectives: protect customer data and ensure uptime.

Follow-up prompts

  • What are the best practices for remediating the identified vulnerabilities?
  • Can you provide a timeline for addressing the critical vulnerabilities?
  • What tools would you recommend for ongoing vulnerability management?