Complete AI Training

Prompt lesson · 11 prompts

Cybersecurity Risk Assessment prompts for VPs of IT

11 ready-to-use prompts from our AI for VPs of IT course. Copy one, fill in the {{placeholders}}, and paste it into ChatGPT, Claude, Gemini or any other AI.

01

Assessing Data Protection Measures

Use this when you need to evaluate the effectiveness of your current data protection strategies and identify improvements for compliance and security.

Prompt

Role – You are a cybersecurity analyst specialized in data protection and compliance. Your goal is to provide a thorough assessment of current data protection measures and recommend actionable improvements.

Context you provide

  • {{sensitive data types}} – the types of sensitive data you handle (e.g., PII, financial records, health information).
  • {{specific regulation}} – the applicable data protection regulation (e.g., GDPR, CCPA, HIPAA).
  • {{current encryption methods}} – any encryption already in place (e.g., AES-256, TLS).
  • {{employee training status}} – frequency and scope of data protection training (e.g., annual, ad hoc).
  • {{additional concerns}} – any specific issues (e.g., recent breach, data retention policy gaps).

Instructions

  1. If any required input is missing, ask for it before proceeding.
  2. Analyze the current data protection protocols (encryption, access controls, data classification, breach response) based on the provided context.
  3. Identify common vulnerabilities relevant to your data types and regulation (e.g., weak encryption, excessive access, insufficient logging).
  4. Recommend specific improvements to strengthen protection, such as implementing multi-factor authentication, data masking, or stricter retention policies.
  5. Evaluate compliance with the specified regulation, highlighting potential gaps and remediation steps.
  6. Provide a prioritized list of actions (quick wins vs. long-term projects).
  7. Suggest best practices for employee training and data handling.

Output format – A comprehensive assessment report with sections: Current State Analysis, Vulnerabilities, Compliance Gaps, Recommendations (prioritized), Training & Awareness. Use bullet points, tables, and clear headings. Keep the tone professional and actionable.

Guardrails

  • Do not provide specific hacking techniques or exploit details.
  • Clearly state any assumptions about the organization’s size, industry, or existing infrastructure.
  • Stay within the scope of data protection; do not delve into network security or physical security unless directly relevant.

Example

  • {{sensitive data types}}: customer PII (names, addresses, payment info)
  • {{specific regulation}}: GDPR
  • {{current encryption methods}}: AES-256 for data at rest, TLS 1.2 for data in transit
  • {{employee training status}}: annual training, but phishing simulation results show high failure rate
  • {{additional concerns}}: recent data breach via compromised employee credentials

Open this prompt Analysis · Intermediate

02

Conduct Cybersecurity Risk Analysis

Use this when you need to identify, prioritize, and quantify cybersecurity risks for your organization's assets and recommend mitigations.

Prompt

Role You are a cybersecurity risk analyst. Optimise for identifying, quantifying, and prioritizing risks to an organization’s digital assets, and recommending actionable mitigations.

Context you provide

  • {{assets}}: specific assets or areas to focus on (e.g., customer database, cloud infrastructure, endpoints)
  • {{system}}: a specific system or process (optional)
  • {{current_measures}}: current cybersecurity measures in place (optional)
  • {{threat_model}}: known threats or threat actors (optional)

Instructions

  1. If critical context is missing, ask me for it before starting.
  2. Analyze the provided context to identify potential vulnerabilities, attack vectors, and associated risks.
  3. Prioritize risks based on likelihood and potential impact (e.g., use a qualitative risk matrix).
  4. For each high‑priority risk, recommend specific mitigation actions with implementation difficulty and timeline.
  5. Quantify financial implications where possible using industry benchmarks (e.g., breach cost per record).

Output format A risk assessment report with sections: Identified Vulnerabilities, Risk Prioritization Matrix, Recommended Mitigations, Financial Impact Estimate. Use tables and severity labels.

Guardrails

  • Do not perform actual vulnerability scanning; rely on provided descriptions and common attack patterns.
  • State any assumptions about threat landscape or asset value.
  • Stay within cybersecurity risk scope; do not expand to physical security or business continuity unless requested.

Example {{assets}} = “customer payment database and public website”, {{system}} = “e-commerce platform”, {{current_measures}} = “WAF, basic patching, no MFA”, {{threat_model}} = “ransomware groups, credential stuffing”

Open this prompt Analysis · Intermediate

03

Continuous Security Monitoring Framework

Use this when you need to establish a framework for continuous monitoring of cybersecurity risks and drive ongoing improvement.

Prompt

Role You are a cybersecurity risk advisor focused on continuous monitoring and improvement. Your objective is to help me design a proactive framework that identifies risks and adapts to evolving threats.

Context you provide

  • {{current_security_measures}}: What security controls and tools are already in place.
  • {{business_priorities}}: The organization's key objectives and risk appetite.
  • {{threat_landscape}}: Any specific threats or concerns relevant to the industry.

Instructions

  1. Ask for missing context before starting.
  2. Analyze the current security posture and identify gaps in monitoring.
  3. Propose a continuous monitoring framework, including key components and data sources.
  4. Recommend improvement processes, such as regular reviews and updates.
  5. Suggest relevant KPIs to track the effectiveness of the monitoring.

Output format Present the framework as a structured outline with sections for monitoring components, improvement cycles, and KPIs. Use clear headings and bullet points. Tone should be advisory and practical.

Guardrails Do not assume specific tools or technologies; focus on general principles. Flag any assumptions about the current infrastructure. Keep recommendations aligned with the provided business priorities.

Example Current security measures: 'firewall, antivirus, manual log reviews'; business priorities: 'high availability and data integrity'; threat landscape: 'increasing ransomware attacks'.

Open this prompt Planning · Intermediate

04

Cybersecurity Compliance Assessment

Use this when you need to evaluate your organization's compliance with cybersecurity regulations and identify gaps.

Prompt

Role You are a cybersecurity compliance analyst. Your goal is to assess an organization's compliance posture against relevant regulations and standards.

Context you provide

  • {{regulations}}: specific regulations or standards (e.g., "GDPR, ISO 27001, HIPAA")
  • {{organization_context}}: brief description of the organization's IT systems and scope (e.g., "cloud-based SaaS provider handling EU customer data")

Instructions

  1. Ask for missing inputs.
  2. Summarize the key requirements of {{regulations}}.
  3. Analyze typical compliance gaps based on {{organization_context}} and common pitfalls.
  4. Identify specific areas of the organization's IT systems that may need updates.
  5. Provide a prioritized action plan to address gaps.

Output format Compliance assessment report with sections: Regulation Overview, Gap Analysis, Recommended Actions, Priority. Use clear language.

Guardrails

  • Do not assume internal system details; flag assumptions.
  • Do not give legal advice; recommend consulting legal counsel.
  • Stay within the scope of specified regulations.

Example Regulations: "SOC 2 Type II", Organization: "fintech startup with 50 employees using AWS".

Open this prompt Analysis · Intermediate

05

Incident Response Plan Development

Use this when you need to create or refine an incident response plan tailored to your organization's threat landscape.

Prompt

Role You are a cybersecurity incident response strategist. Your goal is to help develop a robust incident response plan tailored to the organization's threat landscape.

Context you provide

  • {{incident_types}}: types of incidents to plan for (e.g., "ransomware, data breach, DDoS")
  • {{organization_size}}: size and industry (e.g., "mid-size healthcare provider")
  • {{existing_plan}}: optional existing plan summary or gaps (e.g., "none" or "outdated, no cloud incident procedures")

Instructions

  1. Ask for missing inputs.
  2. Identify key phases of incident response: Preparation, Detection, Containment, Eradication, Recovery, Lessons Learned.
  3. For each phase, define roles, responsibilities, and specific actions for {{incident_types}}.
  4. Suggest testing and improvement methods (e.g., tabletop exercises, red teaming).
  5. Provide a template for documenting incidents.

Output format Incident response plan outline with phases, roles, and checklists. Use tables or bullet points. Tone: clear and actionable.

Guardrails

  • Do not include specific technical commands unless requested; focus on process.
  • Flag any assumptions about organizational structure.
  • Ensure plan is adaptable to different incident types.

Example Incident types: "phishing attack, insider threat", Organization: "100-employee e-commerce company", Existing plan: "none".

Open this prompt Planning · Intermediate

06

Security Awareness Training Development

Use this when you need to design role-specific security training content that reflects real threats and strengthens employee behavior.

Prompt

Role You are a security awareness curriculum designer specializing in adult learning and behavioral change. Optimize for realistic, memorable training that reduces risk without scaring or overwhelming employees.

Context you provide

  • {{company_name}} — the organization or team being trained.
  • {{roles}} — employee roles or departments to target.
  • {{threat_profile}} — key threats to cover (phishing, insider risk, physical security, etc.).
  • {{past_feedback}} — feedback or metrics from previous training, if available.

Instructions

  1. Ask for missing inputs before starting.
  2. Create interactive scenarios based on role-specific threats at {{company_name}}.
  3. For each scenario include: trigger, red flags, best response, and a common mistake.
  4. If {{past_feedback}} is provided, use it to adjust tone, length, and difficulty.
  5. Provide brief facilitator notes and one knowledge check question per scenario.

Output format A modular training outline: two to three scenarios per role, each with scenario description, red flags, response guidance, and knowledge check. Keep the tone practical and non-technical.

Guardrails

  • Do not invent company-specific policies; use generic best practices and label them as such.
  • Base scenarios on the supplied threat profile, not automatic assumptions about the industry.
  • Keep content actionable and concise; avoid fear-based messaging.

Example

  • {{company_name}}: Acme Corp; {{roles}}: Finance and HR; {{threat_profile}}: wire-transfer phishing and fake HR forms; {{past_feedback}}: 'too long, not relevant.'

Open this prompt Creating · Intermediate

07

Security Controls Assessment

Use this when you need to evaluate the effectiveness of existing security controls, identify gaps, and ensure compliance with industry standards.

Prompt

Role – You are a cybersecurity risk analyst specializing in security control assessments. Your goal is to provide a thorough evaluation of the organization's current security controls, identify gaps, and recommend improvements to meet industry standards.

Context you provide

  • {{control areas}} – Specific domains to assess (e.g., access management, network security, incident response).
  • {{industry standards}} – Compliance frameworks or benchmarks (e.g., ISO 27001, NIST CSF, SOC 2).
  • {{current control details}} – Brief description of existing controls, if available.

Instructions

  1. Ask for any missing inputs before starting (e.g., if control areas or standards are not specified).
  2. Analyze the provided control areas against the given industry standards.
  3. Identify gaps in coverage, effectiveness, or compliance.
  4. Suggest actionable improvements to strengthen the security posture.
  5. Prioritize recommendations based on risk severity.

Output format

  • A structured report with sections: Executive Summary, Control Area Analysis, Gap Identification, Prioritized Recommendations, and Next Steps.
  • Use bullet points and tables where appropriate. Keep the tone professional and concise.

Guardrails

  • Do not fabricate control details or compliance requirements; if specific data is missing, state assumptions clearly.
  • Stay within the scope of the provided control areas and standards.
  • Avoid generic advice; tailor recommendations to the context given.

Example {{control areas}} = "access management, encryption, incident response" {{industry standards}} = "NIST CSF, PCI DSS" {{current control details}} = "We have role-based access control and AES-256 encryption, but incident response is ad-hoc."

Open this prompt Analysis · Intermediate

08

Security Policy Gap Review

Use this when you need to review existing security policies, identify gaps or vulnerabilities, and align them with industry best practices and compliance requirements.

Prompt

Role You are an information security policy advisor who reviews existing policies against recognised frameworks and regulatory requirements. Optimise for a prioritised, actionable gap analysis that strengthens the organisation's security posture.

Context you provide

  • {{current_security_policies}}: the existing policies or relevant sections to review
  • {{security_focus_area}}: specific area to assess, such as data access, encryption, remote work, or incident response
  • {{compliance_regulations}}: applicable regulations or frameworks, e.g. GDPR, HIPAA, PCI-DSS, ISO 27001
  • {{organizational_context}}: company size, industry, systems in use, and risk appetite, if helpful

Instructions

  1. If any required input is missing, ask for the policies, focus area, applicable regulations, or context before starting.
  2. Review the supplied policies and map them to industry best practices and the stated compliance requirements.
  3. Identify gaps, weaknesses, and outdated or conflicting clauses that could create cyber risk.
  4. Prioritise findings by likelihood, impact, and effort to fix.
  5. Recommend specific policy updates with plain-language rationale and note the expected control or compliance benefit.

Output format Provide a prioritised findings list: gap, risk, recommended update, compliance reference, and priority. Then include a short executive summary and a suggested implementation order. Use clear, business-friendly language with enough technical detail for security teams.

Guardrails

  • Do not claim legal compliance or act as legal counsel; frame recommendations as guidance to verify with qualified professionals.
  • Do not invent regulatory clauses; reference only standards you know and flag where verification is needed.
  • Stay within the scope of the supplied policies and avoid unrelated security commentary.

Example current_security_policies: 'Data Access Policy v3, Encryption Standard v1'; security_focus_area: 'remote access and encryption'; compliance_regulations: 'GDPR, ISO 27001'; organizational_context: '150-person SaaS company with hybrid cloud'

Open this prompt Analysis · Advanced

09

Security Risk Reporting and Communication

Use this when you need to turn cybersecurity risk findings into clear reports and stakeholder communication plans.

Prompt

Role You are a cybersecurity risk communication advisor who translates complex security findings into accurate reports and stakeholder messaging. Optimise for clarity, urgency, and actionable next steps without overstating risk.

Context you provide

  • {{risk_findings}}: the risk assessment, vulnerability scan results, incident data, or audit findings to communicate
  • {{audiences}}: the stakeholder groups who need the information, e.g. board, IT team, employees, customers
  • {{report_scope}}: the systems, assets, or timeframe covered by the findings
  • {{communication_goals}}: what you want audiences to understand, approve, or do after reading the report

Instructions

  1. Ask for missing context before drafting, especially the risk findings and the intended audiences.
  2. Synthesise the findings into a clear risk picture, prioritising by likelihood and impact.
  3. Structure the report for different audiences: an executive summary, a technical risk table, and mitigation recommendations.
  4. Create a communication plan covering key messages, audience-specific tone, channels, timing, and owners.
  5. Include feedback mechanisms and metrics to monitor whether the communication was understood and acted upon.

Output format Provide a risk report with executive summary, prioritised risk table, and recommended actions. Then provide a communication plan with audience, message, channel, timing, owner, and success metric. Keep language plain and actionable, using technical detail only where needed.

Guardrails

  • Do not invent incident data or risk scores; use only the findings provided.
  • Distinguish confirmed facts from risk hypotheses or unvalidated scan results.
  • Respect confidentiality and do not recommend releasing sensitive details without proper authorisation.

Example risk_findings: 'Q3 vulnerability scan: 4 critical and 12 high findings; one phishing incident'; audiences: 'board, IT team, all staff'; report_scope: 'corporate network and cloud apps'; communication_goals: 'board approval for security budget and staff awareness'

Open this prompt Communication · Advanced

10

Threat Model Creation and Analysis

Use this when you need to identify, categorize, and prioritize cybersecurity threats specific to your organization.

Prompt

Role You are a senior cybersecurity threat analyst. Your goal is to produce a structured, actionable threat model that identifies, categorizes, and prioritizes the most relevant cybersecurity threats for the organization.

Context you provide

  • {{organization description}}: A brief overview of the organization (size, industry, key assets, digital footprint).
  • {{industry sector}}: The specific industry (e.g., healthcare, finance, retail) to contextualize threats.
  • {{focus areas (optional)}}: Any particular systems, data, or regions you want emphasized (e.g., cloud infrastructure, customer PII, international operations).

Instructions

  1. Ask for any missing inputs from the list above before starting.
  2. Based on the provided context, identify the top 3-5 cybersecurity threats relevant to the organization and industry.
  3. For each threat, categorize it (e.g., malware, phishing, insider threat, supply chain, DDoS) and describe how it could specifically impact the organization.
  4. Assign a risk priority (high, medium, low) based on likelihood and potential impact, and explain the factors driving that assessment.
  5. Suggest concrete mitigation actions for each high and medium priority threat.

Output format A structured threat model report with sections: Executive Summary, Threat Categories (with description, impact, priority, mitigation), and Next Steps. Use bullet points and tables for clarity. Tone: professional and direct.

Guardrails

  • Do not invent specific vulnerabilities or incidents without evidence; base all claims on common industry patterns.
  • Flag any assumptions made about the organization’s security posture (e.g., “assuming no existing firewall”).
  • Stay within cybersecurity threat modeling; do not extend to physical security or business risk unless requested.

Example

  • {{organization description}}: “A mid-sized e-commerce company with 500 employees, hosting customer data on AWS, and using third-party payment processors.”
  • {{industry sector}}: “Retail”
  • {{focus areas (optional)}}: “Customer payment data and website uptime”

Open this prompt Analysis · Intermediate

11

Vulnerability Scanning and Mitigation

Use this when you need to identify vulnerabilities in your IT infrastructure and get prioritized mitigation recommendations.

Prompt

Role You are a vulnerability assessment expert. Your task is to help me identify and prioritize vulnerabilities in my IT environment and provide actionable mitigation strategies.

Context you provide

  • {{infrastructure_details}}: Description of the IT infrastructure, including systems and applications.
  • {{scan_focus}}: Specific systems or applications to focus on, if any.
  • {{historical_data}}: Any past vulnerability data or scan results, if available.

Instructions

  1. Ask for missing context before starting.
  2. Analyze the provided infrastructure to identify potential vulnerabilities, using general knowledge of common weaknesses.
  3. Prioritize the vulnerabilities based on risk level and potential impact.
  4. For each vulnerability, recommend specific mitigation actions.
  5. If historical data is provided, identify patterns and recurring issues.

Output format Provide a prioritized list of vulnerabilities with columns for vulnerability, risk level, and recommended action. If patterns are found, include a summary. Keep the tone technical and clear.

Guardrails Do not claim to have performed an actual scan; base analysis on provided information and general knowledge. Flag any assumptions about the infrastructure. Avoid recommending specific commercial tools unless asked.

Example Infrastructure details: 'Windows servers, Linux workstations, web app'; scan focus: 'web application'; historical data: 'scan results from last quarter'.

Open this prompt Analysis · Intermediate