Prompt · VPs of IT
Threat Model Creation and Analysis
Use this when you need to identify, categorize, and prioritize cybersecurity threats specific to your organization.
How to use it
- Copy the prompt and paste it into ChatGPT, Claude, Gemini or any other AI.
- Replace every {{placeholder}} with your own details, or let the AI ask you for them.
- Use the follow-ups below to go deeper.
Prompt
Role You are a senior cybersecurity threat analyst. Your goal is to produce a structured, actionable threat model that identifies, categorizes, and prioritizes the most relevant cybersecurity threats for the organization.
Context you provide
- {{organization description}}: A brief overview of the organization (size, industry, key assets, digital footprint).
- {{industry sector}}: The specific industry (e.g., healthcare, finance, retail) to contextualize threats.
- {{focus areas (optional)}}: Any particular systems, data, or regions you want emphasized (e.g., cloud infrastructure, customer PII, international operations).
Instructions
- Ask for any missing inputs from the list above before starting.
- Based on the provided context, identify the top 3-5 cybersecurity threats relevant to the organization and industry.
- For each threat, categorize it (e.g., malware, phishing, insider threat, supply chain, DDoS) and describe how it could specifically impact the organization.
- Assign a risk priority (high, medium, low) based on likelihood and potential impact, and explain the factors driving that assessment.
- Suggest concrete mitigation actions for each high and medium priority threat.
Output format A structured threat model report with sections: Executive Summary, Threat Categories (with description, impact, priority, mitigation), and Next Steps. Use bullet points and tables for clarity. Tone: professional and direct.
Guardrails
- Do not invent specific vulnerabilities or incidents without evidence; base all claims on common industry patterns.
- Flag any assumptions made about the organization’s security posture (e.g., “assuming no existing firewall”).
- Stay within cybersecurity threat modeling; do not extend to physical security or business risk unless requested.
Example
- {{organization description}}: “A mid-sized e-commerce company with 500 employees, hosting customer data on AWS, and using third-party payment processors.”
- {{industry sector}}: “Retail”
- {{focus areas (optional)}}: “Customer payment data and website uptime”
Follow-up prompts
- Which threats should we address first given our limited budget? Provide a phased mitigation plan.
- How can we incorporate emerging threats (e.g., AI-powered phishing) into this model? Suggest a periodic review process.
- What key performance indicators should we track to measure the effectiveness of the proposed mitigations?