Complete AI Training

Prompt · VPs of IT

Threat Model Creation and Analysis

Use this when you need to identify, categorize, and prioritize cybersecurity threats specific to your organization.

All 11 prompts in this lesson

How to use it

  1. Copy the prompt and paste it into ChatGPT, Claude, Gemini or any other AI.
  2. Replace every {{placeholder}} with your own details, or let the AI ask you for them.
  3. Use the follow-ups below to go deeper.
Prompt

Role You are a senior cybersecurity threat analyst. Your goal is to produce a structured, actionable threat model that identifies, categorizes, and prioritizes the most relevant cybersecurity threats for the organization.

Context you provide

  • {{organization description}}: A brief overview of the organization (size, industry, key assets, digital footprint).
  • {{industry sector}}: The specific industry (e.g., healthcare, finance, retail) to contextualize threats.
  • {{focus areas (optional)}}: Any particular systems, data, or regions you want emphasized (e.g., cloud infrastructure, customer PII, international operations).

Instructions

  1. Ask for any missing inputs from the list above before starting.
  2. Based on the provided context, identify the top 3-5 cybersecurity threats relevant to the organization and industry.
  3. For each threat, categorize it (e.g., malware, phishing, insider threat, supply chain, DDoS) and describe how it could specifically impact the organization.
  4. Assign a risk priority (high, medium, low) based on likelihood and potential impact, and explain the factors driving that assessment.
  5. Suggest concrete mitigation actions for each high and medium priority threat.

Output format A structured threat model report with sections: Executive Summary, Threat Categories (with description, impact, priority, mitigation), and Next Steps. Use bullet points and tables for clarity. Tone: professional and direct.

Guardrails

  • Do not invent specific vulnerabilities or incidents without evidence; base all claims on common industry patterns.
  • Flag any assumptions made about the organization’s security posture (e.g., “assuming no existing firewall”).
  • Stay within cybersecurity threat modeling; do not extend to physical security or business risk unless requested.

Example

  • {{organization description}}: “A mid-sized e-commerce company with 500 employees, hosting customer data on AWS, and using third-party payment processors.”
  • {{industry sector}}: “Retail”
  • {{focus areas (optional)}}: “Customer payment data and website uptime”

Follow-up prompts

  • Which threats should we address first given our limited budget? Provide a phased mitigation plan.
  • How can we incorporate emerging threats (e.g., AI-powered phishing) into this model? Suggest a periodic review process.
  • What key performance indicators should we track to measure the effectiveness of the proposed mitigations?