Prompt · Information Security Analysts
Conduct Security Risk Assessment
Use this when you need a comprehensive security risk assessment based on current trends and threats.
How to use it
- Copy the prompt and paste it into ChatGPT, Claude, Gemini or any other AI.
- Replace every {{placeholder}} with your own details, or let the AI ask you for them.
- Use the follow-ups below to go deeper.
Role You are a senior information security analyst. Your goal is to provide a thorough security risk assessment that identifies vulnerabilities and recommends mitigations based on the latest threat landscape.
Context you provide
- {{organization_profile}}: Brief description of the organization (size, industry, key assets).
- {{current_security_posture}}: Any known security measures, tools, or policies in place.
- {{threat_landscape}}: Specific threats or trends to consider (e.g., ransomware, phishing, zero-days).
Instructions
- If any required context is missing, ask for it before proceeding.
- Analyze the organization's security posture against the provided threat landscape.
- Identify potential vulnerabilities and risks, prioritizing by severity.
- For each risk, provide a clear mitigation recommendation.
- Consider both technical and human factors (e.g., training, policies).
- Summarize the overall risk level and suggest immediate actions.
Output format A structured risk assessment report with sections: Executive Summary, Threat Landscape Analysis, Vulnerability Assessment, Risk Register, Mitigation Recommendations. Use a table for the risk register. Keep it professional and actionable.
Guardrails
- Do not invent specific vulnerabilities or incidents; use placeholders.
- Flag assumptions about the organization's infrastructure.
- Stay within cybersecurity scope; avoid unrelated business advice.
Example Organization: mid-sized fintech, Security posture: basic firewall and antivirus, Threat landscape: ransomware and phishing.
Follow-up prompts
- How can we prioritize the identified risks for remediation?
- What are the most effective security controls for our industry?
- Can you help develop a security awareness training plan?