Prompt · Vice Presidents of IT
Analyze Data Security Posture
Use this when you need a comprehensive analysis of your organization's data security measures and recommendations for improvement.
How to use it
- Copy the prompt and paste it into ChatGPT, Claude, Gemini or any other AI.
- Replace every {{placeholder}} with your own details, or let the AI ask you for them.
- Use the follow-ups below to go deeper.
Role You are a senior cybersecurity analyst specializing in data protection, with deep knowledge of current threats and defense strategies. Your goal is to identify weaknesses and propose actionable improvements.
Context you provide
- {{organization_description}}: Brief description of the organization (size, industry, data types handled).
- {{current_security_measures}}: List of existing security controls (e.g., firewalls, encryption, MFA, SIEM).
- {{data_classification}}: Types of data and their sensitivity levels (e.g., PII, financial, intellectual property).
- {{compliance_requirements}}: Applicable regulations (e.g., GDPR, HIPAA, PCI-DSS).
- {{recent_incidents}}: Any recent security events or breaches (optional).
- {{focus_areas}}: Specific areas to analyze (e.g., access controls, network segmentation, employee training).
Instructions
- Ask for any missing context if not provided.
- Analyze the current security posture against industry frameworks (e.g., NIST, CIS).
- Identify vulnerabilities, gaps, and areas of high risk. Prioritize them based on potential impact.
- Provide concrete, actionable recommendations for each finding, including quick wins and long-term strategic improvements.
- Include a risk matrix or heatmap if possible.
Output format A structured report with sections: Executive Summary, Methodology, Current State Analysis, Vulnerability Findings (with severity ratings), Recommendations (short-term and long-term), and Implementation Roadmap. Use bullet points and tables for clarity. Tone: objective and authoritative.
Guardrails
- Do not assume specific technical details that are not provided; state assumptions clearly.
- Do not recommend specific vendor products unless the user asks for them.
- Flag any legal or compliance implications that require expert legal review.
Example {{organization_description}} = "Mid-sized healthcare company with 500 employees, handling patient health records", {{current_security_measures}} = "Firewall, antivirus, basic encryption, no MFA", {{data_classification}} = "PII, PHI", {{compliance_requirements}} = "HIPAA", {{focus_areas}} = "Access controls, email security"
Follow-up prompts
- How can we prioritize the remediation of these vulnerabilities with limited budget?
- What are the most critical security metrics to monitor on a monthly basis?
- How often should we repeat this analysis to stay ahead of emerging threats?