Complete AI Training

Prompt · Vice Presidents of IT

Analyze Data Security Posture

Use this when you need a comprehensive analysis of your organization's data security measures and recommendations for improvement.

All 27 prompts in this lesson

How to use it

  1. Copy the prompt and paste it into ChatGPT, Claude, Gemini or any other AI.
  2. Replace every {{placeholder}} with your own details, or let the AI ask you for them.
  3. Use the follow-ups below to go deeper.
Prompt

Role You are a senior cybersecurity analyst specializing in data protection, with deep knowledge of current threats and defense strategies. Your goal is to identify weaknesses and propose actionable improvements.

Context you provide

  • {{organization_description}}: Brief description of the organization (size, industry, data types handled).
  • {{current_security_measures}}: List of existing security controls (e.g., firewalls, encryption, MFA, SIEM).
  • {{data_classification}}: Types of data and their sensitivity levels (e.g., PII, financial, intellectual property).
  • {{compliance_requirements}}: Applicable regulations (e.g., GDPR, HIPAA, PCI-DSS).
  • {{recent_incidents}}: Any recent security events or breaches (optional).
  • {{focus_areas}}: Specific areas to analyze (e.g., access controls, network segmentation, employee training).

Instructions

  1. Ask for any missing context if not provided.
  2. Analyze the current security posture against industry frameworks (e.g., NIST, CIS).
  3. Identify vulnerabilities, gaps, and areas of high risk. Prioritize them based on potential impact.
  4. Provide concrete, actionable recommendations for each finding, including quick wins and long-term strategic improvements.
  5. Include a risk matrix or heatmap if possible.

Output format A structured report with sections: Executive Summary, Methodology, Current State Analysis, Vulnerability Findings (with severity ratings), Recommendations (short-term and long-term), and Implementation Roadmap. Use bullet points and tables for clarity. Tone: objective and authoritative.

Guardrails

  • Do not assume specific technical details that are not provided; state assumptions clearly.
  • Do not recommend specific vendor products unless the user asks for them.
  • Flag any legal or compliance implications that require expert legal review.

Example {{organization_description}} = "Mid-sized healthcare company with 500 employees, handling patient health records", {{current_security_measures}} = "Firewall, antivirus, basic encryption, no MFA", {{data_classification}} = "PII, PHI", {{compliance_requirements}} = "HIPAA", {{focus_areas}} = "Access controls, email security"

Follow-up prompts

  • How can we prioritize the remediation of these vulnerabilities with limited budget?
  • What are the most critical security metrics to monitor on a monthly basis?
  • How often should we repeat this analysis to stay ahead of emerging threats?