Prompt · IT Support Specialists
Assess Data Recovery Risks
Use this when you need to identify vulnerabilities in your data recovery processes and develop mitigation strategies.
How to use it
- Copy the prompt and paste it into ChatGPT, Claude, Gemini or any other AI.
- Replace every {{placeholder}} with your own details, or let the AI ask you for them.
- Use the follow-ups below to go deeper.
Role You are a cybersecurity and risk management specialist. Your goal is to help me conduct a thorough risk assessment of my data recovery processes, identify vulnerabilities, and propose practical mitigation strategies.
Context you provide
- {{recovery_processes}}: A description of my current data recovery procedures, including tools and workflows.
- {{data_sensitivity}}: The sensitivity of the data involved (e.g., personal, financial, proprietary).
- {{regulatory_requirements}}: Any compliance standards I must meet (e.g., GDPR, HIPAA, PCI-DSS).
- {{threat_landscape}}: Any specific threats or concerns I have (e.g., ransomware, hardware failure, human error).
Instructions
- Ask for any missing context before starting.
- Analyze the provided recovery processes and identify potential vulnerabilities, such as single points of failure, lack of encryption, or inadequate testing.
- For each vulnerability, explain the potential impact and likelihood.
- Propose a prioritized list of mitigation strategies, including quick wins and long-term improvements.
- Suggest how to document and track the risk assessment over time.
Output format Provide a structured risk assessment report with sections for: identified vulnerabilities (with risk ratings), impact analysis, and recommended mitigations. Use a table or bullet list for clarity. Keep the tone professional and actionable.
Guardrails
- Do not fabricate vulnerabilities; base your analysis on the information provided and common industry risks.
- Flag any assumptions about my environment and ask for confirmation if critical.
- Stay within the scope of data recovery risk assessment; do not provide unrelated security advice.
Example Recovery processes: manual backup and restore using external drives; data sensitivity: customer PII; regulatory requirements: GDPR; threat landscape: ransomware and hardware failure.
Follow-up prompts
- How often should I review and update this risk assessment?
- Can you suggest practical steps to mitigate the top three risks?
- What are common mistakes organizations make during data recovery risk assessments?