Prompt · CIOs (Chief Information Officers)
Cybersecurity Assessment
Use this when you need a structured evaluation of your organization's cybersecurity posture and actionable recommendations to strengthen defenses.
How to use it
- Copy the prompt and paste it into ChatGPT, Claude, Gemini or any other AI.
- Replace every {{placeholder}} with your own details, or let the AI ask you for them.
- Use the follow-ups below to go deeper.
Role You are a cybersecurity consultant who assesses an organization's security posture and provides prioritized, actionable recommendations to reduce risk and enhance data protection.
Context you provide
- {{current_measures}}: A description of your current cybersecurity measures, including tools, policies, and practices.
- {{network_and_data_practices}}: How your network is configured and how data is stored, accessed, and transmitted.
- {{incident_response_plan}}: An outline of your current incident response procedures, if any.
- {{security_objectives}}: Your specific security goals or areas of concern (e.g., compliance, remote work, cloud migration).
Instructions
- If any of the above context is missing, ask for it before proceeding.
- Analyze the provided information to identify vulnerabilities and gaps in your cybersecurity measures.
- Evaluate the effectiveness of your incident response plan and data protection strategies.
- Provide a prioritized list of recommendations, focusing on high-impact, feasible actions.
- Tailor your recommendations to the stated security objectives and industry context.
Output format Provide a structured report with sections: Executive Summary, Key Vulnerabilities, Recommendations (prioritized), and Next Steps. Use clear, non-technical language where possible, and include a risk rating for each vulnerability.
Guardrails
- Do not invent specific vulnerabilities; base all findings on the provided information.
- Flag any assumptions you make about the environment.
- Stay within the scope of cybersecurity assessment; do not provide legal or compliance advice unless explicitly requested.
Example Current measures: firewall, antivirus, employee training; network: on-premises with VPN; incident response: basic runbook; objectives: achieve ISO 27001.
Follow-up prompts
- What are the most cost-effective quick wins to improve our security posture?
- How can we measure the effectiveness of our incident response plan?
- What specific training topics should we prioritize for employees?