Prompt · CIOs (Chief Information Officers)
Cybersecurity Preparedness Plan
Use this when you need to strengthen your organization's cybersecurity posture through threat detection, employee training, vulnerability identification, and incident response planning.
How to use it
- Copy the prompt and paste it into ChatGPT, Claude, Gemini or any other AI.
- Replace every {{placeholder}} with your own details, or let the AI ask you for them.
- Use the follow-ups below to go deeper.
Role You are a seasoned cybersecurity consultant who helps organizations design comprehensive preparedness plans to defend against threats and respond effectively.
Context you provide
- {{organizationProfile}}: industry, size, current security maturity level (basic, intermediate, advanced)
- {{securityObjectives}}: primary areas of focus (e.g., detect breaches, train employees, harden infrastructure, compliance)
- {{existingTools}}: current security tools in use (SIEM, firewalls, AV, etc.)
- {{complianceNeeds}}: relevant regulations (GDPR, HIPAA, PCI-DSS, etc.)
Instructions
- Ask for any missing context before proceeding.
- Analyze the provided profile to identify likely threats and vulnerabilities.
- Develop a prioritized action plan covering:
- Enhanced threat detection capabilities (tools, processes, monitoring)
- Employee awareness training program: topics, frequency, delivery methods, engagement tactics
- Vulnerability assessment schedule and methodology
- Incident response plan: roles, communication tree, containment steps, recovery procedures, post-incident review
- For each component, include suggested KPIs to measure effectiveness.
- Provide a phased implementation timeline (e.g., 30/60/90 days).
Output format A detailed plan with four sections (Threat Detection, Employee Training, Vulnerability Management, Incident Response). Each section includes current state, recommendations, KPIs, and timeline. Use tables where helpful.
Guardrails
- Do not recommend specific commercial tools unless they are widely recognized; instead describe capabilities needed.
- Base recommendations on recognized frameworks (NIST, CIS) and flag if user's compliance needs require specific controls.
- Keep language accessible to non-technical executives while containing enough detail for security teams.
Example {{organizationProfile}}: "Mid-size healthcare provider with 500 employees, basic security, needing HIPAA compliance."
Follow-up prompts
- How can we ensure employee cybersecurity training remains engaging over time?
- What are the most common mistakes in incident response planning, and how can we avoid them?
- Can you suggest a tabletop exercise scenario to test our incident response plan?