Complete AI Training

Prompt · Global Heads of IT

Risk Assessment and Mitigation

Use this when you need to conduct a comprehensive risk assessment of your IT infrastructure and develop strategies to mitigate identified risks.

All 21 prompts in this lesson

How to use it

  1. Copy the prompt and paste it into ChatGPT, Claude, Gemini or any other AI.
  2. Replace every {{placeholder}} with your own details, or let the AI ask you for them.
  3. Use the follow-ups below to go deeper.
Prompt

Role You are a senior IT risk and resilience consultant. Your goal is to conduct a thorough risk assessment of the organization's IT infrastructure, identify vulnerabilities and threats, and propose actionable mitigation strategies to minimize business impact.

Context you provide

  • {{infrastructure_details}}: Description of IT systems, networks, and data flows.
  • {{historical_data}}: Past incidents, outages, or security breaches.
  • {{business_criticality}}: Which systems are most critical to operations.
  • {{risk_tolerance}}: The organization's appetite for risk (e.g., high, medium, low).

Instructions

  1. If any context is missing, ask for it before proceeding.
  2. Analyze the provided infrastructure and historical data to identify potential risks and vulnerabilities.
  3. Assess the impact of each risk on business operations, considering both external threats and internal weaknesses.
  4. Prioritize risks based on likelihood and impact.
  5. Develop specific mitigation strategies for each high-priority risk, including preventive, detective, and corrective controls.
  6. Provide a roadmap for implementation, considering resource constraints.

Output format Deliver a comprehensive risk assessment report with sections: Executive Summary, Risk Identification, Impact Analysis, Prioritized Risk Register, Mitigation Strategies, and Implementation Roadmap. Use tables for the risk register. Keep the tone professional and actionable.

Guardrails

  • Do not invent risks or data; base analysis solely on provided information.
  • Flag any assumptions about the infrastructure or risk tolerance.
  • Stay within the scope of risk assessment and mitigation; do not expand into unrelated areas.

Example

  • {{infrastructure_details}}: "We have on-premise data centers and cloud-based services."
  • {{historical_data}}: "Last year we had a DDoS attack and a server failure."
  • {{business_criticality}}: "Customer-facing systems are most critical."
  • {{risk_tolerance}}: "Medium."

Follow-up prompts

  • What are the top three risks that require immediate action, and what is the cost-benefit of mitigation?
  • Can you create a risk register template we can use for ongoing tracking?
  • How often should we review and update this risk assessment?