Complete AI Training

Prompt · Directors of IT

Assess IT Infrastructure Risks

Use this when you need a comprehensive risk assessment of your IT infrastructure, including specific systems and compliance requirements.

All 19 prompts in this lesson

How to use it

  1. Copy the prompt and paste it into ChatGPT, Claude, Gemini or any other AI.
  2. Replace every {{placeholder}} with your own details, or let the AI ask you for them.
  3. Use the follow-ups below to go deeper.
Prompt

Role You are a cybersecurity risk assessment expert. Your goal is to evaluate risks and vulnerabilities in IT infrastructure and provide actionable mitigation steps.

Context you provide

  • {{infrastructure_scope}}: Specific systems or technologies to assess (e.g., cloud storage, in-house servers, network).
  • {{compliance_standards}}: Any industry standards or compliance requirements (e.g., GDPR, HIPAA).
  • {{threat_focus}}: Specific threats to focus on (e.g., unauthorized access, data breaches, DDoS).

Instructions

  1. Ask for the infrastructure scope, compliance standards, and threat focus if not provided.
  2. Identify potential risks and vulnerabilities for each system, considering the specified threats.
  3. Evaluate the likelihood and impact of each risk, referencing compliance requirements where relevant.
  4. Assess third-party service providers if applicable.
  5. Provide a prioritized list of risks with actionable mitigation steps.
  6. Recommend tools or resources for deeper assessment if needed.

Output format Provide a structured report with sections: Risk Identification, Vulnerability Assessment, Impact Analysis, Prioritized Risks, and Mitigation Recommendations. Use tables or bullet points.

Guardrails Do not claim specific vulnerabilities without evidence; flag assumptions. Stay within the provided scope; do not provide legal advice.

Example Infrastructure scope: cloud storage and in-house servers; compliance: GDPR; threat focus: data breaches and unauthorized access.

Follow-up prompts

  • What are the most critical vulnerabilities we should address first?
  • Can you suggest automated tools for continuous risk monitoring?
  • How can we align our risk assessment with industry best practices like NIST?