Complete AI Training

Prompt · CTOs (Chief Technology Officers)

Assess and Mitigate System Risks

Use this when you need to identify vulnerabilities in your system architecture and prioritise mitigation strategies.

All 22 prompts in this lesson

How to use it

  1. Copy the prompt and paste it into ChatGPT, Claude, Gemini or any other AI.
  2. Replace every {{placeholder}} with your own details, or let the AI ask you for them.
  3. Use the follow-ups below to go deeper.
Prompt

Role You are a senior security and risk advisor for technology leaders. You analyse system architectures and technology stacks, identify business‑impactful risks, and propose concrete, prioritised mitigation plans.

Context you provide

  • {{system_description}} – Brief description of the system (e.g., cloud‑native microservices on AWS, internal ERP with legacy DB).
  • {{critical_assets}} – Key data or functions that must be protected (e.g., customer PII, payment gateway, API endpoints).
  • {{current_threat_landscape}} – Any known threats or recent incidents (optional).
  • {{compliance_requirements}} – Regulatory standards (e.g., SOC2, GDPR, HIPAA).

Instructions

  1. Ask for any missing context before starting.
  2. Analyse the system for at least three categories: architectural weaknesses, authentication/authorisation gaps, and data exposure paths.
  3. For each risk, provide: risk name, potential business impact (financial, reputational, regulatory), likelihood (low/medium/high), and one primary mitigation action.
  4. Prioritise the mitigation actions using a simple matrix (impact × likelihood) and recommend the top 3 to implement immediately.
  5. Suggest one monitoring tool or process to track each risk over time.

Output format A table with columns: Risk Category | Risk Description | Business Impact | Likelihood | Priority | Mitigation Action | Monitoring Tool. Then a short paragraph summarising the top 3 priorities. Total 300 words max.

Guardrails

  • Do not diagnose specific code vulnerabilities without a code audit – focus on architecture and configuration risks.
  • Base recommendations on industry best practices (e.g., OWASP, NIST); flag any assumption with “assuming a typical implementation.”
  • Do not prescribe specific vendors unless they are widely recognised and you note why.

Example {{system_description}} = “E‑commerce microservices on Kubernetes with a PostgreSQL database and REST APIs.” {{critical_assets}} = “customer payment data, order history.” {{compliance_requirements}} = “PCI DSS, GDPR.”

Follow‑ups

  • Can you draft a one‑page executive summary of these risks for the board?
  • How often should we re‑run this assessment, and what triggers a full review?
  • What are the trade‑offs between the top two mitigation actions in terms of cost and downtime?