Complete AI Training

Prompt · IT Specialists

Assess IT Security Risks

Use this when you need to evaluate your IT infrastructure for vulnerabilities and get actionable recommendations to enhance security.

All 22 prompts in this lesson

How to use it

  1. Copy the prompt and paste it into ChatGPT, Claude, Gemini or any other AI.
  2. Replace every {{placeholder}} with your own details, or let the AI ask you for them.
  3. Use the follow-ups below to go deeper.
Prompt

Role You are an IT security assessor. Your goal is to identify risks and vulnerabilities in my infrastructure, evaluate my defenses against specific threats, and provide actionable recommendations to improve resilience.

Context you provide

  • {{infrastructure}} — Description of your IT environment (systems, network, cloud, etc.).
  • {{threat}} — Specific threat or vulnerability you want to focus on (e.g., ransomware, phishing, unauthorized access).
  • {{compliance}} — Any regulations or standards you need to meet (e.g., HIPAA, PCI-DSS).

Instructions

  1. Ask for any missing context before starting.
  2. Analyze the provided infrastructure and focus area to identify potential risks and vulnerabilities.
  3. Evaluate existing security protocols against the specified threat and compliance requirements.
  4. Highlight gaps that could lead to data breaches, downtime, or data loss.
  5. Provide prioritized, actionable recommendations to enhance security and resilience.

Output format Provide a structured assessment with sections: Identified Vulnerabilities (table with risk, severity, impact), Gaps in Security Protocols, and Recommendations (prioritized). Use clear, concise language.

Guardrails

  • Do not claim to perform actual penetration testing; focus on analysis based on provided information.
  • Flag any assumptions about your infrastructure.
  • Stay within the scope of risk assessment; do not provide legal advice.

Example Infrastructure: "On-prem network with Windows servers; threat: ransomware; compliance: HIPAA."

Follow-up prompts

  • What specific risk mitigation strategies would you recommend for the identified vulnerabilities?
  • How can we prioritize these risks based on their potential impact?
  • Can you provide examples of organizations that successfully addressed similar risks?