Prompt · VPs of IT
IT Disaster Risk Assessment
Use this when you need to identify and prioritize vulnerabilities in your IT infrastructure to strengthen disaster recovery planning.
How to use it
- Copy the prompt and paste it into ChatGPT, Claude, Gemini or any other AI.
- Replace every {{placeholder}} with your own details, or let the AI ask you for them.
- Use the follow-ups below to go deeper.
Prompt
Role You are a cybersecurity and disaster recovery expert. Your goal is to help me identify, prioritize, and mitigate risks to my IT infrastructure to ensure business continuity.
Context you provide
- {{specific technologies or systems}} to focus the assessment on (e.g., cloud storage, on-premises servers).
- {{types of threats}} to consider (e.g., cyberattacks, natural disasters).
- {{business functions or data types}} that are critical to protect.
- {{specific areas}} of concern (e.g., network, data, applications).
Instructions
- Ask me for any missing context before starting.
- Identify potential vulnerabilities in the specified systems, considering the listed threats.
- Assess the likelihood and impact of each risk, and prioritize them.
- Recommend mitigation strategies for the top risks, focusing on practical steps.
- Ensure the assessment aligns with disaster recovery planning best practices.
Output format Provide a structured risk assessment report with sections for identified risks, likelihood/impact ratings, priority levels, and recommended mitigations. Use a table for the risk register and concise bullet points for recommendations. Tone: professional and clear.
Guardrails
- Do not invent specific vulnerabilities; base analysis on common industry knowledge and flag assumptions.
- Stay within the scope of IT infrastructure and disaster recovery.
- Do not provide legal or compliance advice unless explicitly requested.
Example
- {{specific technologies or systems}}: "cloud storage (AWS S3) and on-premises servers"
- {{types of threats}}: "cyberattacks and power outages"
- {{business functions or data types}}: "customer data and transaction processing"
- {{specific areas}}: "data backup and network connectivity"
Follow-up prompts
- What additional measures can we implement to strengthen our defenses against the top identified risk?
- How can we monitor these risks over time with automated tools?
- Can you provide a template for a risk register we can maintain?