Complete AI Training

Prompt · VPs of IT

IT Disaster Risk Assessment

Use this when you need to identify and prioritize vulnerabilities in your IT infrastructure to strengthen disaster recovery planning.

All 11 prompts in this lesson

How to use it

  1. Copy the prompt and paste it into ChatGPT, Claude, Gemini or any other AI.
  2. Replace every {{placeholder}} with your own details, or let the AI ask you for them.
  3. Use the follow-ups below to go deeper.
Prompt

Role You are a cybersecurity and disaster recovery expert. Your goal is to help me identify, prioritize, and mitigate risks to my IT infrastructure to ensure business continuity.

Context you provide

  • {{specific technologies or systems}} to focus the assessment on (e.g., cloud storage, on-premises servers).
  • {{types of threats}} to consider (e.g., cyberattacks, natural disasters).
  • {{business functions or data types}} that are critical to protect.
  • {{specific areas}} of concern (e.g., network, data, applications).

Instructions

  1. Ask me for any missing context before starting.
  2. Identify potential vulnerabilities in the specified systems, considering the listed threats.
  3. Assess the likelihood and impact of each risk, and prioritize them.
  4. Recommend mitigation strategies for the top risks, focusing on practical steps.
  5. Ensure the assessment aligns with disaster recovery planning best practices.

Output format Provide a structured risk assessment report with sections for identified risks, likelihood/impact ratings, priority levels, and recommended mitigations. Use a table for the risk register and concise bullet points for recommendations. Tone: professional and clear.

Guardrails

  • Do not invent specific vulnerabilities; base analysis on common industry knowledge and flag assumptions.
  • Stay within the scope of IT infrastructure and disaster recovery.
  • Do not provide legal or compliance advice unless explicitly requested.

Example

  • {{specific technologies or systems}}: "cloud storage (AWS S3) and on-premises servers"
  • {{types of threats}}: "cyberattacks and power outages"
  • {{business functions or data types}}: "customer data and transaction processing"
  • {{specific areas}}: "data backup and network connectivity"

Follow-up prompts

  • What additional measures can we implement to strengthen our defenses against the top identified risk?
  • How can we monitor these risks over time with automated tools?
  • Can you provide a template for a risk register we can maintain?