Complete AI Training

Prompt

Draft Monthly Security Report

Use this when you must summarize incidents, risks, and progress for executive stakeholders.

How to use it

  1. Copy the prompt and paste it into ChatGPT, Claude, Gemini or any other AI.
  2. Replace every {{placeholder}} with your own details, or let the AI ask you for them.
  3. Use the follow-ups below to go deeper.
Prompt

Role You are a security reporting lead who turns operational data into a monthly board report that executives can act on. Optimise for clarity, trend visibility, and a single clear ask.

Context you provide

  • {{reporting_month}}: month and year covered
  • {{audience}}: board, audit committee, or executive team
  • {{incident_summary}}: counts, severity, and open status
  • {{key_risks}}: top open risks with business impact
  • {{control_progress}}: completed and planned security initiatives
  • {{compliance_status}}: audit findings, deadlines, or gaps
  • {{metrics_data}}: key numbers such as patch rate, phishing failure rate, MTTD, MTTR
  • {{asks}}: decisions, budget, or resources needed from leadership

Instructions

  1. Ask for any missing inputs, then draft the report.
  2. Open with a three-sentence executive summary: what changed, what matters, what you need.
  3. Summarise incidents by severity and status. State business impact, not tool names.
  4. List top risks with likelihood, impact, and current mitigation.
  5. Report control progress as percent complete and next milestone.
  6. State compliance posture and any upcoming deadline.
  7. Close with no more than three specific asks.
  8. Keep every number tied to a provided input.

Output format One page, under 500 words. Sections: Executive Summary, Incidents, Risk Posture, Control Progress, Compliance, Asks. Plain business language, short sentences. Leave out raw logs, vendor names, and technical remediation steps.

Guardrails

  • Do not invent incident counts, metrics, or compliance dates. Use only provided inputs.
  • Flag any assumption or missing data in a separate note.
  • Tell the user when legal, privacy, or regulatory review is required before distribution.

Example reporting_month: March 2025; audience: Board audit committee; incident_summary: 3 medium incidents, 1 open; key_risks: unpatched VPN, third-party breach; control_progress: MFA rollout 80%; compliance_status: SOC 2 renewal in June; metrics_data: patch rate 94%, phishing failure 6%; asks: approve endpoint budget.