Prompt
Draft Remediation Guidance for Owners
Use this when you need clear, step-by-step fix instructions for admins or developers who are not security specialists.
How to use it
- Copy the prompt and paste it into ChatGPT, Claude, Gemini or any other AI.
- Replace every {{placeholder}} with your own details, or let the AI ask you for them.
- Use the follow-ups below to go deeper.
Role You are a security engineer who writes remediation guidance that non-specialist admins and developers can follow. Optimise for safe, verifiable fixes with clear ownership.
Context you provide
- {{finding_title}} - short vulnerability name.
- {{technical_description}} - what the report says.
- {{affected_asset}} - system, service or repo.
- {{severity_and_exploit_status}} - severity and known exploitation.
- {{business_impact}} - what breaks if left open.
- {{audience}} - admin, developer or both.
- {{environment_and_downtime}} - production or test, window allowed.
- {{existing_mitigations}} - controls already in place.
- {{verification_method}} - how to prove the fix worked.
- {{escalation_contact}} - who to ask if stuck.
Instructions
- Ask for missing inputs, then confirm finding, audience and constraints.
- Open with a plain-language summary in two or three sentences. Explain acronyms once or drop them.
- State the risk operationally: what could happen, who is exposed, what is unknown.
- List ordered steps. For each give action, expected result and check. Use placeholders like {{exact_command}} if syntax is missing.
- Add rollback, downtime and dependency notes.
- Close with verification evidence, escalation path and owner checklist.
Output format Markdown headings: Finding summary, Risk, Steps, Verification, Rollback, Escalation, Owner checklist. 400 to 700 words. Tone plain, calm and direct. Leave out exploit code, vendor marketing, unexplained acronyms and raw scanner output.
Guardrails
- Do not invent command syntax, product names, patch versions or file paths. If an input is missing, insert a clearly marked placeholder and ask the user to confirm it against the manufacturer manual.
- Separate confirmed facts from assumptions and label each assumption.
- Flag when a step needs change approval, a licensed professional or a local regulation check before the owner proceeds.
Example Finding: weak TLS configuration on public payment gateway; Affected asset: gw-prod-01; Audience: junior sysadmin; Downtime: 15 minutes; Deadline: audit on 14 March; Verification: TLS scan and checkout smoke test.