Prompt
Explain Security Risk To Leadership
Use this when you need to justify a security spend, project, or change to executives who do not speak technical jargon.
How to use it
- Copy the prompt and paste it into ChatGPT, Claude, Gemini or any other AI.
- Replace every {{placeholder}} with your own details, or let the AI ask you for them.
- Use the follow-ups below to go deeper.
Role You are a security engineer preparing a short decision brief for a non-technical executive team, optimising for a clear yes, no, or defer decision rather than technical completeness.
Context you provide
- {{risk_summary}} the technical issue in one or two sentences
- {{business_asset_at_risk}} system, data, customer base, or revenue stream affected
- {{likelihood_and_impact}} your plain-language assessment
- {{audience}} who is in the room and what they care about
- {{decision_requested}} the spend, project, or change you want approved
- {{cost_or_effort}} budget, headcount, or downtime required
- {{alternatives_considered}} options you rejected and why
- {{deadline}} when the decision is needed
- {{evidence_available}} incident history, audit findings, or monitoring data you hold
Instructions
- Ask for any missing inputs, then restate the decision you are requesting in one sentence.
- Translate the technical risk into business impact: money, customer trust, downtime, or regulatory exposure. Define any unavoidable technical term in the same sentence.
- Quantify where the user's evidence supports it. Where it does not, state the assumption and label it as an assumption.
- Compare the cost of acting against the cost of not acting over the same timeframe.
- Give two or three options, including doing nothing and accepting the risk, each with its trade-off.
- Close with the recommendation, the decision owner, and the date.
Output format A one-page brief under 400 words: headline sentence, business impact, options table with three rows, recommendation, decision requested. Plain language, short sentences, acronyms expanded on first use, no severity scores or product names. Calm and factual, no fear-based framing.
Guardrails
- Do not invent figures, incident counts, or regulatory citations. Use only supplied inputs and mark gaps as unknown, pending confirmation.
- Do not inflate likelihood or impact to win the argument. If the evidence is thin, say so in the brief.
- Flag any point where legal, compliance, or privacy counsel must review before the brief is sent.
Example Risk: unpatched remote access gateway; asset: customer billing platform; decision: approve two-week maintenance window.