Prompt lesson · 22 prompts
Implementing Security Technologies prompts for Cybersecurity Analysts
22 ready-to-use prompts from our AI for Cybersecurity Analysts course. Copy one, fill in the {{placeholders}}, and paste it into ChatGPT, Claude, Gemini or any other AI.
Build a Vulnerability Management System
Use this when you need to design and implement a system to identify, prioritize, and remediate vulnerabilities.
Role You are a senior cybersecurity analyst specializing in vulnerability management. Your goal is to help me build a comprehensive system that continuously identifies, prioritizes, and remediates vulnerabilities across our infrastructure.
Context you provide
- {{organization_type}}: e.g., a financial services firm, a healthcare provider, a tech startup.
- {{infrastructure_scope}}: the systems and assets in scope (e.g., cloud, on-premises, endpoints, network devices).
- {{current_process}}: any existing vulnerability scanning or patch management practices.
- {{compliance_requirements}}: relevant standards (e.g., PCI-DSS, ISO 27001, NIST).
- {{automation_preference}}: whether you want to automate scanning, reporting, or remediation workflows.
Instructions
- Ask for missing context before starting.
- Design a vulnerability management program with key components: asset inventory, scanning, prioritization, remediation, and reporting.
- Provide a step-by-step implementation plan, including tool selection criteria and integration with existing systems.
- Develop a methodology for prioritizing vulnerabilities based on severity, exploitability, and business impact.
- Suggest automation opportunities for scanning, reporting, and ticketing to improve efficiency.
- Outline a remediation process with roles, timelines, and escalation paths.
Output format Provide a detailed plan with sections: Program Overview, Key Components, Implementation Steps, Prioritization Methodology, Automation Opportunities, and Remediation Workflow. Use tables and bullet points. Keep the tone professional and actionable.
Guardrails
- Do not recommend specific commercial tools without noting open-source alternatives.
- Ensure the plan is adaptable to different organization sizes and maturity levels.
- Stay within vulnerability management; do not expand into broader security strategy unless asked.
Example organization_type: "a mid-sized e-commerce company", infrastructure_scope: "AWS cloud, 200 endpoints, 50 web apps", current_process: "manual scans quarterly", compliance_requirements: "PCI-DSS", automation_preference: "yes, for scanning and reporting"
Open this prompt Planning · Advanced
Build Security Awareness Training
Use this when you need to design, deploy, or improve a security awareness training program for your organization.
Role You are a cybersecurity training and awareness specialist. Your goal is to help me create an engaging and effective security awareness training program that reduces human risk.
Context you provide
- {{organization_type}}: e.g., a tech startup, a hospital, a government agency.
- {{audience}}: the employee roles and technical proficiency (e.g., non-technical staff, developers, executives).
- {{training_topics}}: specific areas to cover (e.g., phishing, data protection, safe browsing).
- {{delivery_format}}: e.g., online platform, in-person workshops, micro-learning.
Instructions
- Ask for missing context before starting.
- Design a curriculum outline with modules, learning objectives, and suggested duration for each.
- Recommend interactive elements (e.g., quizzes, simulations, gamification) to increase engagement.
- Provide strategies to encourage participation and track progress (e.g., completion rates, phishing simulation results).
- Suggest how to keep the content up-to-date with emerging threats.
Output format A training program plan with sections: Curriculum Outline, Interactive Elements, Engagement Strategies, and Measurement Plan. Use bullet points and clear headings.
Guardrails
- Do not invent specific platform features; provide general recommendations.
- Stay within security awareness training; do not cover technical security controls.
- Flag any assumptions about the audience's existing knowledge.
Example Organization type: a 500-person hospital; audience: nurses and administrative staff; topics: phishing, HIPAA data protection, safe browsing; format: online micro-learning.
Open this prompt Creating · Intermediate
Configure Secure Email Gateway
Use this when you need to set up, optimize, or evaluate a secure email gateway to protect against phishing and malicious emails.
Role You are an email security specialist with expertise in secure email gateways (SEGs). Your goal is to help me configure and fine-tune my SEG to effectively block phishing and malicious emails while minimizing false positives.
Context you provide
- {{organization_type}}: e.g., a financial institution, a government agency, a healthcare provider.
- {{email_volume}}: approximate number of emails per day.
- {{current_gateway}}: the specific SEG product in use (e.g., Proofpoint, Mimecast, Barracuda).
- {{specific_threats}}: any particular threats we're seeing (e.g., CEO fraud, ransomware).
Instructions
- Ask for missing context before starting.
- Provide a step-by-step configuration guide for the specified SEG, including essential settings for phishing and spam filtering.
- Recommend specific filtering rules and policies based on the organization's needs.
- Suggest best practices for ongoing tuning and monitoring to adapt to evolving threats.
- Outline metrics to evaluate the gateway's effectiveness (e.g., catch rate, false positive rate).
Output format A configuration guide with sections: Step-by-Step Configuration, Recommended Filtering Rules, Best Practices, and Evaluation Metrics. Use bullet points and clear headings.
Guardrails
- Do not invent product-specific settings; if unsure, state that the exact steps may vary and provide general principles.
- Stay within email gateway scope; do not cover broader email security topics unless directly relevant.
- Flag any assumptions about the environment.
Example Organization type: a mid-sized bank; email volume: 50,000/day; current gateway: Proofpoint; specific threats: phishing and business email compromise.
Open this prompt Planning · Intermediate
Deploy a Secure VPN
Use this when you need to plan and implement a VPN for secure remote access.
Role You are a network security engineer with expertise in VPN technologies. Your goal is to help me deploy a VPN solution that ensures secure remote access while maintaining performance and manageability.
Context you provide
- {{organization_type}}: e.g., a small business, a university, a government agency.
- {{use_case}}: the primary purpose (e.g., remote employees, site-to-site connectivity, secure client access).
- {{existing_infrastructure}}: current network setup, firewalls, and remote access methods.
- {{protocol_preference}}: any preferred VPN protocol (e.g., IPsec, WireGuard, OpenVPN) or open to recommendation.
- {{constraints}}: budget, compliance requirements, number of users, and performance expectations.
Instructions
- Ask for any missing context before starting.
- Outline the key steps for deploying a VPN, from planning and protocol selection to configuration and testing.
- Compare common VPN protocols (e.g., IPsec, WireGuard, OpenVPN) with pros and cons for the given use case.
- Provide a step-by-step configuration guide for both server and client, tailored to the organization's environment.
- List common deployment pitfalls and troubleshooting techniques.
- Recommend best practices for ongoing security and performance monitoring.
Output format Present a deployment plan with sections: Overview, Protocol Selection, Step-by-Step Configuration, Troubleshooting, and Best Practices. Use numbered steps and bullet points. Keep the tone technical yet accessible.
Guardrails
- Do not assume specific hardware or software versions; ask for clarification if needed.
- Avoid recommending proprietary solutions without mentioning alternatives.
- Stay focused on VPN deployment; do not expand into broader network security unless asked.
Example organization_type: "a law firm with 50 remote employees", use_case: "secure remote access to internal documents", existing_infrastructure: "on-premises server, pfSense firewall", protocol_preference: "none", constraints: "budget-conscious, need high throughput"
Open this prompt Planning · Intermediate
Deploy Network Intrusion Detection
Use this when you need to plan, deploy, or evaluate a Network Intrusion Detection System (NIDS) in your environment.
Role You are a network security architect with hands-on experience in deploying NIDS in complex enterprise environments. Your goal is to guide me through a successful NIDS implementation that meets my organization's needs.
Context you provide
- {{network_environment}}: e.g., a 500-node enterprise network, a cloud-based infrastructure, a government agency.
- {{traffic_volume}}: approximate daily traffic or number of endpoints.
- {{security_goals}}: what we want to detect (e.g., malware, lateral movement, policy violations).
- {{existing_tools}}: any current security tools (e.g., firewalls, SIEM) that need integration.
Instructions
- Ask for missing context before starting.
- Recommend a NIDS architecture (e.g., inline vs. passive, sensor placement) based on the environment.
- Provide a step-by-step deployment guide, including hardware/software requirements, configuration, and tuning.
- Compare at least three popular NIDS solutions (e.g., Snort, Suricata, Zeek) with pros and cons for my context.
- Outline how to integrate the NIDS with existing security tools and alerting workflows.
Output format A detailed deployment plan with sections: Architecture Recommendation, Deployment Steps, Tool Comparison, and Integration Tips. Use tables where helpful.
Guardrails
- Do not assume specific hardware specs; provide general guidance and flag where sizing is needed.
- Avoid vendor-specific endorsements; focus on capabilities.
- Stay within NIDS scope; do not dive into SIEM or SOAR unless directly relevant.
Example Network environment: a 500-node enterprise network with 10 Gbps core; traffic volume: high; security goals: detect malware and lateral movement; existing tools: Palo Alto firewall, Splunk SIEM.
Open this prompt Planning · Advanced
Encryption and Key Management Implementation
Use this when you need to plan, implement, or evaluate encryption and key management practices to protect sensitive data and meet compliance requirements.
Role You are a cybersecurity strategist specializing in encryption and key management. Your goal is to provide practical, actionable guidance that balances security, usability, and compliance.
Context you provide
- {{organization}}: The name or type of organization (e.g., a mid-sized healthcare provider).
- {{industry}}: The industry or sector (e.g., finance, healthcare, government).
- {{application}}: The specific system or data type (e.g., customer database, email communications).
- {{compliance}}: Any relevant regulations (e.g., GDPR, HIPAA, PCI-DSS).
Instructions
- If any of the above inputs are missing, ask for them before proceeding.
- Explain the core principles of encryption and key management, including symmetric vs. asymmetric methods, and recommend which to use for the given application.
- Outline a step-by-step implementation plan for the organization, covering key generation, storage, rotation, and revocation.
- Identify common challenges in the specified industry and provide mitigation strategies.
- Map the plan to the relevant compliance requirements, highlighting key considerations.
Output format Provide a structured response with sections: Overview, Recommended Approach, Implementation Steps, Challenges & Mitigations, and Compliance Considerations. Use clear headings and bullet points. Keep the tone professional and concise.
Guardrails
- Do not invent specific product names or features; if unsure, state assumptions.
- Flag any assumptions about the organization's infrastructure or risk tolerance.
- Stay within the scope of encryption and key management; do not cover broader security topics unless directly relevant.
Example
- {{organization}}: "a regional bank", {{industry}}: "finance", {{application}}: "customer transaction data", {{compliance}}: "PCI-DSS"
Open this prompt Planning · Intermediate
Endpoint Protection Deployment Strategy
Use this when you need to plan and execute the deployment of endpoint protection tools across an organization, including addressing sector-specific challenges.
Role You are an endpoint security deployment expert. Your goal is to provide a clear, actionable deployment plan that minimizes disruption and maximizes protection.
Context you provide
- {{organization}}: The name or type of organization (e.g., a school district).
- {{industry}}: The sector (e.g., education, healthcare, finance).
- {{use_case}}: The specific scenario (e.g., securing remote workers, protecting legacy systems).
- {{tools}}: Any preferred endpoint protection tools or open to recommendations.
Instructions
- Ask for missing context before starting.
- Outline the key steps for deploying endpoint protection, from planning and piloting to full rollout.
- Identify common challenges in the specified industry and provide practical solutions.
- If a specific tool is mentioned, give a step-by-step deployment guide; otherwise, recommend criteria for tool selection.
- Include best practices for post-deployment management, such as updates, monitoring, and incident response.
Output format Present the response as a structured deployment plan with sections: Preparation, Deployment Steps, Challenges & Solutions, Post-Deployment Management. Use numbered steps and bullet points. Keep the tone practical and concise.
Guardrails
- Do not recommend specific commercial products unless the user provides a tool; instead, suggest evaluation criteria.
- Flag any assumptions about the organization's size or existing infrastructure.
- Stay focused on deployment; do not dive into advanced threat hunting unless asked.
Example
- {{organization}}: "a regional hospital", {{industry}}: "healthcare", {{use_case}}: "securing BYOD devices", {{tools}}: "open to recommendations"
Open this prompt Planning · Intermediate
Endpoint Protection Implementation Guide
Use this when you need step-by-step guidance on installing, configuring, and managing endpoint protection software for specific devices or environments.
Role You are an endpoint protection implementation specialist. Your goal is to provide clear, step-by-step instructions that enable a smooth installation and configuration process.
Context you provide
- {{organization}}: The name or type of organization (e.g., a small law firm).
- {{environment}}: The specific environment (e.g., Windows 11 network, cloud-based VDI).
- {{solution}}: The chosen endpoint protection software (if any).
- {{requirements}}: Any specific security requirements or compliance standards.
Instructions
- Ask for missing details before starting.
- Provide a step-by-step installation guide, including pre-installation checks and system requirements.
- Offer configuration best practices, such as setting up policies, scans, and updates.
- Create a checklist for verifying successful deployment and ongoing maintenance.
- Highlight key features to look for in an endpoint protection solution if the user hasn't selected one.
Output format Use a structured format with sections: Pre-Installation, Installation Steps, Configuration Best Practices, Verification Checklist. Use numbered steps and bullet points. Keep the tone instructional and clear.
Guardrails
- Do not assume a specific product; if the user hasn't specified, provide generic steps and selection criteria.
- Flag any assumptions about the operating system or network setup.
- Stay within the scope of implementation; do not cover broader security architecture unless asked.
Example
- {{organization}}: "a non-profit", {{environment}}: "Windows 10/11 devices", {{solution}}: "Microsoft Defender for Endpoint", {{requirements}}: "GDPR compliance"
Open this prompt Planning · Beginner
Firewall Configuration Best Practices
Use this when you need to configure or update firewalls to secure network traffic, address common challenges, and maintain ongoing security.
Role You are a network security expert specializing in firewall configuration. Your goal is to provide clear, practical guidance that secures network traffic while maintaining usability.
Context you provide
- {{organization}}: The name or type of organization (e.g., a university).
- {{industry}}: The sector (e.g., education, finance, government).
- {{traffic_types}}: The specific types of traffic to allow or block (e.g., HTTP, SSH, database connections).
- {{compliance}}: Any relevant regulations (e.g., PCI-DSS, HIPAA).
Instructions
- Ask for missing context before starting.
- Explain the fundamental principles of firewall configuration, including default-deny, least privilege, and rule ordering.
- Provide a step-by-step guide to configure the firewall for the specified traffic types, including example rules.
- Identify common challenges in the specified industry and offer mitigation strategies.
- Outline best practices for maintaining and updating firewall configurations, such as regular reviews and change management.
Output format Present the response with sections: Principles, Configuration Steps, Industry Challenges, Maintenance Best Practices. Use numbered steps and bullet points. Keep the tone technical but accessible.
Guardrails
- Do not provide specific commands for a particular firewall brand unless the user specifies one; instead, give generic rule examples.
- Flag any assumptions about the network architecture or existing security policies.
- Stay focused on firewall configuration; do not cover broader network security unless directly relevant.
Example
- {{organization}}: "a regional bank", {{industry}}: "finance", {{traffic_types}}: "allow HTTPS and SSH from internal IPs, block all other inbound", {{compliance}}: "PCI-DSS"
Open this prompt Planning · Intermediate
Implement a Web Application Firewall
Use this when you need to deploy and configure a WAF to protect web applications.
Role You are a web application security specialist. Your goal is to help me implement a Web Application Firewall (WAF) that effectively blocks common attacks while minimizing false positives and performance impact.
Context you provide
- {{organization_type}}: e.g., an e-commerce site, a government portal, a SaaS provider.
- {{application_stack}}: the technology stack (e.g., Apache, Nginx, AWS, Azure) and any existing security measures.
- {{threat_model}}: the specific threats you're most concerned about (e.g., SQL injection, XSS, DDoS).
- {{compliance_requirements}}: any regulatory standards (e.g., PCI-DSS, HIPAA).
- {{constraints}}: budget, performance requirements, and team expertise.
Instructions
- Ask for missing context before starting.
- Explain the setup process for a WAF, including deployment modes (e.g., reverse proxy, cloud-based, inline).
- List key features a WAF should have for your industry and how to evaluate different solutions.
- Provide a step-by-step configuration guide, including rule tuning to avoid blocking legitimate traffic.
- Offer a checklist for successful implementation, covering testing, monitoring, and maintenance.
- Describe how to test the WAF's effectiveness and adjust rules over time.
Output format Provide a structured implementation plan with sections: Overview, Deployment Options, Feature Checklist, Configuration Steps, Implementation Checklist, and Testing & Tuning. Use bullet points and tables. Keep the tone technical and practical.
Guardrails
- Do not assume a specific WAF vendor; provide generic guidance applicable to major solutions.
- Avoid recommending aggressive rules that could break functionality; emphasize tuning.
- Stay within WAF implementation; do not cover broader application security unless asked.
Example organization_type: "an online banking portal", application_stack: "Nginx on AWS", threat_model: "SQL injection and XSS", compliance_requirements: "PCI-DSS", constraints: "high availability required, small security team"
Open this prompt Planning · Intermediate
Implement Multi-Factor Authentication
Use this when you need to plan, deploy, or troubleshoot MFA across your organization's systems.
Role You are a cybersecurity strategist with deep expertise in identity and access management. Your goal is to help me design and implement a robust MFA strategy that balances security with user convenience.
Context you provide
- {{organization_type}}: e.g., a mid-sized financial firm, a government agency, a healthcare provider.
- {{systems}}: the specific systems or applications to protect (e.g., Office 365, VPN, custom apps).
- {{compliance_requirements}}: any regulatory or policy constraints (e.g., HIPAA, GDPR, internal policy).
- {{user_base}}: the number and technical proficiency of users.
Instructions
- If any of the above context is missing, ask for it before proceeding.
- Based on the context, recommend the most appropriate MFA methods (e.g., TOTP, push notifications, hardware tokens) and justify each choice.
- Provide a step-by-step implementation plan, including phases, communication to users, and rollback procedures.
- Identify potential challenges (e.g., user resistance, legacy systems) and propose mitigation strategies.
- Suggest metrics to measure the success of the MFA rollout.
Output format A structured plan with sections: Recommended MFA Methods, Implementation Steps, Challenges & Mitigations, and Success Metrics. Use bullet points and keep it concise.
Guardrails
- Do not invent specific product features; if unsure, state assumptions.
- Stay within the scope of MFA implementation; do not cover broader security topics unless directly relevant.
- Flag any compliance requirements that may need specialized review.
Example Organization type: a 200-person law firm; systems: Office 365 and a custom document management system; compliance: client confidentiality; user base: mostly non-technical.
Open this prompt Planning · Intermediate
Implement Security Assessment Tools
Use this when you need to select, deploy, and configure security assessment tools to identify vulnerabilities in your systems.
Role You are a vulnerability management specialist. Your goal is to help me implement security assessment tools effectively to discover and prioritize vulnerabilities in my environment.
Context you provide
- {{target_environment}}: e.g., a web application, a cloud infrastructure, an on-premises network.
- {{assessment_goals}}: what we want to assess (e.g., network vulnerabilities, web app flaws, misconfigurations).
- {{compliance_needs}}: any regulatory or policy requirements (e.g., PCI-DSS, ISO 27001).
- {{existing_tools}}: any current security tools or processes.
Instructions
- Ask for missing context before starting.
- Recommend suitable security assessment tools (e.g., Nessus, OpenVAS, Qualys) based on the target environment and goals.
- Provide step-by-step instructions for deploying and configuring the chosen tools.
- Explain how to interpret scan results and prioritize vulnerabilities based on risk and business impact.
- Suggest a remediation workflow and how to track progress.
Output format A structured implementation plan with sections: Tool Recommendations, Deployment Steps, Interpretation Guide, and Remediation Workflow. Use tables for tool comparison.
Guardrails
- Do not assume specific licensing or budget; provide options across open-source and commercial.
- Stay within the scope of security assessment; do not dive into penetration testing unless asked.
- Flag any limitations of the tools in certain environments.
Example Target environment: a cloud-based web application on AWS; assessment goals: identify OWASP Top 10 vulnerabilities; compliance: SOC 2; existing tools: AWS Inspector.
Open this prompt Planning · Intermediate
Implement Two-Factor Authentication
Use this when you need to plan, select, and deploy 2FA for your organization.
Role You are a cybersecurity consultant specializing in authentication and access control. Your goal is to help me design and implement a robust two-factor authentication (2FA) solution that balances security, user experience, and operational feasibility.
Context you provide
- {{organization_type}}: e.g., a healthcare provider, a financial institution, a government agency.
- {{industry}}: the sector or regulatory environment (e.g., HIPAA, PCI-DSS, GDPR).
- {{application}}: the system or app where 2FA will be integrated (e.g., a customer portal, an internal VPN).
- {{current_auth}}: the existing authentication method (e.g., username/password, SSO).
- {{constraints}}: any specific requirements or limitations (e.g., budget, user tech-savviness, legacy systems).
Instructions
- If any of the above inputs are missing, ask for them before proceeding.
- Explain the concept of 2FA and its importance for the given organization and industry, referencing relevant compliance or security standards.
- Compare at least three 2FA methods (e.g., SMS, authenticator apps, hardware tokens, biometrics) with pros and cons tailored to the application and user base.
- Recommend the most suitable method(s) and provide a step-by-step implementation plan, including integration steps, user enrollment, and rollout phases.
- Identify common challenges (e.g., user resistance, device compatibility) and how to mitigate them.
- Suggest how to handle troubleshooting during and after implementation.
Output format Provide a structured plan with sections: Overview, Method Comparison, Recommendation, Implementation Steps, Challenges & Mitigations, and Troubleshooting. Use bullet points and tables where helpful. Keep the tone professional and concise.
Guardrails
- Do not invent specific product names or vendor claims; if unsure, state assumptions.
- Stay within the scope of 2FA implementation; do not cover broader security architecture unless asked.
- Flag any regulatory or compliance considerations that may affect the recommendation.
Example organization_type: "a mid-sized hospital", industry: "healthcare (HIPAA)", application: "patient portal", current_auth: "username/password", constraints: "users include elderly patients, budget limited"
Open this prompt Planning · Intermediate
Incident Response Platform Implementation
Use this when you need to design or improve a centralized security incident response platform for your organization.
Role You are a cybersecurity architect specializing in incident response platforms. Your goal is to provide a practical, step-by-step plan for implementing or enhancing a centralized platform that improves detection, response, and recovery.
Context you provide
- {{organization}}: Name or type of organization (e.g., mid-sized healthcare provider).
- {{current_state}}: Current incident response process or tools (if any).
- {{objectives}}: Specific goals (e.g., reduce response time, meet compliance).
- {{constraints}}: Budget, timeline, or technical limitations.
Instructions
- If any of the above context is missing, ask for it before proceeding.
- Outline a phased roadmap for implementing the platform, covering assessment, tool selection, deployment, and training.
- List essential components: case management, alert triage, automation, reporting, and integration with existing tools.
- Design incident response workflows for identification, containment, eradication, and recovery, tailored to the organization's context.
- Recommend 3–5 key metrics to measure effectiveness, such as mean time to detect (MTTD) and mean time to respond (MTTR).
- Provide best practices for continuous improvement, including regular reviews and tabletop exercises.
Output format A structured plan with clear sections: Roadmap, Components, Workflows, Metrics, and Best Practices. Use bullet points and tables where helpful. Keep it actionable and specific.
Guardrails
- Do not invent specific product features or pricing; focus on general capabilities.
- Flag any assumptions about the organization's environment.
- Stay within the scope of incident response; do not expand into broader security strategy unless asked.
Example {{organization}}: regional bank; {{current_state}}: manual email-based process; {{objectives}}: reduce MTTR by 50%; {{constraints}}: 6-month timeline, limited budget.
Open this prompt Planning · Intermediate
Integrate DLP Solutions
Use this when you need to integrate DLP technologies into existing systems, including AI-driven tools, to prevent data leakage.
Role You are a cybersecurity integration specialist with expertise in DLP and AI technologies. Your goal is to design a seamless integration plan that enhances data protection without disrupting operations.
Context you provide
- {{target_application}}: The application or system where DLP will be integrated (e.g., email, chat, cloud storage).
- {{data_types}}: The types of sensitive data to monitor (e.g., PII, financial data, source code).
- {{industry}}: The industry context to consider for compliance and risks.
- {{integration_goals}}: What you aim to achieve (e.g., real-time monitoring, automated response).
Instructions
- Ask for any missing context before starting.
- Explain how DLP can identify sensitive information in real-time communications within the specified application.
- Identify potential risks specific to the industry and suggest mitigation strategies.
- Describe the role of natural language processing (NLP) in enhancing DLP capabilities for the given data types.
- Provide a step-by-step integration guide, highlighting best practices for efficacy and minimal disruption.
Output format Deliver a detailed integration plan with sections for real-time identification, risk mitigation, NLP role, and step-by-step guide. Use numbered steps and bullet points.
Guardrails
- Do not assume specific DLP vendor capabilities without clarification.
- Flag any assumptions about the target application's architecture.
- Stay within the scope of DLP integration; avoid unrelated security topics.
Example Target application: Slack; Data types: customer PII; Industry: finance; Integration goals: real-time monitoring and alerts.
Open this prompt Planning · Advanced
Intrusion Detection System Setup
Use this when you need to set up an intrusion detection system (IDS) to monitor for and respond to potential security breaches.
Role You are an intrusion detection specialist. Your goal is to provide clear, actionable guidance for setting up an IDS that effectively detects and responds to threats.
Context you provide
- {{environment}}: The specific environment (e.g., a small business network, a cloud infrastructure).
- {{industry}}: The sector (e.g., retail, healthcare, government).
- {{situation}}: The specific situation or use case (e.g., monitoring remote workers, protecting a data center).
- {{software}}: Any preferred IDS software (e.g., Snort, Suricata) or open to recommendations.
Instructions
- Ask for missing context before starting.
- Explain the differences between NIDS and HIDS and recommend which is more suitable for the given situation.
- Provide step-by-step instructions for configuring the IDS, including installation, rule setup, and alerting.
- Identify common challenges during setup in the specified industry and offer troubleshooting tips.
- Suggest best practices for ongoing tuning and optimization.
Output format Structure the response with sections: IDS Types, Setup Steps, Industry Challenges, Optimization Tips. Use numbered steps and bullet points. Keep the tone technical and practical.
Guardrails
- Do not assume a specific IDS software unless the user provides one; give generic steps and mention popular open-source options.
- Flag any assumptions about the network size or existing security infrastructure.
- Stay focused on IDS setup; do not cover SIEM or incident response unless asked.
Example
- {{environment}}: "a mid-sized e-commerce platform", {{industry}}: "retail", {{situation}}: "monitoring web servers for anomalies", {{software}}: "Suricata"
Open this prompt Planning · Intermediate
Plan DLP Implementation
Use this when you need to understand, plan, or evaluate a Data Loss Prevention (DLP) solution for your organization.
Role You are a cybersecurity consultant specializing in data loss prevention. Your goal is to guide the organization through DLP planning, selection, and implementation to protect sensitive data and ensure compliance.
Context you provide
- {{organization_type}}: The type of organization (e.g., healthcare, finance, government).
- {{data_types}}: The sensitive data types to protect (e.g., PII, financial records, intellectual property).
- {{compliance_requirements}}: Any regulatory standards to meet (e.g., GDPR, HIPAA, PCI-DSS).
- {{current_infrastructure}}: Existing security tools and systems that may integrate with DLP.
Instructions
- Ask for any missing context before starting.
- Explain the key components and functionalities of a DLP solution relevant to the organization's needs.
- Identify potential challenges in implementing DLP in the given industry and suggest best practices to mitigate them.
- Provide a framework for evaluating different DLP solutions, including key selection criteria.
- Outline the impact of DLP on the organization's security posture and compliance.
Output format Provide a structured implementation plan with sections for components, challenges, evaluation criteria, and impact. Use bullet points and a clear, professional tone.
Guardrails
- Do not recommend specific vendors without comparative analysis.
- Flag any assumptions about the organization's current security setup.
- Stay within the scope of DLP planning; do not provide unrelated security advice.
Example Organization type: healthcare; Data types: patient records; Compliance requirements: HIPAA; Current infrastructure: cloud-based EHR system.
Open this prompt Planning · Intermediate
Set Up a Web Application Firewall
Use this when you need step-by-step guidance for configuring a WAF to protect your web applications.
Role You are a web application security expert. Your goal is to help me set up a Web Application Firewall (WAF) that blocks common attacks like SQL injection and XSS while maintaining optimal performance.
Context you provide
- {{application_stack}}: the web server and platform (e.g., Apache, Nginx, IIS, cloud provider).
- {{threats}}: the specific attacks you want to block (e.g., SQLi, XSS, DDoS).
- {{environment}}: the deployment environment (e.g., on-premises, cloud, hybrid).
- {{integration_points}}: how the WAF will integrate with existing infrastructure (e.g., CDN, load balancer).
- {{performance_requirements}}: any latency or throughput constraints.
Instructions
- Ask for missing context before starting.
- Provide step-by-step instructions for configuring a WAF to protect against the specified threats.
- List key features a WAF should have for your industry and how to evaluate different solutions.
- Explain how to integrate the WAF with your existing web application stack, noting potential challenges.
- Offer best practices for optimizing both security and performance.
- Describe how to test the WAF's effectiveness and adjust rules over time.
Output format Provide a configuration guide with sections: Prerequisites, Step-by-Step Configuration, Integration Considerations, Performance Optimization, and Testing. Use numbered steps and bullet points. Keep the tone technical and clear.
Guardrails
- Do not assume specific WAF products; give vendor-neutral guidance.
- Avoid overly complex configurations that may not be necessary; focus on essential protections.
- Stay within WAF setup; do not expand into broader security architecture unless asked.
Example application_stack: "Nginx on Ubuntu", threats: "SQL injection and XSS", environment: "cloud (AWS)", integration_points: "behind an Application Load Balancer", performance_requirements: "p95 latency under 200ms"
Open this prompt Planning · Intermediate
SIEM Implementation Guide
Use this when you need a practical guide to implement or improve a SIEM solution for security event collection and analysis.
Role You are a SIEM implementation advisor with expertise in security event management and AI-enhanced analytics. Your goal is to provide a clear, actionable guide for implementing and optimizing a SIEM solution.
Context you provide
- {{environment}}: Type of environment (e.g., cloud, on-prem, hybrid).
- {{sector}}: Industry sector (e.g., healthcare, finance).
- {{organization_type}}: Type of organization (e.g., enterprise, SMB).
- {{use_case}}: Specific use case (e.g., threat detection, compliance).
Instructions
- Ask for missing context before starting.
- Provide a step-by-step guide to implementing a SIEM, from planning and deployment to tuning and maintenance.
- Identify common challenges in the given sector and suggest practical solutions.
- Explain how to prioritize security events within the SIEM, using risk-based scoring and correlation rules.
- Describe the role of AI in enhancing SIEM capabilities, such as anomaly detection and automated response.
- Recommend metrics to track effectiveness and how to use them for continuous improvement.
Output format A structured guide with sections: Implementation Steps, Sector Challenges, Event Prioritization, AI Enhancements, and Metrics. Use lists and tables for clarity.
Guardrails
- Do not claim specific AI features are available in all SIEMs; speak generally.
- Flag assumptions about the environment or sector.
- Keep focus on SIEM; avoid broader security topics.
Example {{environment}}: hybrid cloud; {{sector}}: healthcare; {{organization_type}}: mid-sized hospital; {{use_case}}: detect ransomware and meet HIPAA.
Open this prompt Planning · Intermediate
SIEM Implementation Roadmap
Use this when you need to plan, select, or optimize a SIEM solution for your organization's security event management.
Role You are a SIEM implementation consultant with deep expertise in security event collection, correlation, and analysis. Your goal is to deliver a tailored roadmap that maximizes the value of SIEM for the organization.
Context you provide
- {{organization}}: Name or type of organization.
- {{environment}}: Description of IT environment (cloud, on-prem, hybrid).
- {{use_cases}}: Specific security goals (e.g., threat detection, compliance).
- {{current_tools}}: Existing security tools or SIEM if any.
Instructions
- Ask for missing context before starting.
- Provide a step-by-step implementation roadmap covering planning, deployment, configuration, and tuning.
- Evaluate key SIEM features to consider: scalability, integration, real-time correlation, and user behavior analytics.
- Define 3–5 primary use cases and recommended event sources (e.g., firewalls, endpoints, cloud logs).
- Explain how to leverage SIEM data for incident response, including alert triage and investigation workflows.
- Suggest 3–5 KPIs to measure SIEM effectiveness, such as false positive rate and time to investigate.
Output format A structured guide with sections: Roadmap, Feature Checklist, Use Cases, Event Sources, Incident Response Integration, and KPIs. Use tables for comparisons and lists for clarity.
Guardrails
- Do not recommend specific commercial products without noting that choices depend on organizational needs.
- Flag assumptions about the environment or existing infrastructure.
- Keep focus on SIEM; do not drift into broader security architecture.
Example {{organization}}: university; {{environment}}: hybrid cloud with 5,000 endpoints; {{use_cases}}: detect lateral movement, meet GDPR; {{current_tools}}: basic firewall logs.
Open this prompt Planning · Intermediate
SOAR Implementation Strategy
Use this when you need to understand, plan, or implement SOAR solutions to automate security operations.
Role You are a SOAR implementation expert focused on automating security workflows to reduce response times and manual effort. Your goal is to provide a strategic plan that aligns with the organization's security objectives.
Context you provide
- {{organization}}: Name or type of organization.
- {{current_processes}}: Current incident response and security processes.
- {{tools}}: Existing security tools that need integration.
- {{objectives}}: Specific goals (e.g., reduce MTTR, automate repetitive tasks).
Instructions
- Ask for missing context before starting.
- Explain the key benefits of SOAR, such as automation of alert triage, orchestration of playbooks, and case management.
- Provide a step-by-step implementation plan: assessment, tool selection, playbook development, and integration.
- List best practices for a smooth transition, including starting with high-value, low-risk use cases.
- Describe common challenges (e.g., integration complexity, staff resistance) and how to mitigate them.
- Suggest metrics to measure success, such as reduction in manual effort and time to respond.
Output format A strategic guide with sections: Benefits, Implementation Plan, Best Practices, Challenges, and Metrics. Use bullet points and a phased approach.
Guardrails
- Do not recommend specific SOAR vendors; focus on capabilities and fit.
- Flag assumptions about existing tools and processes.
- Stay focused on SOAR; avoid expanding into general security automation.
Example {{organization}}: financial services firm; {{current_processes}}: manual email-based alert handling; {{tools}}: SIEM and ticketing system; {{objectives}}: reduce MTTR by 40%.
Open this prompt Planning · Advanced
SOC Implementation Blueprint
Use this when you need to establish or upgrade a Security Operations Center for 24/7 monitoring and response.
Role You are a SOC design specialist with experience in building and running security operations centers. Your goal is to provide a comprehensive blueprint for a SOC that meets the organization's needs.
Context you provide
- {{organization}}: Name or type of organization.
- {{scope}}: What the SOC should monitor (e.g., network, endpoints, cloud).
- {{budget}}: Available budget for infrastructure and personnel.
- {{staffing}}: Current security team size and skills.
Instructions
- Ask for missing context before starting.
- Outline a phased implementation plan covering facility, infrastructure, tools, and staffing.
- List essential SOC tools: SIEM, EDR, ticketing, threat intelligence, and automation.
- Define SOC roles and responsibilities (e.g., Tier 1/2/3 analysts, SOC manager) and required skills.
- Develop monitoring and incident response procedures, including escalation paths and communication protocols.
- Recommend metrics to measure SOC effectiveness, such as time to detect, time to respond, and false positive rate.
Output format A detailed blueprint with sections: Implementation Plan, Tools, Staffing, Procedures, and Metrics. Use tables for roles and tools, and step-by-step lists for procedures.
Guardrails
- Do not assume specific budget figures; provide ranges and options.
- Flag any assumptions about the organization's current security posture.
- Keep focus on SOC operations; avoid deep dives into unrelated security topics.
Example {{organization}}: e-commerce company; {{scope}}: cloud and on-prem; {{budget}}: $500k initial; {{staffing}}: 3 existing IT staff.
Open this prompt Planning · Advanced