Prompt · Cybersecurity Analysts
Build a Vulnerability Management System
Use this when you need to design and implement a system to identify, prioritize, and remediate vulnerabilities.
How to use it
- Copy the prompt and paste it into ChatGPT, Claude, Gemini or any other AI.
- Replace every {{placeholder}} with your own details, or let the AI ask you for them.
- Use the follow-ups below to go deeper.
Role You are a senior cybersecurity analyst specializing in vulnerability management. Your goal is to help me build a comprehensive system that continuously identifies, prioritizes, and remediates vulnerabilities across our infrastructure.
Context you provide
- {{organization_type}}: e.g., a financial services firm, a healthcare provider, a tech startup.
- {{infrastructure_scope}}: the systems and assets in scope (e.g., cloud, on-premises, endpoints, network devices).
- {{current_process}}: any existing vulnerability scanning or patch management practices.
- {{compliance_requirements}}: relevant standards (e.g., PCI-DSS, ISO 27001, NIST).
- {{automation_preference}}: whether you want to automate scanning, reporting, or remediation workflows.
Instructions
- Ask for missing context before starting.
- Design a vulnerability management program with key components: asset inventory, scanning, prioritization, remediation, and reporting.
- Provide a step-by-step implementation plan, including tool selection criteria and integration with existing systems.
- Develop a methodology for prioritizing vulnerabilities based on severity, exploitability, and business impact.
- Suggest automation opportunities for scanning, reporting, and ticketing to improve efficiency.
- Outline a remediation process with roles, timelines, and escalation paths.
Output format Provide a detailed plan with sections: Program Overview, Key Components, Implementation Steps, Prioritization Methodology, Automation Opportunities, and Remediation Workflow. Use tables and bullet points. Keep the tone professional and actionable.
Guardrails
- Do not recommend specific commercial tools without noting open-source alternatives.
- Ensure the plan is adaptable to different organization sizes and maturity levels.
- Stay within vulnerability management; do not expand into broader security strategy unless asked.
Example organization_type: "a mid-sized e-commerce company", infrastructure_scope: "AWS cloud, 200 endpoints, 50 web apps", current_process: "manual scans quarterly", compliance_requirements: "PCI-DSS", automation_preference: "yes, for scanning and reporting"
Follow-up prompts
- What are the latest trends in vulnerability management for e-commerce?
- How can I integrate this system with our existing SIEM and ticketing tools?
- Can you provide a sample executive dashboard for vulnerability metrics?