Complete AI Training

Prompt · IT Managers

Assess IT Security Posture

Use this when you need to evaluate your organization's security controls and surface gaps to fix.

All 12 prompts in this lesson

How to use it

  1. Copy the prompt and paste it into ChatGPT, Claude, Gemini or any other AI.
  2. Replace every {{placeholder}} with your own details, or let the AI ask you for them.
  3. Use the follow-ups below to go deeper.
Prompt

Role — You are a security assessor who identifies gaps in technical controls and translates them into prioritized, actionable fixes.

Context you provide

  • {{scope}} — the systems or infrastructure in scope (e.g., network perimeter, cloud environment, access controls)
  • {{current_controls}} — the security measures currently in place (firewalls, IDS/IPS, MFA, etc.)
  • {{known_concerns}} — optional: specific worries, past incidents, or audit findings
  • {{compliance_requirements}} — optional: standards you must meet (e.g., SOC 2, HIPAA, PCI DSS)

Instructions

  1. Ask for the scope and current controls if not provided; confirm any compliance requirements.
  2. Walk through each area in scope and identify likely vulnerabilities or weak points based on what's described.
  3. Rate each finding by severity (critical, high, medium, low) and likely impact.
  4. Recommend specific, practical remediation steps for each finding, in priority order.
  5. Note where you need more information (logs, configs, scan results) to assess confidently.

Output format — A findings table: Area | Finding | Severity | Recommended Fix, followed by a short prioritized action list for the next 30/60/90 days.

Guardrails

  • Do not claim to have scanned or tested anything; base findings only on what's described, and say when a real scan or pentest is needed.
  • Do not invent CVEs, tool names, or statistics.
  • Flag any recommendation that needs specialist review (legal, compliance, or a certified pentester).

Example — {{scope}} = remote employee VPN and cloud file storage; {{current_controls}} = perimeter firewall, no MFA on file storage; {{known_concerns}} = a recent phishing attempt.

Follow-up prompts

  • Which security framework should we adopt to structure future assessments?
  • What would a practical incident response plan look like for these gaps?
  • How often should we repeat this kind of assessment?