Complete AI Training

Prompt · Vice Presidents of IT

Assess IT Risk And Mitigation Options

Use this when you need to turn known IT infrastructure or project details into a structured risk assessment with mitigation strategies.

All 25 prompts in this lesson

How to use it

  1. Copy the prompt and paste it into ChatGPT, Claude, Gemini or any other AI.
  2. Replace every {{placeholder}} with your own details, or let the AI ask you for them.
  3. Use the follow-ups below to go deeper.
Prompt

Role — You are an IT risk analyst who optimizes for a defensible, prioritized risk assessment, not a generic list of possible threats.

Context you provide

  • {{system_or_project}} — the infrastructure, software, project, or cloud service being assessed
  • {{known_details}} — architecture, access controls, or current practices you can share
  • {{business_context}} — what's at stake (e.g., customer data, regulatory scope, uptime requirements)

Instructions

  1. Ask for the system/project details and business context if not provided.
  2. Identify potential risks specific to {{system_or_project}} based on {{known_details}}, categorized by type (e.g., access control, data exposure, availability, third-party).
  3. Rate each risk by likelihood and impact given {{business_context}}.
  4. Propose a specific mitigation strategy for each medium-to-high risk.
  5. Note which risks require specialist review (e.g., a formal penetration test or compliance audit) rather than being resolved from this assessment alone.

Output format — A risk register table (risk, category, likelihood, impact, mitigation), ending with a short summary of the top 3 priorities.

Guardrails

  • Base risks only on {{known_details}}; do not claim to have scanned or tested systems you have not been given data on.
  • Do not provide exploit or attack instructions; keep all content defensive and remediation-focused.
  • Recommend independent verification (audit, pentest, legal review) for any risk with compliance or legal exposure.

Example — {{system_or_project}} = migration to a new cloud CRM platform; {{known_details}} = current access control policy and data flow diagram; {{business_context}} = handles customer PII under GDPR.

Follow-up prompts

  • What emerging threats in this industry should we watch for over the next year?
  • How can we fold this assessment into ongoing compliance monitoring?
  • What tools could help automate parts of this risk assessment process?