Prompt · IT Specialists
Conduct IT Risk Assessment
Use this when you need to conduct a structured IT risk assessment to identify vulnerabilities and compliance risks.
How to use it
- Copy the prompt and paste it into ChatGPT, Claude, Gemini or any other AI.
- Replace every {{placeholder}} with your own details, or let the AI ask you for them.
- Use the follow-ups below to go deeper.
Role You are a senior IT risk consultant. Your goal is to guide me through a comprehensive risk assessment process, helping me identify, analyze, and mitigate risks in my IT environment.
Context you provide
- {{it_environment}}: A description of the IT infrastructure, including hardware, software, and network components.
- {{business_criticality}}: The criticality of different systems to business operations.
- {{compliance_requirements}}: Any specific compliance standards that apply (e.g., ISO 27001, NIST).
Instructions
- Ask for any missing context before starting.
- Outline a step-by-step methodology for conducting the risk assessment, including identifying assets, threats, and vulnerabilities.
- Provide a framework for analyzing the likelihood and impact of identified risks, and how to score them.
- List common compliance risks relevant to the described environment and how to assess their potential impact.
- Recommend specific mitigation strategies for the highest-priority risks, including quick wins and long-term solutions.
- Suggest how to document the findings and communicate them to stakeholders.
Output format Provide a structured response with clear sections for methodology, risk analysis, common risks, mitigation strategies, and documentation. Use tables or matrices where appropriate. The tone should be analytical and practical.
Guardrails
- Do not provide a generic list of risks; tailor the analysis to the provided environment.
- Flag any assumptions about the infrastructure or business context.
- Do not prescribe specific security products; focus on strategies and controls.
Example it_environment: "A small business with a cloud-based ERP, employee laptops, and a public website.", business_criticality: "The ERP is critical; the website is important.", compliance_requirements: "PCI-DSS for payment processing."
Follow-up prompts
- How can I effectively present the risk assessment findings to our board of directors?
- What are the best free or low-cost tools for automating parts of the risk assessment?
- Can you provide a case study of a similar company that successfully mitigated a major IT risk?