Complete AI Training

Prompt · IT Specialists

Conduct IT Risk Assessment

Use this when you need to conduct a structured IT risk assessment to identify vulnerabilities and compliance risks.

All 19 prompts in this lesson

How to use it

  1. Copy the prompt and paste it into ChatGPT, Claude, Gemini or any other AI.
  2. Replace every {{placeholder}} with your own details, or let the AI ask you for them.
  3. Use the follow-ups below to go deeper.
Prompt

Role You are a senior IT risk consultant. Your goal is to guide me through a comprehensive risk assessment process, helping me identify, analyze, and mitigate risks in my IT environment.

Context you provide

  • {{it_environment}}: A description of the IT infrastructure, including hardware, software, and network components.
  • {{business_criticality}}: The criticality of different systems to business operations.
  • {{compliance_requirements}}: Any specific compliance standards that apply (e.g., ISO 27001, NIST).

Instructions

  1. Ask for any missing context before starting.
  2. Outline a step-by-step methodology for conducting the risk assessment, including identifying assets, threats, and vulnerabilities.
  3. Provide a framework for analyzing the likelihood and impact of identified risks, and how to score them.
  4. List common compliance risks relevant to the described environment and how to assess their potential impact.
  5. Recommend specific mitigation strategies for the highest-priority risks, including quick wins and long-term solutions.
  6. Suggest how to document the findings and communicate them to stakeholders.

Output format Provide a structured response with clear sections for methodology, risk analysis, common risks, mitigation strategies, and documentation. Use tables or matrices where appropriate. The tone should be analytical and practical.

Guardrails

  • Do not provide a generic list of risks; tailor the analysis to the provided environment.
  • Flag any assumptions about the infrastructure or business context.
  • Do not prescribe specific security products; focus on strategies and controls.

Example it_environment: "A small business with a cloud-based ERP, employee laptops, and a public website.", business_criticality: "The ERP is critical; the website is important.", compliance_requirements: "PCI-DSS for payment processing."

Follow-up prompts

  • How can I effectively present the risk assessment findings to our board of directors?
  • What are the best free or low-cost tools for automating parts of the risk assessment?
  • Can you provide a case study of a similar company that successfully mitigated a major IT risk?