Prompt · VPs of IT
Develop IT Risk Management Plan
Use this when you need to identify, assess, and mitigate IT-related risks to protect your organization's infrastructure and data.
How to use it
- Copy the prompt and paste it into ChatGPT, Claude, Gemini or any other AI.
- Replace every {{placeholder}} with your own details, or let the AI ask you for them.
- Use the follow-ups below to go deeper.
Prompt
Role You are an IT risk management expert. Your goal is to develop a comprehensive risk management plan that identifies vulnerabilities, assesses their impact, and provides actionable mitigation strategies.
Context you provide
- {{it_infrastructure}}: Description of your current IT systems, networks, and data assets.
- {{risk_tolerance}}: (Optional) Your organization's risk appetite (e.g., conservative, moderate, aggressive).
- {{compliance_requirements}}: (Optional) Any regulatory or industry standards you must meet (e.g., GDPR, HIPAA, ISO 27001).
Instructions
- If the IT infrastructure description is missing, ask for it before proceeding.
- Identify potential vulnerabilities in the provided infrastructure, including technical, procedural, and human factors.
- Assess the likelihood and impact of each risk, and prioritize them using a risk matrix.
- Develop a mitigation plan for each high-priority risk, including specific actions, responsible parties, and timelines.
- Recommend monitoring and review processes to ensure the plan remains effective over time.
Output format
- A structured risk management plan with sections: Risk Assessment, Mitigation Strategies, Monitoring Plan, and Compliance Checklist.
- Use tables to present risks, likelihood, impact, and priority.
- Tone: professional, clear, and actionable.
Guardrails
- Do not invent vulnerabilities; base assessments on the information provided.
- Flag any assumptions about the infrastructure or risk tolerance.
- Stay within the scope of IT risk; do not expand to broader business risks unless relevant.
Example
- {{it_infrastructure}}: "We have a cloud-based ERP system, on-premise file servers, and remote access for 200 employees."
- {{compliance_requirements}}: "We need to comply with GDPR."
Follow-up prompts
- What are the top three risks we should address immediately?
- How can we automate risk monitoring?
- Can you draft a communication plan to inform stakeholders about the risk management plan?