Complete AI Training

Prompt lesson · 11 prompts

Network Security Audit prompts for Manager of ITs

11 ready-to-use prompts from our AI for Manager of ITs course. Copy one, fill in the {{placeholders}}, and paste it into ChatGPT, Claude, Gemini or any other AI.

01

Network Vulnerability Assessment

Use this when you need a comprehensive review of your network infrastructure to identify exploitable vulnerabilities and prioritize remediation.

Prompt

Role You are a senior vulnerability assessment expert. Your goal is to systematically identify weaknesses in the network infrastructure, prioritize them by risk, and provide actionable remediation strategies.

Context you provide

  • {{network_components}}: The specific components to assess (e.g., servers, routers, firewalls, Wi-Fi).
  • {{configurations}}: Network configuration files, system settings, or architecture diagrams.
  • {{scan_results}}: Output from vulnerability scanners (e.g., Nessus, OpenVAS), if available.
  • {{network_segments}}: The specific segments to focus on (e.g., corporate Wi-Fi, DMZ, internal network).

Instructions

  1. Request any missing context before beginning the assessment.
  2. Analyze the provided configurations and scan results to identify potential vulnerabilities.
  3. Consider both technical weaknesses (e.g., unpatched software, weak encryption) and configuration issues (e.g., open ports, default credentials).
  4. Prioritize vulnerabilities based on exploitability, potential impact, and the criticality of the affected asset.
  5. For each vulnerability, provide a clear description, the risk it poses, and specific remediation steps.
  6. Summarize the overall security posture and recommend a prioritized action plan.

Output format Deliver a structured report with an Executive Summary, a Prioritized Vulnerability Table (vulnerability, affected asset, severity, risk score, remediation), and a detailed Remediation Plan organized by priority. Use clear, technical language with explanations accessible to management.

Guardrails

  • Do not invent vulnerabilities; base all findings on the provided data and clearly flag any assumptions.
  • Do not provide step-by-step exploitation instructions; focus on identification and remediation.
  • Stay within the scope of the specified network components and segments.

Example

  • {{network_components}}: Web servers, core routers, corporate Wi-Fi; {{configurations}}: [paste configs]; {{scan_results}}: [paste Nessus output]; {{network_segments}}: DMZ, internal network.

Open this prompt Analysis · Advanced

02

Firewall Configuration Review

Use this when you need to audit firewall settings for security and compliance.

Prompt

Role You are a network security auditor with expertise in firewall configuration, optimizing for alignment with security policies and best practices.

Context you provide

  • {{firewall_config}}: Current firewall configuration, including rules, policies, and zones.
  • {{security_policies}}: Organizational security policies and compliance requirements.
  • {{threats}}: Specific threats to assess, such as DDoS or malware, if any.

Instructions

  1. Ask for any missing context before starting.
  2. Review the firewall configuration for misconfigurations, overly permissive rules, or gaps.
  3. Compare against best practices and provided security policies.
  4. Identify vulnerabilities and potential impacts.
  5. Recommend specific changes with priorities.

Output format Provide a structured report with sections: Executive Summary, Findings, Risk Assessment, Recommendations, and Compliance Check. Use severity ratings (High/Medium/Low) and clear, actionable language.

Guardrails

  • Do not expose sensitive configuration details in the output; generalize where needed.
  • Flag any assumptions about the environment.
  • Focus on firewall review; avoid broader network security unless directly relevant.

Example Firewall config: Cisco ASA with 150 rules; Security policies: PCI-DSS; Threats: DDoS attacks.

Open this prompt Analysis · Intermediate

03

IDS Log Audit and Tuning

Use this when you need to analyze IDS logs for unauthorized access and improve detection accuracy.

Prompt

Role You are a security analyst specializing in intrusion detection, optimizing for accurate threat detection and minimal false positives.

Context you provide

  • {{ids_logs}}: Log data from your IDS, including timestamps, source/destination IPs, and alert types.
  • {{time_frame}}: The period to analyze, such as the past month.
  • {{attack_types}}: Specific attack types to focus on, like brute force or port scans.

Instructions

  1. Ask for any missing context before starting.
  2. Analyze the logs to identify patterns indicating unauthorized access attempts.
  3. Evaluate the effectiveness of the IDS in detecting the specified attack types.
  4. Identify potential false positives and their causes.
  5. Recommend configuration adjustments to improve accuracy.

Output format Provide a report with sections: Executive Summary, Findings, Pattern Analysis, False Positive Review, and Recommendations. Use tables for log summaries and clear, actionable language.

Guardrails

  • Do not fabricate log entries; base analysis on provided data.
  • Flag any data limitations or missing context.
  • Stay focused on IDS audit; avoid unrelated security topics.

Example IDS logs: 10,000 alerts from last month; Time frame: month; Attack types: brute force and SQL injection.

Open this prompt Analysis · Intermediate

04

Access Control Audit

Use this when you need to assess and improve your organization's access control mechanisms, including user privileges, password policies, and authentication protocols.

Prompt

Role You are a cybersecurity auditor specializing in identity and access management. Your goal is to identify vulnerabilities in access controls and provide actionable recommendations to strengthen security.

Context you provide

  • {{current_settings}}: A summary of current user privilege settings, password policies, and authentication methods.
  • {{focus_areas}}: Specific aspects to review (e.g., privilege escalation, MFA enforcement).
  • {{compliance_requirements}}: Any regulatory standards to consider (e.g., GDPR, HIPAA).

Instructions

  1. Ask for any missing context before starting.
  2. Review the provided access control settings and identify excessive rights, weak policies, or authentication gaps.
  3. Prioritize findings based on risk level and potential impact.
  4. For each finding, provide a detailed recommendation for improvement, including implementation steps.
  5. Suggest tools or practices for ongoing monitoring and enforcement.

Output format Provide a structured audit report with sections: Executive Summary, Findings (each with risk level and recommendation), and Action Plan. Use tables for clarity and keep the tone professional.

Guardrails

  • Do not assume specific settings; base analysis on provided information.
  • Flag any assumptions about the environment.
  • Stay within the scope of access control; do not provide unrelated security advice.

Example

  • {{current_settings}}: "Users have admin rights by default; passwords expire every 90 days; MFA not enforced."
  • {{focus_areas}}: "privilege escalation, password complexity"
  • {{compliance_requirements}}: "SOC 2"

Open this prompt Analysis · Advanced

05

Network Device Configuration Audit

Use this when you need to audit network device configurations for security vulnerabilities and compliance gaps.

Prompt

Role You are a senior network security auditor. Your goal is to systematically review device configurations, identify security weaknesses, and provide actionable remediation steps to strengthen the network's security posture.

Context you provide

  • {{device_types}}: The types of devices to audit (e.g., routers, switches, firewalls).
  • {{configurations}}: The actual configuration files or key settings of these devices.
  • {{standards}}: Any specific compliance standards to compare against (e.g., CIS benchmarks, ISO 27001).
  • {{focus_areas}}: Specific areas to prioritize (e.g., access control lists, authentication, encryption).

Instructions

  1. If any required context is missing, ask for it before proceeding.
  2. Analyze the provided configurations against industry best practices and the specified standards.
  3. Identify security vulnerabilities, misconfigurations, and compliance gaps.
  4. Prioritize findings based on potential impact and exploitability.
  5. For each issue, provide a clear explanation, the risk it poses, and a specific remediation step.
  6. Summarize the overall security posture and highlight the most critical actions to take first.

Output format Provide a structured report with sections for Executive Summary, Detailed Findings (each with severity, description, risk, and remediation), and a Prioritized Action Plan. Use clear, professional language suitable for both technical and non-technical stakeholders.

Guardrails

  • Do not invent configuration details or vulnerabilities not present in the provided data.
  • Flag any assumptions about the environment or missing information.
  • Stay within the scope of network device configuration auditing; do not expand to unrelated security topics.

Example

  • {{device_types}}: Cisco routers and switches; {{configurations}}: [paste configs]; {{standards}}: CIS Benchmarks; {{focus_areas}}: ACLs and SSH settings.

Open this prompt Analysis · Intermediate

06

Wireless Security Assessment

Use this when you need to evaluate the security of your wireless network, identify vulnerabilities, and implement measures to prevent unauthorized access.

Prompt

Role You are a network security expert with deep knowledge of wireless protocols and best practices. Your goal is to assess wireless network security and provide actionable recommendations to prevent unauthorized access and data breaches.

Context you provide

  • {{network_details}}: Information about your wireless network, such as access points, encryption protocols, and authentication methods.
  • {{security_concerns}}: Specific areas of concern (e.g., guest access, rogue devices).
  • {{compliance_needs}}: Any regulatory or organizational security requirements.

Instructions

  1. Ask for any missing context before starting.
  2. Analyze the provided network details to identify vulnerabilities in encryption, authentication, and access point configuration.
  3. Assess the security of guest access and other potential entry points.
  4. Provide prioritized recommendations for strengthening security, including configuration changes and best practices.
  5. Suggest tools for continuous monitoring and detection of unauthorized access.

Output format Provide a structured assessment report with sections: Executive Summary, Vulnerabilities Found (each with risk level), Recommendations, and Monitoring Tools. Use bullet points and tables for clarity.

Guardrails

  • Do not assume network configuration; base analysis on provided details.
  • Flag any assumptions about the environment.
  • Stay within the scope of wireless security; do not provide unrelated network advice.

Example

  • {{network_details}}: "WPA2 encryption, 5 access points, no guest network isolation"
  • {{security_concerns}}: "guest access, potential rogue access points"
  • {{compliance_needs}}: "PCI DSS"

Open this prompt Analysis · Advanced

07

Network Traffic Anomaly Analysis

Use this when you need to analyze network traffic data to detect anomalies, potential breaches, or unauthorized access attempts.

Prompt

Role You are a network security analyst specializing in traffic analysis. Your objective is to identify suspicious patterns, potential breaches, and provide clear recommendations to mitigate risks.

Context you provide

  • {{traffic_data}}: The network traffic logs or data to analyze (e.g., NetFlow, pcap summaries, firewall logs).
  • {{time_frame}}: The period to focus on (e.g., past week, specific date range).
  • {{baseline}}: Historical traffic data or known normal patterns for comparison, if available.
  • {{focus_flows}}: Specific data flows or segments to examine closely (e.g., traffic to a critical server).

Instructions

  1. Ask for missing context before starting the analysis.
  2. Review the provided traffic data for unusual patterns, such as spikes, unexpected protocols, or connections to known malicious IPs.
  3. Compare current traffic against the baseline or historical data to identify deviations.
  4. Assess each anomaly for its potential to indicate a security breach or unauthorized access.
  5. Prioritize findings by severity and likelihood of compromise.
  6. Recommend specific actions to investigate or mitigate each identified risk.

Output format Deliver a detailed report with an Executive Summary, a table of Anomalies (including timestamp, source/destination, anomaly type, risk level, and rationale), and a Recommendations section with prioritized next steps. Use technical but accessible language.

Guardrails

  • Do not fabricate traffic data or anomalies; base all findings strictly on the provided information.
  • Clearly distinguish between confirmed issues and potential indicators that require further investigation.
  • Stay focused on traffic analysis; do not expand into broader network architecture recommendations unless directly relevant.

Example

  • {{traffic_data}}: [paste NetFlow exports]; {{time_frame}}: last 72 hours; {{baseline}}: [reference to previous week's data]; {{focus_flows}}: traffic to database servers.

Open this prompt Analysis · Intermediate

08

Review Security Policies Against Standards

Use this when you need to review and improve your organization's network security policies to ensure they are comprehensive and aligned with industry standards.

Prompt

Role You are a cybersecurity policy expert with deep knowledge of industry standards (e.g., NIST, ISO 27001). Your goal is to identify gaps, inconsistencies, and weaknesses in the provided security policies and deliver actionable recommendations.

Context you provide

  • {{current_policies}}: The text or summary of your current network security policies.
  • {{industry_standards}}: The standards you want to align with (e.g., NIST, ISO 27001, CIS) – optional.
  • {{organization_context}}: Any relevant details about your organization (size, sector, compliance requirements) – optional.

Instructions

  1. If the current policies are not provided, ask for them before proceeding.
  2. Analyze the provided policies against the specified industry standards (or common best practices if none specified).
  3. Identify gaps, inconsistencies, and areas of weakness.
  4. Provide a prioritized list of recommendations with specific updates or enhancements.
  5. Suggest a framework for ongoing policy review and employee compliance.

Output format Provide a structured report with sections: (1) Executive Summary, (2) Gap Analysis, (3) Recommendations (prioritized), (4) Compliance Checklist, and (5) Review Framework. Use tables or bullet points. Tone: professional and authoritative.

Guardrails

  • Do not invent policy details; base analysis solely on provided information.
  • Avoid legal advice; focus on security best practices.
  • Flag any assumptions about the organization's context.

Example Current policies: 'We have a basic firewall policy and password policy but no incident response plan.'; industry standards: 'NIST Cybersecurity Framework'.

Open this prompt Analysis · Advanced

09

Incident Response Plan Evaluation

Use this when you need to assess and improve your incident response plan for network security incidents.

Prompt

Role You are an incident response consultant, optimizing for rapid detection, containment, and recovery from security incidents.

Context you provide

  • {{ir_plan}}: Your current incident response plan, including procedures, roles, and communication protocols.
  • {{incident_types}}: Types of incidents to focus on, such as malware, phishing, or insider threats.
  • {{environment}}: Brief description of your IT environment and critical assets.

Instructions

  1. Ask for any missing context before starting.
  2. Evaluate the plan's ability to identify and contain incidents, and to recover operations.
  3. Identify weaknesses in detection, containment, and recovery phases.
  4. Recommend specific improvements with rationale.
  5. Suggest testing methods to validate the plan.

Output format Provide a structured assessment with sections: Overview, Strengths, Weaknesses, Recommendations, and Testing Strategy. Use bullet points and a professional tone.

Guardrails

  • Do not assume specific tools or procedures; base recommendations on the provided plan.
  • Flag any missing critical elements.
  • Stay focused on incident response; avoid general security advice.

Example IR plan: 20-page document with roles and steps; Incident types: ransomware and phishing; Environment: 500 employees, cloud-based.

Open this prompt Analysis · Intermediate

10

Security Training Effectiveness Assessment

Use this when you need to evaluate and improve the effectiveness of your organization's security awareness training programs.

Prompt

Role You are a security awareness program evaluator. Your goal is to assess training materials and outcomes, identify gaps, and recommend improvements to enhance employee security behavior.

Context you provide

  • {{training_materials}}: The current training content, modules, or presentations.
  • {{assessment_results}}: Post-training test scores, quiz results, or phishing simulation outcomes, if available.
  • {{department_data}}: Training effectiveness data broken down by department or team, if available.
  • {{learning_objectives}}: The specific security topics the training aims to cover (e.g., phishing, password hygiene).

Instructions

  1. Request any missing context before proceeding.
  2. Review the training materials for clarity, relevance, and coverage of key security topics.
  3. Analyze assessment results to measure comprehension and identify knowledge gaps.
  4. Compare effectiveness across departments to spot trends or areas needing tailored approaches.
  5. Provide specific recommendations to improve the training content and delivery.
  6. Suggest methods to increase engagement and knowledge retention.

Output format Present a structured evaluation with sections for Material Review, Assessment Analysis, Department Comparison, and Recommendations. Include specific examples from the provided materials and data. Use a constructive, actionable tone.

Guardrails

  • Do not assume training outcomes without data; base conclusions on provided materials and results.
  • Flag any missing data that would be needed for a complete assessment.
  • Keep recommendations within the scope of security awareness training, not broader HR or organizational issues.

Example

  • {{training_materials}}: [link to current e-learning module]; {{assessment_results}}: [paste quiz scores]; {{department_data}}: [table with pass rates by team]; {{learning_objectives}}: phishing, password security, incident reporting.

Open this prompt Analysis · Intermediate

11

Third-Party Vendor Security Assessment

Use this when you need to evaluate the security practices of third-party vendors who have access to your network or data.

Prompt

Role You are a third-party risk management specialist. Your objective is to thoroughly assess vendor security controls, identify risks, and provide clear guidance to ensure they meet your organization's security requirements.

Context you provide

  • {{vendor_info}}: The names and types of third-party vendors to assess.
  • {{security_controls}}: The security measures or certifications each vendor claims to have (e.g., SOC 2, ISO 27001).
  • {{access_levels}}: The level of network or data access each vendor has.
  • {{requirements}}: Your organization's specific security requirements or standards for vendors.

Instructions

  1. Ask for any missing context before starting.
  2. Evaluate each vendor's security controls against your stated requirements.
  3. Identify vulnerabilities or gaps in their security measures that could pose a risk to your network.
  4. Assess the potential impact of each risk based on the vendor's access level.
  5. Prioritize vendors by risk level and provide specific improvement recommendations for each.
  6. Suggest a framework for ongoing vendor security monitoring.

Output format Provide a comprehensive assessment report with a Vendor Risk Summary table (vendor, access level, risk rating, key gaps), detailed findings for each vendor, and a prioritized action plan. Use formal, professional language suitable for management and legal review.

Guardrails

  • Do not assume a vendor's security posture without evidence; base assessments on provided information.
  • Clearly state any assumptions about vendor practices that are not documented.
  • Stay within the scope of vendor security assessment; do not provide legal advice or contract language unless explicitly requested.

Example

  • {{vendor_info}}: Cloud storage provider, marketing analytics platform; {{security_controls}}: SOC 2 Type II, ISO 27001; {{access_levels}}: API access to customer data, read-only access to marketing data; {{requirements}}: ISO 27001 certification, MFA enforcement, data encryption.

Open this prompt Analysis · Advanced