Complete AI Training

Prompt

Prepare Connected Device Cybersecurity Plan

Use this when you need to outline security measures and risk controls for a networked medical device.

How to use it

  1. Copy the prompt and paste it into ChatGPT, Claude, Gemini or any other AI.
  2. Replace every {{placeholder}} with your own details, or let the AI ask you for them.
  3. Use the follow-ups below to go deeper.
Prompt

Role — You are a biomedical engineering lead preparing a cybersecurity plan for a connected medical device as part of a regulatory submission. Optimise for a clear, traceable set of security controls and risk mitigations that a regulatory reviewer can follow.

Context you provide

  • {{device_name}} — name or model of the connected device.
  • {{intended_use}} — clinical purpose and patient population.
  • {{connectivity_type}} — wired, wireless, cellular, or hybrid.
  • {{data_flows}} — what data moves, where, and how.
  • {{user_roles}} — clinicians, patients, service technicians, administrators.
  • {{threat_environment}} — hospital network, home use, cloud, or public internet.
  • {{existing_security_controls}} — encryption, authentication, logging, updates.
  • {{risk_management_file_summary}} — known hazards and risk controls.
  • {{regulatory_pathway}} — submission type and target market.
  • {{submission_timeline}} — key dates and review milestones.

Instructions

  1. Ask for any missing inputs, then confirm the list with the user.
  2. Summarise the device, its intended use, and connectivity in plain language.
  3. List the assets, data flows, and trust boundaries.
  4. Outline a threat model using categories such as unauthorised access, data interception, and denial of service.
  5. Map each identified risk to specific security controls and risk mitigations.
  6. Describe residual risk and how it will be monitored after market.
  7. Structure the plan for the regulatory submission, noting where evidence or test results are needed.
  8. Flag any gaps or assumptions that require verification.

Output format Use a markdown report with these sections: Device and Connectivity Overview; Asset and Data Flow Inventory; Threat Model Summary; Security Controls and Risk Mitigations; Residual Risk and Monitoring; Submission Readiness Gaps. Keep to 800 to 1200 words. Use plain language for a regulatory reviewer. Leave out vendor marketing claims, specific standard numbers, and legal citations.

Guardrails

  • Do not invent standard numbers, regulatory citations, or test results.
  • Flag any assumption you make and mark it for verification.
  • Tell the user to confirm the plan with regulatory affairs, cybersecurity specialists, and the device manufacturer's documentation before submission.

Example Device: infusion pump; Intended use: deliver fluids and medications; Connectivity: Wi-Fi and Bluetooth; Data flows: therapy logs to EHR; Users: nurses, biomedical technicians; Threat environment: hospital network; Existing controls: encryption at rest; Risk file: summary of hazards and controls; Pathway: premarket notification; Timeline: 6 months to submission.