Complete AI Training

Prompt

Prioritize A Vulnerability Scan Report

Use this when you have a vulnerability scan export and need to rank findings by exploitability, exposure, and business impact instead of raw severity scores.

How to use it

  1. Copy the prompt and paste it into ChatGPT, Claude, Gemini or any other AI.
  2. Replace every {{placeholder}} with your own details, or let the AI ask you for them.
  3. Use the follow-ups below to go deeper.
Prompt

Role You are a security engineer triaging a vulnerability scan export. You optimise for a defensible, risk-based priority order that a remediation team can act on this week, not a restatement of vendor severity scores.

Context you provide

  • {{scan_export}} — pasted rows or CSV of findings (host, CVE or check name, severity, description)
  • {{asset_inventory}} — asset names, roles, owners, environment (prod, staging, internal)
  • {{exposure}} — which assets are internet-facing, partner-facing or internal only
  • {{business_criticality}} — what each asset supports and the cost of downtime or data loss
  • {{known_exploits}} — any findings with public exploit code, active exploitation reports or threat intel you hold
  • {{compensating_controls}} — WAF, network segmentation, EDR, MFA or other controls already in front of the asset
  • {{remediation_capacity}} — team size, change windows and hours available this cycle

Instructions

  1. Ask for any missing inputs, then confirm the asset list you will triage against.
  2. Normalise the findings: deduplicate, group by asset and by root cause, and flag rows with missing or ambiguous data.
  3. Score each finding on exploitability, exposure and business impact. State the reasoning in one line per finding.
  4. Rank into tiers: fix now, fix this cycle, schedule, accept with a review date.
  5. Map the top tier to the remediation capacity and note what will not fit.
  6. List the assumptions you made and the data you would need to tighten the ranking.

Output format A ranked table with columns: rank, finding, asset, tier, one-line rationale, suggested owner. Follow with a short list of assumptions and open questions. Keep it under 800 words. Plain professional tone. No vendor severity restated as the reason.

Guardrails Do not invent CVE identifiers, exploit availability or asset names; use only what is provided and mark gaps as unknown. If a finding touches regulated data, authentication infrastructure or a safety system, say so and recommend the relevant owner or compliance contact review it before scheduling. Flag any ranking that depends on an unverified assumption about exposure or compensating controls.

Example {{scan_export}} = 40 rows from a Nessus CSV; {{asset_inventory}} = 12 hosts, 3 prod web, 9 internal; {{exposure}} = 2 prod web internet-facing; {{business_criticality}} = checkout service, internal wiki, build server; {{known_exploits}} = one finding has public PoC; {{compensating_controls}} = WAF on prod web, no segmentation on internal; {{remediation_capacity}} = 2 engineers, 6 hours, next change window Thursday.