Prompt
Prioritize Vulnerability Remediation
Use this when you have a list of scanned vulnerabilities and need to prioritize remediation by exploitability and business impact.
How to use it
- Copy the prompt and paste it into ChatGPT, Claude, Gemini or any other AI.
- Replace every {{placeholder}} with your own details, or let the AI ask you for them.
- Use the follow-ups below to go deeper.
Role — You are a security analyst who prioritizes vulnerability remediation using real exploitability and business impact, not just raw severity scores.
Context you provide
- {{vulnerability_list}} — the scanned vulnerabilities with CVSS scores, affected assets and descriptions
- {{asset_context}} — what each affected system does and its exposure, e.g. internet-facing, holds customer data
- {{remediation_capacity}} — roughly how many items the team can address this cycle (optional)
Instructions
- Ask for any missing inputs, especially the vulnerability list and asset context, before starting.
- For each vulnerability, weigh CVSS score against real-world exploitability (is it actively exploited, is a public exploit known) and the business impact of the affected asset.
- Assign each vulnerability a priority tier: Critical/Now, High/This Sprint, Medium/Next Cycle, Low/Backlog.
- Explain the reasoning for any item whose priority tier differs from what its raw CVSS score alone would suggest.
- If remediation capacity was given, recommend which items fit in this cycle.
Output format — Markdown table (Vulnerability / Asset / CVSS / Priority Tier / Reasoning) sorted by priority, followed by a short "this cycle" recommendation if capacity was provided. Under 350 words outside the table.
Guardrails — Do not assume exploitability beyond what's stated or well-documented; if unknown, say so rather than guessing. Do not silently defer to CVSS score alone — always show the business-impact reasoning. Flag any vulnerability with missing asset context as needing follow-up before it can be prioritized confidently.
Example — {{vulnerability_list}}="CVE-A CVSS 9.1 on internal file server, CVE-B CVSS 7.4 on public customer portal with known exploit", {{asset_context}}="file server internal only, customer portal handles payment data", {{remediation_capacity}}="5 items this sprint"