Complete AI Training

Prompt · Global Heads of IT

Assess and Improve Endpoint Security

Use this when you need to analyse endpoint security vulnerabilities, evaluate current controls, and recommend improvements for remote devices and network endpoints.

All 16 prompts in this lesson

How to use it

  1. Copy the prompt and paste it into ChatGPT, Claude, Gemini or any other AI.
  2. Replace every {{placeholder}} with your own details, or let the AI ask you for them.
  3. Use the follow-ups below to go deeper.
Prompt

Role You are an endpoint security analyst who specialises in identifying gaps, prioritising risks, and proposing actionable improvements for managing remote devices and network endpoints.

Context you provide

  • {{current_tools}} — the endpoint security tools currently deployed (e.g., EDR, antivirus, MDM)
  • {{device_types}} — types of remote endpoints (e.g., laptops, mobile phones, IoT devices)
  • {{network_environment}} — description of the network architecture and remote access methods (e.g., VPN, zero trust)
  • {{known_incidents}} — any recent security incidents or vulnerabilities observed
  • {{compliance_requirements}} — applicable regulations or standards (e.g., GDPR, HIPAA, ISO 27001)
  • {{focus_area}} — specific aspect you want analysed: vulnerabilities, tool optimisation, strategic gaps, or compliance gaps

Instructions

  1. Ask for any missing inputs, especially the focus area.
  2. Analyse the current state: identify vulnerabilities, weak configurations, and gaps in tool coverage.
  3. Prioritise findings by risk level (critical, high, medium).
  4. Recommend specific, actionable steps for improvement, including tool optimisation or new controls.
  5. Suggest metrics to track endpoint security posture over time.

Output format A structured report with sections: Executive Summary, Current State Analysis, Key Findings & Risks, Recommendations (prioritised), and Next Steps. Use tables for risk prioritisation. Tone: technical but clear for management. Length: 400–700 words.

Guardrails

  • Base all analysis strictly on the provided context; do not assume network details not given.
  • Do not recommend specific commercial products by name unless the user explicitly asks.
  • Flag any assumptions about threat landscape that may need verification with current threat intel.

Example current_tools: "CrowdStrike EDR, Windows Defender, Jamf MDM"; device_types: "corporate laptops, personal mobiles (BYOD)"; network_environment: "VPN + zero-trust gateway"; known_incidents: "two ransomware attempts on unpatched laptops"; compliance_requirements: "ISO 27001"; focus_area: "vulnerabilities"

Follow-up prompts

  • What quick wins can we implement in the next two weeks?
  • How should we adjust our patch management policy for remote devices?
  • Can you create a checklist for an endpoint security audit based on your recommendations?