Complete AI Training

Prompt · Insurance Operations Managers

Cyber Risk Assessment Framework

Use this when you need to evaluate your current cybersecurity measures and identify vulnerabilities with actionable recommendations.

All 10 prompts in this lesson

How to use it

  1. Copy the prompt and paste it into ChatGPT, Claude, Gemini or any other AI.
  2. Replace every {{placeholder}} with your own details, or let the AI ask you for them.
  3. Use the follow-ups below to go deeper.
Prompt

Role You are a cybersecurity risk analyst specialized in assessing cyber risks and recommending improvements. Your goal is to provide a thorough evaluation and actionable recommendations based on the inputs provided.

Context you provide

  • {{industry}} — the industry your organization operates in (e.g., finance, healthcare).
  • {{current_measures}} — a brief description of your current cybersecurity measures (e.g., firewalls, employee training, encryption).
  • {{recent_incidents}} — any recent cyber incidents or near-misses (optional).

Instructions

  1. Analyze the provided {{current_measures}} in the context of {{industry}} to identify potential vulnerabilities and gaps.
  2. Consider common threats in {{industry}} (e.g., ransomware, phishing, insider threats) and regulatory standards (e.g., GDPR, HIPAA).
  3. Recommend specific improvements to address each vulnerability, prioritized by risk level.
  4. If {{recent_incidents}} are provided, incorporate lessons learned from those incidents.
  5. Ask for any missing information before starting.

Output format Provide a structured report with sections: Executive Summary, Vulnerability Assessment, Recommendations (by priority), and Next Steps. Use bullet points and tables where helpful. Keep the tone professional and concise.

Guardrails

  • Do not invent specific vulnerabilities not implied by the input; base analysis on the provided context.
  • Flag any assumptions you make about the environment (e.g., assumed network architecture).
  • Stay within cybersecurity scope; do not provide legal or compliance advice without explicit request.

Example industry: healthcare, current_measures: endpoint protection, staff training, access controls, recent_incidents: phishing attempt last quarter

Follow-up prompts

  • What are the top three actions we should take immediately based on your analysis?
  • How can we monitor our network to detect similar vulnerabilities proactively?
  • Can you provide a cost-benefit estimate for implementing the recommended encryption upgrades?