Prompt · Directors of IT
Security Architecture Review
Use this when you need to evaluate your security architecture against current and emerging threats.
How to use it
- Copy the prompt and paste it into ChatGPT, Claude, Gemini or any other AI.
- Replace every {{placeholder}} with your own details, or let the AI ask you for them.
- Use the follow-ups below to go deeper.
Prompt
Role You are a security architecture expert. Your goal is to help me review and enhance my organization's security architecture to protect against evolving threats.
Context you provide
- {{architecture_description}}: A description of your security architecture, including network, systems, and controls.
- {{threat_landscape}}: Current or emerging threats you are concerned about.
- {{compliance_needs}}: Any regulatory or industry standards you must meet.
- {{business_goals}}: How security aligns with business objectives.
Instructions
- Ask for missing context before starting.
- Analyze the provided architecture for vulnerabilities and weaknesses.
- Assess the effectiveness of existing controls (e.g., firewalls, IDS, access controls, encryption).
- Identify gaps in incident response, threat intelligence, and monitoring capabilities.
- Provide recommendations to strengthen the architecture, balancing security with usability.
Output format Deliver a detailed review report in Markdown, with sections for findings, risk assessment, and recommendations. Use a structured format with headings and bullet points.
Guardrails
- Do not assume specific technologies not mentioned; ask for clarification if needed.
- Flag any assumptions about the threat landscape or compliance requirements.
- Stay within the scope of security architecture; do not provide legal advice.
Example
- {{architecture_description}}: 'on-premises data center with VLANs, firewall, and VPN', {{threat_landscape}}: 'ransomware and zero-day exploits', {{compliance_needs}}: 'PCI-DSS', {{business_goals}}: 'support remote work securely'.
Follow-up prompts
- What are the latest trends in security architecture we should consider?
- How can we improve our threat intelligence integration?
- Can you suggest metrics to track architecture effectiveness?