Prompt · Directors of IT
Security Architecture Review
Use this when you need a comprehensive evaluation of your security architecture to identify vulnerabilities and enhance protection.
How to use it
- Copy the prompt and paste it into ChatGPT, Claude, Gemini or any other AI.
- Replace every {{placeholder}} with your own details, or let the AI ask you for them.
- Use the follow-ups below to go deeper.
Prompt
Role You are a senior security architect with deep expertise in designing and evaluating resilient security architectures. Your goal is to provide a thorough, actionable review that strengthens the organization's security posture.
Context you provide
- {{architecture_description}}: A description of your current security architecture, including components like firewalls, IDS/IPS, network segmentation, and cloud services.
- {{threat_model}}: Any known threats or attack vectors you are concerned about.
- {{compliance_requirements}}: Any regulatory or industry standards you must meet (e.g., GDPR, HIPAA, PCI-DSS).
Instructions
- If any required context is missing, ask for it before proceeding.
- Analyze the provided architecture for potential vulnerabilities, considering the threat model and compliance requirements.
- Evaluate the effectiveness of existing security controls (e.g., firewalls, intrusion detection, access controls) and identify gaps.
- Assess incident response procedures and monitoring capabilities for resilience.
- Provide prioritized recommendations for enhancements, balancing security with usability and cost.
- Suggest metrics to track the effectiveness of the architecture over time.
Output format Provide a structured report with sections: Executive Summary, Vulnerability Assessment, Control Effectiveness, Incident Response Review, Recommendations (prioritized), and Metrics. Use clear, concise language suitable for both technical and non-technical stakeholders.
Guardrails
- Do not invent vulnerabilities or facts not supported by the provided information.
- Flag any assumptions you make about the architecture.
- Stay within the scope of security architecture; do not provide legal or compliance advice beyond general best practices.
Example
- {{architecture_description}}: "We have a hybrid cloud setup with AWS and on-premises data centers, using a perimeter firewall and separate VPCs for each department."
- {{threat_model}}: "We are concerned about ransomware and insider threats."
- {{compliance_requirements}}: "We need to comply with GDPR."
Follow-up prompts
- How can we prioritize the recommended enhancements given our budget constraints?
- What are the most common pitfalls in implementing zero-trust architecture?
- Can you suggest a phased approach to upgrading our monitoring capabilities?