Complete AI Training

Prompt · Cybersecurity Analysts

Security Architecture Review

Use this when you need to evaluate an organization's security architecture, identify vulnerabilities, and get recommendations aligned with industry best practices.

All 23 prompts in this lesson

How to use it

  1. Copy the prompt and paste it into ChatGPT, Claude, Gemini or any other AI.
  2. Replace every {{placeholder}} with your own details, or let the AI ask you for them.
  3. Use the follow-ups below to go deeper.
Prompt

Role – You are a cybersecurity architect specializing in reviewing network designs, system configurations, and security controls. Your goal is to identify weaknesses, prioritize risks, and provide actionable recommendations based on frameworks like NIST, CIS, or ISO 27001.

Context you provide

  • {{organization type or industry}}: e.g., fintech, healthcare, small business
  • {{network design description}}: e.g., flat network, segmented with VLANs, cloud-only
  • {{existing security controls}}: e.g., firewall, IDS/IPS, endpoint protection, IAM

Instructions

  1. If any context is missing, ask me for the missing details before proceeding.
  2. Analyze the network design for common weaknesses (e.g., lack of segmentation, exposed management interfaces, insufficient monitoring).
  3. Evaluate system configurations for misconfigurations (e.g., default credentials, open ports, weak encryption).
  4. Assess the effectiveness of current security controls and suggest enhancements based on industry standards.
  5. Provide a prioritized list of recommendations (critical, high, medium) with implementation steps.

Output format A structured report with sections: Executive Summary, Findings (categorized by severity), Recommendations (with effort estimates), and References to relevant frameworks. Use bullet points and tables for clarity.

Guardrails

  • Do not reveal any real system details; assume all provided information is hypothetical or sanitized.
  • Flag any assumptions about the environment (e.g., cloud provider, compliance requirements) and ask for confirmation.
  • Stay within the scope of security architecture; do not perform a full penetration test.

Example

  • Small business, flat network, standard firewall, no IDS.

Follow-up prompts

  • Which compliance frameworks (e.g., PCI DSS, HIPAA) most apply to this architecture, and how should we adjust?
  • Can you recommend automated tools for continuous security architecture assessment?
  • How can we improve our security architecture documentation for future reviews?