Complete AI Training

Prompt

Security Metrics Board Summary

Use this when you need a narrative summary of security metrics for a leadership or board update.

How to use it

  1. Copy the prompt and paste it into ChatGPT, Claude, Gemini or any other AI.
  2. Replace every {{placeholder}} with your own details, or let the AI ask you for them.
  3. Use the follow-ups below to go deeper.
Prompt

Role — You are a security lead who turns raw security metrics into a narrative summary a board or executive audience can actually understand and act on.

Context you provide

  • {{metrics_data}} — the raw metrics for the period, such as incidents, mean time to detect/respond, vulnerability counts, patch compliance, or phishing test results
  • {{period_covered}} — the reporting period and prior period for comparison, if available
  • {{notable_events}} — any significant incidents, audits or initiatives during the period
  • {{audience_context}} — how technical the board or audience is, and what they care about, such as risk exposure, compliance status, or budget justification

Instructions

  1. Ask for any missing inputs before drafting.
  2. Open with a one-paragraph executive summary of overall security posture this period — improving, stable, or concerning — grounded in the metrics.
  3. Translate each key metric into business-relevant language: what it means for risk, not just the raw number.
  4. Compare to the prior period if given, noting trend direction.
  5. Cover notable_events with impact and current status, such as resolved, ongoing, or monitoring.
  6. Close with two to three recommended actions or investments, tied to what the metrics show.

Output format — A board-ready summary (Executive Summary, Key Metrics with plain-language interpretation, Notable Events, Recommendations), non-technical tone, free of jargon, under 400 words.

Guardrails — Do not invent metrics, incident details or trend data that weren't provided. Do not understate a concerning trend to sound reassuring — present it factually with the recommended response.

Example — metrics_data: "3 incidents this quarter, down from 5; mean time to detect improved from 6 hours to 2 hours; patch compliance at 87%"; period_covered: "Q3 vs. Q2"; notable_events: "one phishing incident led to a contained credential compromise, resolved within 24 hours"; audience_context: "board is non-technical, cares about risk exposure and whether a budget increase is justified."