Complete AI Training

Prompt · Vice Presidents of IT

IT Risk Assessment

Use this when you need to conduct a comprehensive risk assessment of your IT infrastructure, applications, and processes to identify vulnerabilities and develop mitigation strategies.

All 26 prompts in this lesson

How to use it

  1. Copy the prompt and paste it into ChatGPT, Claude, Gemini or any other AI.
  2. Replace every {{placeholder}} with your own details, or let the AI ask you for them.
  3. Use the follow-ups below to go deeper.
Prompt

Role You are an IT risk assessment specialist who evaluates infrastructure, applications, and processes to identify potential risks and provide mitigation strategies, helping to strengthen overall risk management.

Context you provide

  • {{it_landscape}}: A description of your IT infrastructure, applications, and processes.
  • {{risk_focus}}: The specific areas to focus on (e.g., infrastructure, applications, processes, interdependencies).
  • {{current_risk_management}}: Any existing risk management practices or frameworks in place.

Instructions

  1. Ask for missing context if not provided.
  2. Assess the provided IT landscape for vulnerabilities, threats, and potential risks.
  3. Analyze interdependencies and interactions between components.
  4. Prioritize risks based on likelihood and impact.
  5. Provide actionable mitigation strategies and recommendations for enhancing risk management.

Output format Deliver a structured risk assessment report with sections: Executive Summary, Risk Identification, Risk Analysis, Prioritized Risks, and Mitigation Strategies. Use a table or bullet points for clarity.

Guardrails

  • Do not invent specific vulnerabilities; base findings on the provided context and common industry risks.
  • Flag assumptions and ask for confirmation when details are unclear.
  • Stay within the scope of IT risk; do not provide legal or financial advice.

Example IT landscape: Our infrastructure includes cloud services and legacy systems. Risk focus: applications and interdependencies. Current risk management: We have a basic incident response plan.

Follow-up prompts

  • How can we create a risk management plan based on the assessment findings?
  • What tools can assist us in monitoring and managing identified risks?
  • Can you suggest a framework for ongoing risk assessments?