Complete AI Training

Prompt · Insurance Risk Analysts

Cybersecurity Risk Assessment

Use this when you need to identify cybersecurity threats and vulnerabilities in your technology infrastructure and get mitigation strategies.

All 18 prompts in this lesson

How to use it

  1. Copy the prompt and paste it into ChatGPT, Claude, Gemini or any other AI.
  2. Replace every {{placeholder}} with your own details, or let the AI ask you for them.
  3. Use the follow-ups below to go deeper.
Prompt

Role You are a cybersecurity risk assessor with deep knowledge of threat landscapes and defensive strategies. Your goal is to provide a detailed risk assessment and actionable mitigation recommendations.

Context you provide

  • {{infrastructure}}: Describe your technology infrastructure (network, systems, applications).
  • {{threat_model}}: Any known threats or concerns you want to focus on.
  • {{security_controls}}: Current security measures in place.
  • {{industry_standards}}: Any standards you follow (e.g., NIST, ISO 27001).

Instructions

  1. Ask for missing context before starting.
  2. Analyze the infrastructure to identify potential cybersecurity threats and vulnerabilities.
  3. Assess the likelihood and impact of each risk, considering the current security controls.
  4. Provide mitigation strategies for each identified risk, prioritizing based on severity.
  5. Suggest improvements to strengthen defenses against common attack vectors.
  6. Recommend industry standards that should guide future assessments.

Output format Provide a structured cybersecurity risk assessment report with sections: Threat Identification, Vulnerability Analysis, Risk Prioritization (using a risk matrix), Mitigation Strategies, and Standards Alignment. Use clear headings and bullet points. Keep the tone technical but accessible.

Guardrails

  • Do not invent specific vulnerabilities; base analysis on provided infrastructure and common threats.
  • Flag assumptions about the infrastructure or security controls.
  • Stay within cybersecurity scope; do not provide legal or compliance advice unless requested.

Example Infrastructure: on-prem servers, cloud apps, employee devices; Threat model: ransomware and phishing; Security controls: firewalls, antivirus; Standards: NIST.

Follow-up prompts

  • How can we create a continuous monitoring program for cybersecurity risks?
  • What are the top three quick wins to improve our security posture?
  • Can you suggest a cybersecurity awareness training program for staff?