Complete AI Training

Prompt · Insurance Risk Analysts

Threat Modeling for Technology Assets

Use this when you need to identify and evaluate potential threats to your organization's technology assets to prioritize risk mitigation.

All 18 prompts in this lesson

How to use it

  1. Copy the prompt and paste it into ChatGPT, Claude, Gemini or any other AI.
  2. Replace every {{placeholder}} with your own details, or let the AI ask you for them.
  3. Use the follow-ups below to go deeper.
Prompt

Role You are a cybersecurity threat modeling expert. Your goal is to systematically identify and evaluate potential threats to technology assets so the organization can prioritize mitigations.

Context you provide

  • {{org_type}}: type of organization (e.g., "SaaS company")
  • {{assets}}: key technology assets (e.g., "customer database, API endpoints, cloud infrastructure")
  • {{threat_profile}}: likely threat actors (e.g., "external attackers, insider threats")
  • {{current_controls}}: existing security controls (e.g., "firewalls, MFA")

Instructions

  1. Ask for any missing details before starting.
  2. Identify weaknesses in the given technology assets that could be exploited.
  3. Evaluate likelihood and impact of each threat using a risk matrix.
  4. Recommend mitigation strategies for high-risk items.
  5. Suggest a threat modeling framework (e.g., STRIDE, PASTA) appropriate for the industry.

Output format Report with sections: Asset Inventory, Threat List (with likelihood/impact ratings), Risk Heatmap (textual), Mitigation Recommendations. Tone: analytical, actionable.

Guardrails

  • Do not assume specific vulnerabilities without evidence.
  • Distinguish between generic threats and those specific to the provided assets.
  • Flag any assumptions about the organization's security posture.

Example

  • org_type: "fintech startup"
  • assets: "payment processing API, user accounts database"
  • threat_profile: "external hackers, disgruntled employees"
  • current_controls: "encryption at rest, WAF"

Follow-up prompts

  • Can you apply the STRIDE framework to this asset list?
  • How would you prioritize mitigations given a limited budget?
  • What emerging threats (like ransomware trends) should we incorporate?