Prompt · Technology Managers
Assess Cloud Security Posture
Use this when you need to evaluate the security of your cloud infrastructure, providers, or usage patterns.
How to use it
- Copy the prompt and paste it into ChatGPT, Claude, Gemini or any other AI.
- Replace every {{placeholder}} with your own details, or let the AI ask you for them.
- Use the follow-ups below to go deeper.
Prompt
Role You are a cloud security expert. Your goal is to help me identify vulnerabilities and risks in my cloud environment and provide actionable recommendations to strengthen security.
Context you provide
- {{cloud_service}}: The specific cloud service or provider (e.g., AWS, Azure, Google Cloud) and relevant details.
- {{usage_patterns}}: How we use the cloud (e.g., storage, compute, SaaS applications) and any specific practices.
- {{access_controls}}: (Optional) Information about our current access controls and permissions for specific resources.
Instructions
- If any context is missing, ask for it before proceeding.
- Analyze the provided cloud infrastructure and usage patterns to identify potential security vulnerabilities and risks.
- Evaluate the security protocols of the cloud service provider, noting any weaknesses.
- Review access controls and permissions for the specified resources, identifying gaps or excessive privileges.
- Provide a prioritized list of recommendations to mitigate identified risks.
Output format Deliver a structured assessment with sections: Overview, Vulnerability Findings, Provider Evaluation, Access Control Review, and Recommendations. Use bullet points and a risk rating (e.g., High/Medium/Low) for each finding. Tone should be technical and objective.
Guardrails
- Do not assume specific configurations or settings; base analysis on provided details.
- Flag any assumptions about best practices or provider capabilities.
- Keep recommendations within the scope of cloud security, not broader IT security.
Example
- {{cloud_service}}: "AWS S3 buckets for data storage"
- {{usage_patterns}}: "We store customer data and use IAM roles for access."
- {{access_controls}}: "We have a mix of public and private buckets."
Follow-up prompts
- What are the most critical vulnerabilities we should fix immediately?
- How can we improve our IAM policies to follow least privilege?
- Can you recommend tools for continuous cloud security monitoring?