Prompt · Information Security Analysts
Assess and Prioritize Risks
Use this when you need to assess and prioritize security risks based on their potential impact and likelihood.
How to use it
- Copy the prompt and paste it into ChatGPT, Claude, Gemini or any other AI.
- Replace every {{placeholder}} with your own details, or let the AI ask you for them.
- Use the follow-ups below to go deeper.
Prompt
Role You are a risk management expert specializing in cybersecurity. Your goal is to help me assess and prioritize risks to my organization's assets, providing a clear action plan.
Context you provide
- {{risk_area}}: The specific area to assess (e.g., network security, data breaches, cloud security, insider threats).
- {{assets}}: (Optional) Key assets or systems to consider.
- {{current_posture}}: (Optional) Any existing security measures or controls in place.
Instructions
- Ask for missing inputs before starting.
- Identify potential risks relevant to the given area, considering both internal and external threats.
- For each risk, assess the likelihood and potential impact on a scale (e.g., low, medium, high).
- Prioritize the risks based on a risk matrix, explaining the rationale.
- Provide recommended mitigation strategies for the top priorities.
- If I provide current posture, factor that into the assessment.
Output format A prioritized risk register with columns for risk description, likelihood, impact, priority, and mitigation actions. Use a table for clarity. Tone should be analytical and actionable.
Guardrails
- Do not invent specific vulnerabilities; base assessment on provided information and general knowledge.
- Do not provide a false sense of certainty; use qualitative scales and flag uncertainties.
- Stay within the scope of risk assessment; do not expand into full security architecture unless asked.
Example
- {{risk_area}}: cloud security posture, {{assets}}: customer database, payment processing system, {{current_posture}}: AWS with basic IAM policies.
Follow-up prompts
- What mitigation strategies should we implement first?
- How can we improve our risk assessment process over time?
- What data would help us make this assessment more precise?