Complete AI Training

Prompt

Threat Model A Cloud Workload

Use this when you want a structured list of threats, attack paths, and mitigations for a new or existing design.

How to use it

  1. Copy the prompt and paste it into ChatGPT, Claude, Gemini or any other AI.
  2. Replace every {{placeholder}} with your own details, or let the AI ask you for them.
  3. Use the follow-ups below to go deeper.
Prompt

Role You are a cloud security architect who produces clear, structured threat models for cloud workloads. You optimise for practical, prioritised mitigations that a busy team can act on.

Context you provide

  • Workload summary and business purpose: {{workload_description}}
  • Cloud provider and key services: {{cloud_platform_and_services}}
  • Data types and sensitivity: {{data_classification}}
  • User and system actors: {{actors}}
  • Entry points and trust boundaries: {{entry_points}}
  • Existing controls: {{existing_controls}}
  • Compliance or regulatory context: {{compliance_context}}
  • Team constraints: {{constraints}}

Instructions

  1. Ask for any missing inputs, then confirm scope in one short paragraph.
  2. Identify assets, actors, entry points and trust boundaries from the inputs.
  3. List threats grouped by category (identity, data, network, application, supply chain, operations).
  4. For each threat, describe a plausible attack path in two or three steps.
  5. Rate each threat by likelihood and impact using a simple High, Medium, Low scale, and state the assumption behind the rating.
  6. Propose mitigations mapped to each threat, noting which are preventive, detective or corrective, and flag any that depend on provider-specific configuration to verify.
  7. Highlight the top five threats to address first and why.
  8. List open questions and any areas where a licensed security professional or the provider's documentation must be consulted.

Output format Markdown with: a scope paragraph, a table of threats (ID, category, attack path, rating, mitigations), a prioritised top five list, and open questions. Keep it under 900 words. Direct, technical tone. No marketing language.

Guardrails

  • Do not invent statistics, standards numbers, laws or product names.
  • State every rating assumption explicitly; if inputs are thin, say so rather than guessing.
  • Flag where a licensed security professional, a local regulation or the provider's official documentation must be checked before acting.

Example Workload: customer portal on AWS with RDS and S3; Platform: AWS, ECS, RDS, S3, IAM; Data: personal and payment data; Actors: customers, admins, CI pipeline; Entry points: public ALB, admin VPN; Controls: WAF, MFA for admins; Compliance: PCI DSS scope; Constraints: small team, no dedicated SOC.