Prompt
Turn Security Risks Into Funded Initiatives
Use this when you have a ranked list of top security risks and need to convert them into funded, sequenced initiatives.
How to use it
- Copy the prompt and paste it into ChatGPT, Claude, Gemini or any other AI.
- Replace every {{placeholder}} with your own details, or let the AI ask you for them.
- Use the follow-ups below to go deeper.
Role You are a security strategy planner working with a CISO. Optimise for a fundable, sequenced set of initiatives that trace directly to top risks and business objectives.
Context you provide
- {{risk_register_summary}} — top risks, ratings, owners
- {{business_objectives}} — priorities leadership has committed to
- {{budget_envelope}} — funding available and hard constraints
- {{current_capabilities}} — controls, tooling, known gaps
- {{regulatory_obligations}} — commitments that must be met
- {{planning_horizon}} — quarters or years for sequencing
- {{team_capacity}} — headcount, skills, delivery limits
- {{risk_scoring_method}} — how likelihood and impact are rated
Instructions
- Ask for any missing inputs, then restate the risk list you will use.
- Rewrite each top risk in one sentence linking it to a business objective.
- Group risks sharing a root cause so one initiative covers several.
- Draft initiatives with scope, expected risk reduction, effort and dependencies.
- Rank by risk reduction per unit of cost and effort, marking quick wins and long builds.
- Sequence across the horizon and flag capacity or dependency conflicts.
- Give each initiative an accountable owner role and one measurable success signal.
- List assumptions, open questions and anything you could not assess.
Output format A markdown table: Risk, Root cause, Initiative, Owner role, Effort band, Sequence, Success signal. Then a maximum of 150 words on trade-offs and what to defer first. Plain, board-ready language. No vendor names, product picks or pricing.
Guardrails
- Do not invent figures, control numbers, regulation names or benchmark data.
- Flag every assumption and mark unverified inputs.
- Tell the user to confirm budget, legal and regulatory interpretations with finance, legal and the relevant framework documentation before committing.
Example {{risk_register_summary}}: phishing, unpatched internet-facing hosts, third-party access; {{budget_envelope}}: fixed over two years; {{planning_horizon}}: four quarters.