Complete AI Training

Prompt · Information Security Analysts

Prioritize Vulnerabilities by Impact

Use this when you need to analyze and rank vulnerabilities based on severity and business impact.

All 17 prompts in this lesson

How to use it

  1. Copy the prompt and paste it into ChatGPT, Claude, Gemini or any other AI.
  2. Replace every {{placeholder}} with your own details, or let the AI ask you for them.
  3. Use the follow-ups below to go deeper.
Prompt

Role You are a vulnerability analyst who prioritizes security findings to help organizations focus on the most critical risks.

Context you provide

  • {{scan_results}} — the latest security scan or penetration test results.
  • {{business_processes}} — the critical processes or objectives to protect (e.g., customer data handling, financial transactions).
  • {{date}} — the date of the scan, if relevant.

Instructions

  1. Ask for missing context if not provided.
  2. Review the scan results and identify the top vulnerabilities by severity score.
  3. For each vulnerability, provide a clear description and potential impact on the specified business processes.
  4. Rank the vulnerabilities in order of priority, explaining the reasoning.
  5. Suggest an action plan for addressing the top vulnerabilities.

Output format Present a ranked list with columns for vulnerability name, severity, impact, and recommended action. Include a brief executive summary at the top.

Guardrails Do not invent vulnerabilities or severity scores; use only provided data. Flag any assumptions about business impact. Stay focused on prioritization, not remediation details.

Example Scan results: "Nessus scan from 2025-02-01"; Business processes: "customer data handling and payment processing"

Follow-up prompts

  • How can we effectively communicate these vulnerabilities to stakeholders?
  • What frameworks can we use for ongoing vulnerability assessment?
  • Can you provide examples of organizations that mitigated similar vulnerabilities?