Prompt
Write Executive Summary Of Findings
Use this when you need a non-technical overview of the engagement's risk and key themes for leadership.
How to use it
- Copy the prompt and paste it into ChatGPT, Claude, Gemini or any other AI.
- Replace every {{placeholder}} with your own details, or let the AI ask you for them.
- Use the follow-ups below to go deeper.
Role You are the reporting lead on a penetration testing engagement. You turn technical findings into a short, plain-language executive summary that lets senior leadership understand the risk and decide what to fund.
Context you provide
- {{client_name}}: the client organisation
- {{business_context}}: what the client does, and which assets matter most
- {{engagement_scope}}: systems or applications tested
- {{testing_window}}: dates the testing ran
- {{findings_list}}: findings with severity, affected asset and status
- {{key_themes}}: patterns running across the findings
- {{remediation_status}}: what is already fixed or in progress
- {{audience}}: who reads this, for example board or risk committee
- {{target_length}}: page or word limit
Instructions
- Ask for any missing inputs, then wait for the answers before writing.
- Open with two sentences describing the engagement a non-technical reader can follow.
- State the overall risk posture in plain terms, tied to the business impact of the supplied findings.
- Group the findings into three to five themes. For each, give one line on the business meaning and one on the recommended direction.
- Note anything already remediated so leadership sees progress.
- Close with a prioritised list of next steps, ordered by risk.
- Keep every claim traceable to the inputs given.
Output format Markdown with short headings: Overview, Overall Risk, Key Themes, Progress To Date, Next Steps. Around {{target_length}}. Plain business English, active voice. No exploit steps, no raw tool output, no severity codes unless explained in plain words.
Guardrails
- Do not invent findings, severities, dates or figures. Use only what is supplied.
- Flag any assumption you make, and any theme resting on thin evidence.
- Where a fix needs a vendor manual, a local regulation or a licensed professional's sign-off, say so instead of prescribing it.
Example {{client_name}}: Northwind Retail; {{audience}}: board risk committee; {{findings_list}}: 2 high, 5 medium, external web app and VPN gateway; {{target_length}}: 1 page.