Cybersecurity & Compliance Roadmap Prompt
Prompt
Our [PASTE: client name]] failed a security audit and needs a comprehensive remediation plan to fix critical gaps. Build a cybersecurity roadmap that addresses compliance gaps and reduces risk systematically. Include: (1) Gap analysis – specific compliance gaps identified by audit? NIST, ISO 27001, SOC 2, industry-specific requirements? Quantify risk level. (2) Risk prioritization – which security controls address the highest-impact risks first? Likelihood vs. impact matrix? (3) Phased remediation – what can be fixed in 90 days? What's a 6-12 month commitment? Quick wins to build credibility early. (4) Technical controls – specific recommendations for identity, access, data encryption, network segmentation, monitoring, incident response. (5) Organizational alignment – governance, policies, training, incident response procedures. What cultural changes? (6) Vendor assessment – should they consolidate security vendors or use best-of-breed? Tool recommendations? Provide a sample remediation timeline with resource estimates, compliance checklist, risk ranking, and vendor assessment scorecard. Budget implications?
Why it works
Security is now board-level. Clients value a structured approach to risk reduction and compliance, especially after audit failures.
Watch out for
Security complexity requires expertise. Partner with specialized firm if you're not deeply confident in recommendations.
Used by
IT & Ops TeamsExecutives