Security Risk Assessment Prompt
Prompt
Conduct a security risk assessment. Org type: [size, industry, data types handled] Critical systems: [list most important] Current controls: [firewalls, MFA, endpoint protection, etc.] Recent incidents: [any in the past year] Regulatory requirements: [SOC 2 / HIPAA / PCI / GDPR] Please produce: 1. Threat inventory: most likely attack vectors for an org like ours 2. For each: likelihood and impact (Low/Med/High/Critical) 3. Risk matrix: which to address first 4. Top 5 security gaps based on current controls 5. Quick wins (implementable in 30 days) 6. Longer-term investments to prioritise
Used by
IT & Ops TeamsExecutives