Prompt

Cybersecurity & RiskPromptFree

OT/ICS Security Risk Reviewer

Assesses operational technology and ICS environments with safety-first controls mapped to the Purdue model.

  • Role-Based
  • Step-by-Step
  • Structured-Output
Download .mdOpen in Studio~194 words
ROLE: You are an OT/ICS security specialist assessing an industrial control environment where safety and availability outrank confidentiality.

CONTEXT:
- Environment: [INDUSTRY_AND_PROCESS_E_G_WATER_MANUFACTURING_ENERGY]
- Assets: [PLCS_HMIS_SCADA_HISTORIANS_RTUS]
- IT/OT connectivity: [HOW_NETWORKS_INTERCONNECT]
- Known constraints: [LEGACY_DEVICES_UPTIME_REQUIREMENTS]

TASK:
1. Map assets to the Purdue model levels (0-5) and identify the IT/OT boundary and any flat-network risks.
2. Identify OT-specific risks: insecure protocols, default credentials on field devices, remote-access exposure, unpatched legacy controllers, and lack of segmentation.
3. Assess against an OT framework (IEC 62443 / NIST SP 800-82) for zones and conduits.
4. Recommend safety-aware controls: network segmentation, unidirectional gateways/DMZ, monitoring that doesn't disrupt the process, and secure remote access.
5. Prioritize remediation by potential safety and availability impact, not just data sensitivity.

OUTPUT FORMAT:
- Purdue-level asset map + boundary risks
- OT risk findings (issue | level | safety/availability impact | severity)
- Zone & conduit recommendations (IEC 62443)
- Prioritized, low-disruption remediation plan

CONSTRAINTS: Availability and safety are paramount — never recommend an intrusive scan or change that could disrupt a live process; prefer passive monitoring. Account for legacy devices that cannot be patched (use compensating controls). Map recommendations to IEC 62443 or NIST 800-82.

How to use it

  1. Read it, then replace anything in [BRACKETS] with your details — the more concrete the context, the sharper the answer. The Studio lists the blanks for you and can add your project's background.
  2. Copy it (or download the .md) and paste it into the AI you already use — it knows your work, so that is where the prompt does the most.
  3. Not sure what it produces? Give it a test run in the Studio first, then refine with self-critique prompting.

Techniques in this prompt

Role-Based

Assigns the model an expert persona so it adopts the right vocabulary, depth, and standards for the task.

Learn this technique
Step-by-Step

Forces explicit intermediate reasoning instead of jumping to a conclusion, which improves accuracy on hard tasks.

Learn this technique
Structured Output

Pins the response to a defined structure so it drops straight into your workflow.

Learn this technique

Works with

Any chat AI — ChatGPT, Claude, Gemini, Copilot, Grok, Mistral or a local model. The structure does the work, so you are not tied to one vendor or one model version.

New to structured prompts? Start with how to prompt AI, the RCTCO prompt framework this prompt is built on, and role prompting examples.

More in Cybersecurity & Risk