Cyber Risk Register Builder
Converts identified threats into a quantified, prioritized risk register aligned to a treatment strategy.
Prompt
ROLE: You are a cyber risk manager building a board-ready risk register for an organization. CONTEXT: - Organization profile: [SIZE_INDUSTRY_REGULATORY_ENV] - Identified risks / findings: [PASTE_RISK_INPUTS] - Risk appetite statement: [APPETITE_OR_TOLERANCE] - Existing controls: [SUMMARY_OF_CONTROLS] TASK: 1. Normalize each input into a clear risk statement using the form: 'Risk that [threat] exploits [vulnerability] affecting [asset], leading to [impact].' 2. Assess inherent risk (Likelihood x Impact, 1-5 each) and explain the rating. 3. Map current controls and estimate residual risk after controls. 4. Recommend a treatment: Mitigate, Transfer, Avoid, or Accept — with rationale and a target residual level. 5. Assign an owner role and a review cadence. OUTPUT FORMAT: Risk register table | ID | Risk statement | Inherent (L/I/score) | Key controls | Residual (L/I/score) | Treatment | Owner | Review date Plus: a heat-map summary (count of risks per residual band) and the 3 risks exceeding stated appetite. CONSTRAINTS: Tie likelihood/impact to evidence, not vibes. Express impact in business terms (financial, operational, regulatory, reputational). Do not mark a risk 'Accept' if it exceeds the stated appetite without flagging it for escalation.
How to use this prompt
- 1
Copy the prompt above and paste it into ChatGPT, Claude, or Gemini — or open it in the visual Studio to edit each part on a canvas and run it with your own key.
- 2
Replace any bracketed placeholders with your specifics. The more concrete your context and constraints, the sharper the result — see the 5-part prompt structure.
- 3
Run it, then refine. Ask the model to critique and improve its own answer with self-critique prompting.
Techniques in this prompt
Assigns the model an expert persona so it adopts the right vocabulary, depth, and standards for the task.
Learn this techniquePins the response to a defined structure so it drops straight into your workflow.
Learn this techniqueForces explicit intermediate reasoning instead of jumping to a conclusion, which improves accuracy on hard tasks.
Learn this techniqueRecommended models
Build on this prompt
Open it in the visual Studio to wire it into a full workflow with your own API key — or learn the craft behind prompts like this.
More in Cybersecurity & Risk
STRIDE Threat Model For A New Service
Builds a structured STRIDE threat model for a system with trust boundaries, ranked threats, and concrete mitigations.
Security Incident Postmortem Author
Drafts a blameless post-incident review with timeline, root cause, and corrective actions ready for leadership.
CVE Triage And Prioritization Analyst
Triages a list of CVEs by exploitability and business context to produce an actionable patch priority queue.
Phishing Email Forensic Examiner
Analyzes a suspicious email's headers, URLs, and payload to classify intent and recommend SOC response.