Executive Cyber Risk Board Briefing Writer
Translates technical security status into a concise, decision-oriented board briefing with metrics and asks.
Prompt
ROLE: You are a CISO preparing a quarterly cyber risk briefing for a non-technical board of directors. CONTEXT: - Reporting period: [QUARTER_YEAR] - Key events: [INCIDENTS_AUDITS_CHANGES] - Current metrics: [PASTE_KPIS_KRIS] - Top risks & initiatives: [WHAT_MATTERS_NOW] - Decisions/budget needed: [THE_ASK] TASK: 1. Open with a plain-language risk posture summary the board can grasp in 30 seconds (trend: improving/stable/worsening). 2. Present 3-5 key risks in business terms (financial, regulatory, operational, reputational) — not CVE counts. 3. Show metrics that matter to governance (risk reduction trend, incident response time, third-party exposure, control coverage) with context for whether each is good or bad. 4. Frame initiatives as risk-reduction investments with expected outcomes. 5. State the specific decisions, approvals, or budget you are asking the board for, with the consequence of inaction. OUTPUT FORMAT: - Posture summary (traffic-light + one paragraph) - Top risks (business-impact framing) - Metrics dashboard (metric | value | trend | what it means) - Initiatives & investment asks - Decisions required + risk of doing nothing CONSTRAINTS: No jargon or acronyms without a plain-language gloss. Lead with business impact and money, not technology. Be honest about bad news — boards penalize surprises more than problems. Every metric must include 'so what' interpretation, not just a number.
How to use this prompt
- 1
Copy the prompt above and paste it into ChatGPT, Claude, or Gemini — or open it in the visual Studio to edit each part on a canvas and run it with your own key.
- 2
Replace any bracketed placeholders with your specifics. The more concrete your context and constraints, the sharper the result — see the 5-part prompt structure.
- 3
Run it, then refine. Ask the model to critique and improve its own answer with self-critique prompting.
Techniques in this prompt
Assigns the model an expert persona so it adopts the right vocabulary, depth, and standards for the task.
Learn this techniquePins the response to a defined structure so it drops straight into your workflow.
Learn this techniqueRelies on one clear instruction with no examples — fast, and effective when the task is unambiguous.
Learn this techniqueRecommended models
Build on this prompt
Open it in the visual Studio to wire it into a full workflow with your own API key — or learn the craft behind prompts like this.
More in Cybersecurity & Risk
STRIDE Threat Model For A New Service
Builds a structured STRIDE threat model for a system with trust boundaries, ranked threats, and concrete mitigations.
Security Incident Postmortem Author
Drafts a blameless post-incident review with timeline, root cause, and corrective actions ready for leadership.
CVE Triage And Prioritization Analyst
Triages a list of CVEs by exploitability and business context to produce an actionable patch priority queue.
Phishing Email Forensic Examiner
Analyzes a suspicious email's headers, URLs, and payload to classify intent and recommend SOC response.