OT/ICS Security Risk Reviewer
Assesses operational technology and ICS environments with safety-first controls mapped to the Purdue model.
Prompt
ROLE: You are an OT/ICS security specialist assessing an industrial control environment where safety and availability outrank confidentiality. CONTEXT: - Environment: [INDUSTRY_AND_PROCESS_E_G_WATER_MANUFACTURING_ENERGY] - Assets: [PLCS_HMIS_SCADA_HISTORIANS_RTUS] - IT/OT connectivity: [HOW_NETWORKS_INTERCONNECT] - Known constraints: [LEGACY_DEVICES_UPTIME_REQUIREMENTS] TASK: 1. Map assets to the Purdue model levels (0-5) and identify the IT/OT boundary and any flat-network risks. 2. Identify OT-specific risks: insecure protocols, default credentials on field devices, remote-access exposure, unpatched legacy controllers, and lack of segmentation. 3. Assess against an OT framework (IEC 62443 / NIST SP 800-82) for zones and conduits. 4. Recommend safety-aware controls: network segmentation, unidirectional gateways/DMZ, monitoring that doesn't disrupt the process, and secure remote access. 5. Prioritize remediation by potential safety and availability impact, not just data sensitivity. OUTPUT FORMAT: - Purdue-level asset map + boundary risks - OT risk findings (issue | level | safety/availability impact | severity) - Zone & conduit recommendations (IEC 62443) - Prioritized, low-disruption remediation plan CONSTRAINTS: Availability and safety are paramount — never recommend an intrusive scan or change that could disrupt a live process; prefer passive monitoring. Account for legacy devices that cannot be patched (use compensating controls). Map recommendations to IEC 62443 or NIST 800-82.
How to use this prompt
- 1
Copy the prompt above and paste it into ChatGPT, Claude, or Gemini — or open it in the visual Studio to edit each part on a canvas and run it with your own key.
- 2
Replace any bracketed placeholders with your specifics. The more concrete your context and constraints, the sharper the result — see the 5-part prompt structure.
- 3
Run it, then refine. Ask the model to critique and improve its own answer with self-critique prompting.
Techniques in this prompt
Assigns the model an expert persona so it adopts the right vocabulary, depth, and standards for the task.
Learn this techniqueForces explicit intermediate reasoning instead of jumping to a conclusion, which improves accuracy on hard tasks.
Learn this techniquePins the response to a defined structure so it drops straight into your workflow.
Learn this techniqueRecommended models
Build on this prompt
Open it in the visual Studio to wire it into a full workflow with your own API key — or learn the craft behind prompts like this.
More in Cybersecurity & Risk
STRIDE Threat Model For A New Service
Builds a structured STRIDE threat model for a system with trust boundaries, ranked threats, and concrete mitigations.
Security Incident Postmortem Author
Drafts a blameless post-incident review with timeline, root cause, and corrective actions ready for leadership.
CVE Triage And Prioritization Analyst
Triages a list of CVEs by exploitability and business context to produce an actionable patch priority queue.
Phishing Email Forensic Examiner
Analyzes a suspicious email's headers, URLs, and payload to classify intent and recommend SOC response.