Turn your intent into a clear, structured security policy with legal-review flags.
Draft a [type] security policy for a [size, industry] company. The key points to cover are [list]. Structure it as purpose, scope, the policy itself, roles and responsibilities, and enforcement, in plain language. Flag anything that depends on local law or a specific regulation as 'confirm with legal' rather than stating it as fact.
policydocumentationcompliance
Rewrite a policy in plain English
ChatGPTIntermediate
Cut jargon while keeping every requirement intact so employees actually follow it.
Rewrite this security policy in plain English so employees will actually follow it: [paste a non-sensitive policy]. Keep every requirement intact, cut the jargon, add a one-line summary at the top, and flag anything ambiguous that should be clarified. Do not change the meaning, only the readability.
policyplain languagedocumentation
Draft a runbook outline
ChatGPTIntermediate
Lay out triggers, steps, owners, and sign-off points for a routine process.
Draft a runbook outline for [a routine security process, e.g. onboarding access review]. Lay out the trigger, the step-by-step actions, who is responsible for each, the decision points, and what to record. Keep it concrete enough that someone new could follow it, and mark the steps where a second person should sign off.
runbookdocumentationprocess
AI acceptable-use policy
ChatGPTIntermediate
Draft an AI-tools use policy covering data, approved tools, and client data.
Create an acceptable-use policy section specifically for employee use of AI tools at a [size, industry] company. Cover what data must never be entered, which tools are approved, and how to handle client or personal data. Practical and specific, not a list of vague principles.
policyai toolsdata handling
Write an incident report
ChatGPTIntermediate
Turn generic notes into a structured, readable incident report.
Write an incident report from these notes: [paste generic notes, no real identifiers]. Structure it as summary, timeline, impact, root cause, actions taken, and follow-ups. Factual and clear, honest about what is still unknown, and written so both technical and non-technical readers can follow it.
incident responsereportingsoc
Leadership incident update
ChatGPTIntermediate
Draft a calm, honest status update for leadership during an active incident.
Draft an internal update to leadership about an ongoing security incident: [describe generically]. Lead with current status and impact, then what is being done, what we need from them, and the next update time. Calm and honest, no jargon, and no promises we cannot keep.
incident responsecommsleadership
Structure a post-incident review
ChatGPTIntermediate
Get past blame to real causes and owned improvements.
Help me structure a post-incident review for [describe the incident generically]. Give me the sections, the questions that get past blame to real causes, and how to turn the discussion into specific, owned improvements rather than a list of good intentions.
incident responsepost-mortemprocess
Affected-user notification
ChatGPTIntermediate
Draft a clear, non-alarming breach notice, marked for legal review.
Draft a clear, non-alarming notification to affected users about a security incident: [describe generically]. Cover what happened, what data was involved, what we are doing, and what they should do. Plain and respectful, and mark this as a draft for legal and compliance to review before sending.
incident responsecommscompliance
Explain a vuln to the board
ChatGPTIntermediate
Translate a vulnerability into business terms and a clear ask.
Explain this vulnerability to a non-technical board: [describe the issue generically]. Cover what it is, what could happen in business terms, how likely it is, and the decision or budget I am asking for. Two short paragraphs, no jargon, and no scaremongering.
risk communicationreportingleadership
Risk register entry
ChatGPTIntermediate
Turn a technical finding into a defensible risk register entry.
Turn this technical finding into a risk register entry: [describe]. Give me a plain-language description, the business impact, likelihood, a suggested risk rating with the reasoning, an owner, and a recommended treatment. Keep the rating defensible, not inflated.
risk communicationrisk registerreporting
Translate a CVSS score
ChatGPTIntermediate
Turn a CVSS score into business risk without over- or under-hyping it.
Translate this CVSS score and technical detail into business risk for executives: [paste the non-sensitive detail]. Explain what the number actually means for us, what an attacker could do, and what changes if we fix it now versus later. Help me avoid both downplaying and overhyping it.
risk communicationcvssleadership
Security-awareness message
ChatGPTIntermediate
Write a short, calm all-staff message about a current threat.
Write a short, calm security-awareness message to all staff about [the current threat, e.g. a phishing wave]. Explain the risk in one line, give two or three concrete things to do, and make it easy to report something suspicious. No fear, no blame, just clear action.
awarenesscommsphishing
Phishing-awareness module
ChatGPTIntermediate
Design a memorable phishing-awareness training module for non-technical staff.
Design a short phishing-awareness training module for non-technical staff. Cover how to spot a phishing email, the common tricks, what to do and not do, and how to report one, with a few realistic but clearly educational examples. Practical and non-technical, built to be remembered.
awarenessphishingtraining
Spot-the-phish quiz
ChatGPTIntermediate
Write a short quiz with an answer key that teaches the tell.
Write a spot-the-phish quiz for employees: 6 short scenarios where some are legitimate and some are suspicious, with an answer key that explains the tell in each. Keep the examples realistic and generic, and make the explanations teach the pattern, not just the answer.
awarenessphishingtraining
Security-basics onboarding session
ChatGPTIntermediate
Draft a friendly security-basics agenda for new hires.
Draft an onboarding security-basics session for new hires at a [size, industry] company. Cover passwords and MFA, device safety, data handling, phishing, and how to get help, as a short agenda with the key point for each. Friendly and practical, aimed at people who are not technical.
awarenessonboardingtraining
Phishing-awareness campaign
ChatGPTIntermediate
Plan an education-first campaign that builds a reporting habit.
Help me plan an internal phishing-awareness campaign (education, not simulation): the messages, the timing, and how to measure whether reporting improves. Focus on building a reporting habit and a no-blame culture, and suggest how to keep it from becoming noise people ignore.
awarenessphishingcampaign
Reason about an activity pattern
ChatGPTIntermediate
Rank benign and suspicious explanations for a generically described pattern.
I am seeing this pattern of activity, described generically: [describe without real IPs, hostnames, or user data]. Help me reason about what could cause it, the benign explanations as well as the suspicious ones, and what I would look at next to tell them apart. Rank the possibilities by likelihood.
triagesocdetection
Explain a log or alert type
ChatGPTIntermediate
Learn what an alert type generally means and which fields to check.
Explain what this type of log or alert generally means and why it fires: [describe the alert type, not real data]. Cover the common legitimate causes, the malicious ones, and the fields I should check to triage it quickly. Keep it practical for a busy analyst.
triagesoclogs
Draft detection logic
ChatGPTAdvanced
Spec detection logic in plain English with false positives and tuning.
Help me draft detection logic in plain English for [the behaviour you want to catch]. Describe what the rule should look for, the conditions, the likely false positives, and how to tune it down, so I can hand a clear specification to whoever writes the actual rule. Do not assume a specific product syntax.
detectionsocrules
Alert-to-ticket summary
ChatGPTIntermediate
Turn rough triage notes into a clear handoff for the next analyst.
Turn my rough triage notes into a clear alert-to-ticket summary: [paste generic notes]. Structure it as what fired, what I checked, what I found, the current assessment, and the recommended next step, so the next analyst can pick it up without re-doing my work.
triagesocreporting
Prioritise vulnerabilities
ChatGPTAdvanced
Order a vuln list by exploitability, exposure, and business impact.
Help me prioritise this list of vulnerabilities for a [describe the environment]: [paste generic list with severities]. Factor in exploitability, exposure, and business impact, not just the raw score, and give me a defensible order with a one-line reason each. Flag any where I need more context to decide.
vulnerability managementprioritisationrisk
Explain a vulnerability
ChatGPTIntermediate
Plain-English explanation of a vuln, verified against the official advisory.
Explain this vulnerability in plain English: [name or describe it]. Cover what it is, how it is typically exploited at a conceptual level, what is at risk, and the general remediation direction. Keep it defensive and educational, and I will confirm the specifics against the official advisory.
vulnerability managementeducation
Remediation plan outline
ChatGPTIntermediate
Draft mitigation, fix, verification, and comms with rough sequencing.
Draft a remediation plan outline for [the issue, described generically]. Lay out the immediate mitigation, the proper fix, how to verify it worked, and how to communicate the change, with rough sequencing. Mark anything that needs testing before it touches production.
vulnerability managementremediationplanning
Patch change communication
ChatGPTIntermediate
Explain a fix to stakeholders in plain, reassuring but honest language.
Write a patch or change communication to stakeholders about [the fix]. Explain what is changing, why it matters, any expected disruption, and the timing, in plain language for a non-technical audience. Reassuring but honest about any downtime.
vulnerability managementcommschange
Threat-model with STRIDE
ChatGPTAdvanced
Walk a system through STRIDE, noting concerns, mitigations, and assumptions.
Help me threat-model this system, described generically: [describe the components and data flows without real detail]. Walk through it in a STRIDE style, spoofing, tampering, repudiation, information disclosure, denial of service, elevation of privilege, and for each note the most likely concern and a mitigation to consider. Flag the assumptions I should confirm.
threat modelingstridearchitecture
Design a tabletop exercise
ChatGPTIntermediate
Build a scenario with injects, decision points, and gap-revealing questions.
Design a tabletop exercise for my team around [a scenario, e.g. ransomware or a vendor breach]. Give me the scenario, the injects that escalate it, the decision points, and the questions that reveal gaps in our response. Aim it at learning, not at catching people out.
tabletopincident responsetraining
Red-team the plan
ChatGPTAdvanced
Have the model attack your plan and rank the likeliest ways it fails.
Act as a skeptical attacker and red-team this plan of mine: [paste a non-sensitive plan or policy]. Show me the five most likely ways it fails or gets bypassed, ranked, with the assumption behind each. I want the holes found here rather than in production.
red teamthreat modelingreview
Vendor security questionnaire
ChatGPTIntermediate
Draft a practical, grouped questionnaire to assess a new vendor.
Draft a security questionnaire to assess a new [type] vendor handling [type of data]. Group the questions by area, access control, data protection, incident response, compliance, and business continuity, and note what a good answer looks like for the most important ones. Practical, not a 200-item box-ticking list.
vendor riskcomplianceassessment
Control-framework checklist
ChatGPTAdvanced
Turn a framework into a plain-language self-assessment checklist.
Turn this control framework into a plain-language self-assessment checklist for us: [name the framework, e.g. NIST CSF, ISO 27001, or SOC 2]. For each area, give me the question to ask, what evidence would satisfy it, and a place to note our status. I will confirm the exact control wording against the official source.
complianceframeworksassessment
Compliance gap analysis
ChatGPTAdvanced
Surface likely gaps between current practice and a framework.
Help me find the likely gaps between our current practices and [the framework]. Given what we do today, described generically: [paste], ask me the questions that would surface where we fall short, and group them so I can tackle the biggest gaps first. Do not assume we comply, probe it.
compliancegap analysisframeworks
Third-party risk summary
ChatGPTIntermediate
Draft a defensible vendor risk assessment summary from notes.
Draft a third-party risk assessment summary from these notes on a vendor: [paste generic notes]. Cover the risk areas, the concerns, the vendor's stated controls, and a recommended risk rating with the reasoning, so a decision-maker can act on it. Keep the rating defensible.
vendor riskreportingassessment
SOC runbook outline
ChatGPTIntermediate
Draft a tight, usable-under-pressure SOC runbook for a process.
Draft an outline for a SOC runbook covering [the process, e.g. handling a confirmed phishing report]. Lay out the steps, the decision points, who does what, when to escalate, and what to record, so it is usable under pressure. Keep it tight and unambiguous.
runbooksocprocess
Analyst onboarding checklist
ChatGPTIntermediate
Group onboarding for a new analyst into access, tools, contacts, and goals.
Write a security onboarding checklist for a new analyst joining the team. Group it into access and accounts, tools and training, key contacts, and the first-week goals, with a note on what 'ready to take shifts' looks like. Practical and specific.
onboardingsocprocess
On-call handoff summary
ChatGPTIntermediate
Turn shift notes into a clean handoff so nothing gets dropped.
Turn my shift notes into a clear on-call handoff summary: [paste generic notes]. Structure it as open incidents, what changed this shift, what needs watching, and what the next person should pick up first, so nothing gets dropped between shifts.
sochandoffprocess
Get the plain-English tech brief
One email a week on AI tools and smart-home tech. No jargon, no hype.