Back to Blog
Scheduled — appears September 25, 2026 at 1:00 PM UTC

The AI prompt every CISO should steal

The AI industry aimed itself at the SOC — alert triage, log summarization, phishing detection. Meanwhile 71% of CISOs spend 10+ hours preparing each quarterly board report and boards give them 15 minutes on the agenda. The prompt at CISO altitude that has been walked past for two years: rank my security programs by loss reduced per dollar spent, given my current exposure and this budget. Why it's not a spreadsheet, four pitfalls in the order they bite, and how to acquire the capability — DIY in half a Saturday or productized in an hour.

Quick Answer

The AI industry aimed itself at the SOC — alert triage, log summarization, phishing detection. Meanwhile 71% of CISOs spend 10+ hours preparing each quarterly board report and boards give them 15 minutes on the agenda. The prompt at CISO altitude that has been walked past for two years: rank my security programs by loss reduced per dollar spent, given my current exposure and this budget. Why it's not a spreadsheet, four pitfalls in the order they bite, and how to acquire the capability — DIY in half a Saturday or productized in an hour.

A journalist asked me last week what AI prompt every CISO should steal. The obvious answers are things every CISO is already doing badly: summarize this article, draft this board memo, does this look right. Confirmation-mode chat with a language model.

The more useful answer is the prompt CISOs are not running, and it starts with a question about where the industry has put its AI.

Everyone aimed AI at the SOC

AI is now in more than three-quarters of security stacks. This is not aspiration; this is production. When you look at what for, it is almost entirely analyst-tier work: alert triage, log summarization, phishing detection, indicator-of-compromise correlation, threat-feed enrichment, red-team automation. Useful, all of it. None of it aimed at the CISO's calendar.

77%
of security stacks now include GenAI.
61%
+28pt YoY
of security practitioners use AI in red-team activities.
71%
of CISOs spend 10+ hours prepping each quarterly board report for a 15-minute agenda slot.

Multiply 10 hours of prep by four quarters and the CISO is spending a full work-week per year producing artifacts that get an hour of collective board attention. The CISO's actual calendar is a different set of problems than what analyst-tier AI addresses:

  • Board translation: Someone forwards you an article. A breach, a court case, a new SEC ruling. From above, they want to know your exposure. From below, it's a pitch: this could be us if we don't get xyz tool, detection, or hire. Same question, opposite accountability directions. Same 10-hour prep cycle for a 15-minute conversation.
  • Vendor cross-mapping: A new regulation ships. You need to know which of your 20 largest vendors' data processing agreements (DPAs) no longer meet what you're now obligated to enforce. Nobody's doing this on the day the regulation drops. Everyone's doing it on the day the auditor asks.
  • Regulatory diffing against your own policy library: Where does what your policies say diverge from what the current version of the framework actually requires? This is pre-audit prep, and it's mostly Ctrl-F today.
  • The six-week annual budget defense: Every CISO in America runs the same exercise every fall. It ends in a spreadsheet, and it eats Sunday afternoons in October. Spreadsheets have been around for twenty-five years, so the fact that the exercise still takes six weeks tells you the bottleneck was never the arithmetic. It was everything upstream of it.

The AI industry, in aggregate, has done a lot of great work on the first list and almost nothing on the second. That is the gap.

Why the CISO seat has an AI gap in the first place

This is not an accident. It is an incentive story.

The buyers for AI-augmented security tooling are almost always operations budgets: SOC managers, detection engineers, IR leads, red-team owners, TPRM programs. That is where the money flows, that is where the pilot programs run, and that is where the sales motion is optimized. Every vendor who sells to security has been pointed at the same set of tickets, alerts, and evidence collection tasks for the last three years. Analyst-tier problems are well-defined, high-volume, and easy to demo. The ROI arithmetic writes itself.

The CISO's own workload is the opposite. It is low volume, high stakes, ambiguous, and shaped by relationships you cannot put on a demo call. Board reporting, budget defense, vendor cross-mapping, regulatory diffing, executive translation. Each one is a one-off. Each one is politically loaded. Each one happens on a schedule the vendor cannot see. It is a terrible product category and a great practitioner opportunity.

Which is why the prompt worth stealing is the one you build yourself. Nobody is going to sell it to you as an out-of-box capability with a Gartner category attached, at least not for another two years. In the meantime, the CISO who runs it every quarter is running with an advantage that has not been priced in.

The prompt to steal

The prompt every CISO should steal

Rank my security programs by loss reduced per dollar spent, given my current exposure and this budget.

A CFO can push back on that ranking. A board can defend it. A cyber-insurance broker can quote against it. An auditor can read the accepted-risk trail out the back of it. It is the prompt at the top of the operating plan, and the industry has walked past it for two years.

Why this specifically is not a spreadsheet

The pushback I get is: this is a sort operation. Excel has done this since 1985. Fair. The ranking is a sort. What the sort depends on, and what has kept this problem unsolved for twenty-five years, is three things upstream:

  • Generating the loss event frequency (LEF) and loss magnitude (LM) inputs for every program: A ranked menu is only as defensible as the estimates feeding it. Producing consistent LEF and LM ranges across thirty candidate programs, for programs you have not yet run, is reasoning across your incident history, your attack surface, comparable public breach outcomes, and your control gaps. Concrete example: you are pricing a maturity upgrade on secrets management. The industry loss curve for accidentally committed credentials in your vertical, the historical frequency of near-miss incidents in your own ticket queue, the change in attack surface introduced by six new developer hires last quarter, and the current state of your secret-scanning coverage all bear on the LEF and LM you should feed the ranking. An LLM will happily produce a ranged estimate with each of those inputs cited. A spreadsheet cannot participate in that reasoning at all.
  • Cross-referencing across the unstructured data: Concentration risks live inside twenty DPAs. Duplicate control coverage lives inside last summer's risk-assessment readout. Which program addresses your top uncovered loss scenario under the FAIR (Factor Analysis of Information Risk) methodology lives in the last 90 days of tickets. Spreadsheets hold numbers. Tableau visualizes numbers. Neither reads documents. Concrete example: three of your top five vendors run on the same cloud provider region, four of them share the same identity provider, and two of them contractually name your data as sub-processed to a fourth party you have never heard of. That is a concentration risk that will not appear in your risk register unless someone reads every DPA and connects the dots. An LLM can do that read in fifteen minutes. Nobody on the CISO's team is doing it manually because there are not enough hours in the day.
  • Naming the risks the budget implicitly accepts: A ranking picks winners. What it has nothing to say about is the unfunded remainder: the loss scenarios that fell below the cost line. Give the LLM the same inputs plus the cutoff and it produces the risk-acceptance view: “at this budget, these five unaddressed loss scenarios are worth $X in expected annual loss, and are what you’re implicitly accepting.” Concrete example: at the CFO-approved budget, insider-threat instrumentation upgrades fall out. That decision has a dollar value: the LLM will produce something like “$2.3M expected annual loss from insider incidents you cannot detect within 30 days, based on your industry base rate and the last two incidents in your own history.” That is the slide every board asks for and no spreadsheet will surface, because it requires reasoning about the negative space, not the arithmetic.

The ranking itself is trivial. Everything that has to be true for the ranking to be defensible is what LLMs are actually built for.

Why it changes the shape of the CFO conversation

The annual budget defense has one dominant failure mode: the CFO says "cut 10%" and the CISO argues. Both sides burn political capital, and the ranking of what actually got cut is an artifact of the argument, not the risk.

The prompt inverts that. You hand finance a rank-ordered menu with every program tied to a dollar figure of loss reduced, and they pick where the cuts land. Every program that fell below the line becomes a signed accepted-risk record with the inputs preserved, not a footnote in an email chain nobody can find in 18 months.

Run quarterly, on the same cadence as the board report the stat above measures, the prompt gives you near-real-time visibility into which risks you're actually mitigating and where the tacitly accepted ones are quietly devaluing the business. It also keeps the operating plan alive between budget cycles instead of becoming shelfware the moment the annual exercise ends.

What the output actually looks like

The point of naming the output shape is that CISOs who have not run this prompt yet imagine an inscrutable JSON blob or a wall of prose. Neither. The useful output is closer to a three-part memo you can hand a CFO, a board member, and an auditor and have all three read it the same way.

Part 1: the funded list. Roughly a dozen programs, ordered by loss reduced per dollar spent, each with an annualized loss expectancy (ALE) reduction figure (a range, not a point estimate), the program's total cost, the loss-scenario it maps to, and the P90 outcome under a plausible worst-case. Read time: 90 seconds.

Part 2: the accepted list. Everything below the budget line. Same shape, same fields, but with an explicit "accepted" flag and a one-line rationale grounded in the ranking that produced the cut. This is the artifact you want the CFO to sign, because when this list becomes evidence in an incident review 18 months from now, you want it to say the accept was deliberate.

Part 3: the sensitivity view. A short set of counter-scenarios: what changes at 90% of this budget, at 110%, at 125%. The value of this section is that finance will ask for it before you finish the meeting. Producing it in advance is what turns the conversation from adversarial back-and-forth into a decision between two rank-ordered options.

None of the three parts is a novel artifact type. What is new is that they arrive on the CISO's desk in ninety minutes instead of six weeks, and they arrive with reasoning about your specific posture instead of platitudes about the industry.

Four pitfalls, in the order they bite

  • The shiny-scenario trap: LLMs disproportionately weight vivid public breaches (SolarWinds, MOVEit, Change Healthcare) over your actual industry loss curve. Left unchecked, the ranking overweights the tail because the model remembers what got press. Constrain the context to your industry's loss distribution, not general cybersecurity news.
  • Anchoring on last year's plan: Feed in last year's operating plan as context and the LLM will produce this year's plan as a variation of it. Which means it will never zero out a program you've had for five years, even when the math says you should. Feed the register clean, or the prompt just tells you what you already believe.
  • Losing the accepted-risk trail across cycles: Every ranking implicitly accepts a set of risks. If you run this quarterly without capturing which risks moved from accepted to funded (or the reverse) between cycles, you lose the audit narrative. Eighteen months later you can't reconstruct why the board OK'd accepting $2M ARR of insider-threat exposure in Q1 that you then funded in Q3.
  • Board-optics compression: The prompt outputs a ranked list. The board packet compresses to a top-5. What you cut for the packet is where the real decision lives, and the LLM will not do that compression well because it doesn't know your board's personalities. If you delegate that compression, you're one prompt away from a bad meeting.

How to acquire the capability

Two paths.

DIY. Get Claude or another frontier model to propose rough LEF and LM inputs and risk scenarios based on your industry and regulatory environment. Use that to build or strengthen your risk register. From there, feed the LLM your business context (goals, objectives, constraints) alongside your unstructured data: DPAs, risk-assessment readouts, incident tickets, so the prompt's outputs are actually tailored to your situation. Treat the first result as alpha. Keep refining the context you provide until you reach MVP. All in, about half a Saturday.

What the risk register actually has to hold for the prompt to do useful work: one row per candidate program, with the program name, the primary loss scenario it addresses, an LEF range (low and high), an LM range (low and high), a cost estimate (one-time plus annual), a control-family tag that maps to the framework you report against, and the risk-owner name. Nine columns. Not fancy. The reason CISO risk registers rarely have all nine is that the columns are political, not technical. Deciding which program owns which loss scenario is the argument the register is supposed to close, and closing that argument in advance is what makes the LLM's ranking defensible on the day the CFO reads it.

Productized. Tools exist that run the mapping against a live, signed control state and generate the first draft in about an hour. Our Operating Plan does exactly this . It was the answer to the question I kept running myself every October.

What running it compounds into

The first time you run this prompt, the value is a defensible ranking and a couple of hours back on your calendar. That alone justifies the effort. But the shape of the payoff changes once you run it on a cadence.

Each quarter's run reads against the last quarter's plan. Programs that moved from accepted to funded (or the reverse) become an audit narrative you did not have to write. The risk register gets sharper because you kept feeding the LLM the actual outcomes of the decisions it helped you make. The accepted-risk list starts working as insurance, not just as documentation: when something on that list turns into an incident, you have contemporaneous evidence of the deliberate acceptance, priced and signed at the time. And the six-week October exercise starts taking three weeks the second year and one week the third.

Which is the part CISOs who have not lived through it underestimate. The value of the prompt is not the single ranking. It is that the operating plan stops being an artifact that expires the moment the budget is approved.

The closer

A full work-week per year of board prep for an hour of board attention is where the AI industry has room to give the CISO time back. The prompts worth stealing are the ones that shrink that ratio and produce more accurate, more timely risk decisions. Your SOC lead already has prompts that catch the next AI-powered phishing campaign faster. You need the prompt that demonstrates why it matters to the business.

Where this matters next

Share this article:

Ready to build your security program?

See how easy it can be.