Home · Business · IT, Data & Security · Cybersecurity

PARTLY

As of 13 August 2026, AI can only partly create a cybersecurity risk assessment for your business.

This still needs a person who signs their name to it.

Can you do it?

15 minutesto a draft.

1 hourto something you’d act on.

Cost, all in£0

Skill neededchat-fluent

Who has to check ita professional

What the alternative costsNo comparable alternative price is provided in the available tool data.

If this goes wrong: the assessment misses a material weakness, so you spend time and money on the wrong controls while an avoidable incident remains possible.

What to actually do

  1. Hand it to a person

    The route this page recommends

    Someone with a licence or accountable authority has to sign this before it counts.

  2. Use a tool built for this

    Second choice
  3. Do it yourself

    The distant third

    A chat interface, chat-fluent skill, and roughly 1 hour until you can act on the result.

    How to actually do it

    1. Open a document or spreadsheet and create an inventory of your devices, applications, cloud services, websites, data stores, suppliers, users and backups.
    2. Gather your current security policies, asset list, supplier details, access arrangements, backup information, incident records, audit findings and technical test reports.
    3. Remove passwords, secret keys, personal details and other unnecessary private data, then paste the remaining business information and documents into a chatbot with the prompt above.
    4. Ask the model to produce the assessment and keep a separate list of every missing fact, assumption and item requiring technical testing.
    5. Compare each asset, control and incident in the draft against your inventory and documents, correcting any invented, outdated or unsupported entry.
    6. Ask an independent IT security professional to test the highest-priority risks, challenge the ratings and approve the treatment plan before you accept the assessment.

    Prompt

    Create a cybersecurity risk assessment for this UK business using only the information and documents I provide.
    
    Business description:
    [describe the business, locations, staff numbers and important operations]
    
    Systems and assets:
    [list devices, applications, cloud services, websites, networks and backups]
    
    Data:
    [list personal, financial, confidential and operational data, where it is stored, and who can access it]
    
    Suppliers and dependencies:
    [list hosting providers, software suppliers, payment providers, IT support, outsourced services and critical dependencies]
    
    Existing controls:
    [list MFA, passwords, patching, antivirus or endpoint protection, backups, access reviews, staff training, logging, incident response and supplier checks]
    
    Known incidents or concerns:
    [describe any incidents, vulnerabilities, weaknesses or planned changes]
    
    Evidence and source documents:
    [paste or attach policies, asset lists, supplier information, audit findings and technical reports]
    
    Produce:
    1. A concise scope and list of assumptions.
    2. An asset and information summary, marking missing or unverified information.
    3. A risk register with one row per risk. Include threat, vulnerability, affected asset or data, possible consequence, likelihood, impact, inherent risk, existing controls, control effectiveness, recommended treatment, owner, target date and residual risk.
    4. A prioritised action plan that separates urgent evidence-gathering from remediation.
    5. Questions that a security professional or system owner must answer.
    
    Do not invent systems, incidents, controls, legal conclusions, risk ratings or facts. Do not claim that a control is effective without evidence. Explain the rating method in plain English, show why each rating was chosen, distinguish facts from assumptions, and mark every item that requires technical testing or professional judgement. Use UK terminology. Identify relevant NCSC guidance or other authoritative sources only when you can name the source accurately, and do not present this assessment as certification or professional advice.

    Open it prefilled in ChatGPT or Claude, or copy it into Gemini, which takes no prefill link.

What it gets wrong

  • AI cannot discover every asset or unauthorised service that your business has failed to record.
  • AI cannot prove that patching, backups, access controls or monitoring work without technical evidence or testing.
  • AI cannot reliably judge the likelihood and business impact of an unfamiliar threat in your particular environment.
  • AI cannot take responsibility for accepting residual risk or deciding which security investment your business should make.
  • AI cannot turn an assessment into assurance, certification or a substitute for an independent security review.

What caps this at PARTLY: context depth, verification cost and stakes of error.

How we scored this

Five axes, each scored nought to two by hand: ten means AI carries the task cleanly, and the thresholds that turn a total into YES, PARTLY or NO are published in the methodology. Each axis name links to its definition.

AxisScore (0–2)
Output2
Inputs1
Verification1
Liability1
Effort delta1
Total6 / 10

FAQ

Can ChatGPT create a cybersecurity risk assessment?
Yes, it can draft a useful risk register and action plan from your business information. It cannot discover missing assets, test controls or take responsibility for the final risk decisions, so treat the draft as preparation for a security review.
Is it safe to put my business information into an AI chatbot?
Only share information your organisation permits you to share, and remove passwords, keys, personal data and unnecessary confidential material first. Check the chatbot's data handling terms and use an approved business account where your organisation requires one.
Do I need a cybersecurity professional to check an AI risk assessment?
For a serious or complex assessment, yes. A professional needs to challenge the threat model, test important controls and confirm that the priorities are defensible; this is not professional advice.
What should a cybersecurity risk assessment include?
It should cover scope, assets, data, threats, vulnerabilities, consequences, likelihood, existing controls, treatment actions, owners, dates and residual risk. It should also show assumptions, missing evidence and which findings need technical testing.

Nearby answers

Assessed by gpt-5.6-luna (gpt-5.6-luna) on 2026-08-13, second-checked by an independent model. Wrong somewhere? Email [email protected] and it gets re-checked.

The newsletter

AI news, new answers and product picks, straight to your inbox.