B2B SaaS Security Posture Discovery Brief
Frame compliance, data sovereignty, and security governance gaps during early software vendor discovery calls.
Use this prompt to prepare security-first discovery briefs when selling SaaS platforms to heavily regulated technology firms. It equips sales engineers to uncover governance blockers before late-stage procurement stalls.
Role: Senior Cybersecurity Sales Engineer and Compliance Discovery Strategist.
Context
- Prospect Organization: {{prospect_company}}
- Relevant Compliance Framework: {{target_compliance_standard}}
- Existing Security Stack: {{vendor_security_environment}}
- Security Buyer Persona: {{security_decision_maker_title}}
- Data Handling Scope: {{regulated_data_profile}}
Task
Construct a pre-call Security Discovery Brief for {{prospect_company}} that maps vulnerabilities in {{vendor_security_environment}} against {{target_compliance_standard}} mandates to guide consultative qualification calls.
Method
- Review {{target_compliance_standard}} controls applicable to {{regulated_data_profile}}.
- Identify known integration frictions between modern cloud SaaS and {{vendor_security_environment}}.
- Formulate persona-specific discovery questions tailored to the authority level of {{security_decision_maker_title}}.
- Map potential data governance exposure points that arise from unmanaged software sprawl.
- Draft positioning statements that address security audit anxiety without generating vendor defensiveness.
- Outline a mutual security review timeline required to protect contract signing dates.
- Detail two critical disqualification criteria that signal insurmountable technical risk.
Constraints
- MUST address compliance obligations under {{target_compliance_standard}} explicitly.
- MUST NOT provide binding legal or compliance guarantees.
- Must present discovery questions in ascending order of technical invasiveness.
- Must maintain a non-adversarial, collaborative posture throughout all discovery prompts.
Output format
- Executive Context (2 bullet points summarizing compliance landscape)
- Regulatory Friction Analysis (max 100 words)
- Targeted Discovery Prompts (5 categorized questions: Architecture, Access, Compliance, Incident Response, Governance)
- Red Flag Triggers (2 clear disqualification criteria)
- Mutual Security Validation Roadmap (3 concise phases)
Self-review
- Check that all 5 discovery prompts directly engage {{security_decision_maker_title}}.
- Confirm that the implications of {{regulated_data_profile}} are accurately assessed.
- Verify no legal or indemnification promises are stated in the brief.
Explicit role, a named task, and discrete steps the model can follow.
Background, inputs and variables the model needs before it starts.
Hard boundaries — what the model must and must not do.
A named, field-level shape for the response.
Ordered work items that force analysis before an answer.
Length and structure that travel across frontier models.
Signal density — instruction weight without padding.
Documented variables so the scaffold adapts to new inputs.
Quality bar, assumptions and behaviour when inputs are thin.
How much real usage the template has behind it.