Course overview
Lesson 4 of 8 · 3 promptsAI for Chief Information Security Officers (CISOs)
LESSON 04 OF 8

Security Awareness Training

3 prompts for Chief Information Security Officers (CISOs)

Prompts for Chief Information Security Officers (CISOs): copy one, fill it in, paste it into your AI.

Track progress as a member

In this lesson

  1. 01Draft Phishing Awareness EmailUse this when you need to reinforce phishing red flags after a simulation or real incident.
  2. 02Create Role-Based Security Training OutlineUse this when different teams need tailored security awareness training mapped to their daily work.
  3. 03Turn Security Policy Into Quiz QuestionsUse this when you need to check whether staff understood a new or updated security policy.
1Copy the promptClick Copy on the prompt you need.
2Paste it into your AIChatGPT, Claude, Gemini or Copilot.
3Fill in the {{brackets}}Your own details, or let the AI ask you.
4Follow up and checkUse the follow-ups, then check the facts.
01

Draft Phishing Awareness Email

Use this when you need to reinforce phishing red flags after a simulation or real incident.

Prompt

Role You are a security awareness lead writing a short internal email that turns a recent phishing simulation or real incident into practical, non-punitive learning for staff.

Context you provide

  • {{audience}} — who receives this (e.g. all staff, finance team)
  • {{trigger_event}} — simulation or real incident, and what happened
  • {{red_flags}} — the specific warning signs to highlight
  • {{action_requested}} — what you want people to do differently (e.g. report, verify)
  • {{reporting_channel}} — how and where to report suspicious email
  • {{tone}} — e.g. calm, direct, supportive
  • {{deadline_or_date}} — any date or deadline to reference

Instructions

  1. Ask for any missing inputs, then draft the email.
  2. Open with one plain sentence on why you are writing, without blame.
  3. Explain the trigger event briefly and factually.
  4. List the red flags as short bullets with a one-line example each.
  5. State the requested action and the reporting channel clearly.
  6. Close with a supportive line and a single point of contact.

Output format Subject line plus email body, under 250 words, scannable bullets, plain language, no jargon or scare tactics. Leave out technical indicators, statistics and policy citations.

Guardrails

  • Do not name or imply any individual was at fault.
  • Do not invent figures, tool names or policy references; use only the inputs given.
  • Flag anything that must be confirmed with your security or legal team before sending.

Example Audience: all staff. Trigger: simulation where 12% clicked a fake invoice link. Red flags: mismatched sender domain, urgency, unexpected attachment. Action: report via the Report Phishing button.

Open as its own page

02

Create Role-Based Security Training Outline

Use this when different teams need tailored security awareness training mapped to their daily work.

Prompt

Role — You are a security awareness program lead supporting a CISO. You optimise for training outlines that map to how each role actually handles data, systems and people, so learners can apply them the same week.

Context you provide

  • {{organization_type}} — sector and rough size
  • {{roles_in_scope}} — teams or job families to cover
  • {{training_duration}} — minutes or modules per role
  • {{delivery_format}} — live, e-learning, microlearning, hybrid
  • {{policy_references}} — internal policies learners must follow
  • {{incident_themes}} — recurring issues seen internally
  • {{compliance_obligations}} — obligations that apply, named by you
  • {{assessment_method}} — quiz, phishing simulation, manager sign-off

Instructions

  1. Ask for any missing inputs, then confirm scope in one short paragraph before drafting.
  2. For each role, list the three to five security behaviours that matter most in their daily tasks.
  3. Build a module outline per role: title, learning objective, key points, realistic scenario, and a knowledge check.
  4. Sequence modules from baseline to role-specific, and note what can be shared across roles.
  5. Add a delivery plan: cadence, owner, and how completion is tracked.
  6. Close with two or three metrics that show whether behaviour changed, not just completion.

Output format — Markdown with one section per role; tables allowed. Keep each objective to one sentence. No filler introductions. Do not write full slide scripts.

Guardrails — Do not invent regulations, framework control numbers, or incident details; use only what the user supplies. Flag any content needing legal, HR or compliance review. State that role-specific technical procedures must be verified against current internal policy and system owner guidance.

Example — {{organization_type}}: regional health insurer; {{roles_in_scope}}: finance, clinical support, IT admins, executive assistants.

Open as its own page

03

Turn Security Policy Into Quiz Questions

Use this when you need to check whether staff understood a new or updated security policy.

Prompt

Role — You are a security awareness content designer who turns plain policy text into fair, job-relevant quiz questions that test comprehension, not trivia.

Context you provide

  • {{policy_name}} — title and version
  • {{policy_text}} — the new or updated wording
  • {{audience}} — roles or teams taking the quiz
  • {{high_risk_behaviours}} — the mistakes that matter most
  • {{question_count}} — how many questions
  • {{format}} — multiple choice, true/false or scenario
  • {{pass_mark}} — required score, if set

Instructions

  1. Ask for any missing inputs, then wait.
  2. Identify the 3 to 6 policy rules that change behaviour or carry real risk.
  3. Write {{question_count}} questions, each tied to one rule, using scenarios from {{audience}}.
  4. For multiple choice, give four options with one correct answer and distractors based on common misreadings.
  5. Add a one-sentence rationale per answer, pointing to the clause it comes from.
  6. Flag policy wording that is ambiguous or untestable and suggest a rewrite.
  7. Keep every question answerable from {{policy_text}} alone.

Output format — Numbered questions, options, correct answer, rationale, then a short list of flagged gaps. Plain language, no trick questions. Leave out legal citations and invented standards.

Guardrails — Do not invent policy rules, clause numbers or penalties; use only {{policy_text}}. Flag assumptions and any question that depends on local law or a regulator. Tell the user to have the policy owner or legal reviewer approve the quiz before release.

Example — Policy: Acceptable Use v3, finance team, 8 multiple choice questions, 80% pass mark.

Open as its own page

Skills for these tasks

Give your AI these skills and it does these tasks the expert way. Connect your AI once and it picks them up by itself.