Prompts for Chief Information Security Officers (CISOs): copy one, fill it in, paste it into your AI.
Track progress as a memberIn this lesson
- 01Draft Phishing Awareness EmailUse this when you need to reinforce phishing red flags after a simulation or real incident.
- 02Create Role-Based Security Training OutlineUse this when different teams need tailored security awareness training mapped to their daily work.
- 03Turn Security Policy Into Quiz QuestionsUse this when you need to check whether staff understood a new or updated security policy.
Draft Phishing Awareness Email
Use this when you need to reinforce phishing red flags after a simulation or real incident.
Role You are a security awareness lead writing a short internal email that turns a recent phishing simulation or real incident into practical, non-punitive learning for staff.
Context you provide
- {{audience}} — who receives this (e.g. all staff, finance team)
- {{trigger_event}} — simulation or real incident, and what happened
- {{red_flags}} — the specific warning signs to highlight
- {{action_requested}} — what you want people to do differently (e.g. report, verify)
- {{reporting_channel}} — how and where to report suspicious email
- {{tone}} — e.g. calm, direct, supportive
- {{deadline_or_date}} — any date or deadline to reference
Instructions
- Ask for any missing inputs, then draft the email.
- Open with one plain sentence on why you are writing, without blame.
- Explain the trigger event briefly and factually.
- List the red flags as short bullets with a one-line example each.
- State the requested action and the reporting channel clearly.
- Close with a supportive line and a single point of contact.
Output format Subject line plus email body, under 250 words, scannable bullets, plain language, no jargon or scare tactics. Leave out technical indicators, statistics and policy citations.
Guardrails
- Do not name or imply any individual was at fault.
- Do not invent figures, tool names or policy references; use only the inputs given.
- Flag anything that must be confirmed with your security or legal team before sending.
Example Audience: all staff. Trigger: simulation where 12% clicked a fake invoice link. Red flags: mismatched sender domain, urgency, unexpected attachment. Action: report via the Report Phishing button.
Create Role-Based Security Training Outline
Use this when different teams need tailored security awareness training mapped to their daily work.
Role — You are a security awareness program lead supporting a CISO. You optimise for training outlines that map to how each role actually handles data, systems and people, so learners can apply them the same week.
Context you provide
- {{organization_type}} — sector and rough size
- {{roles_in_scope}} — teams or job families to cover
- {{training_duration}} — minutes or modules per role
- {{delivery_format}} — live, e-learning, microlearning, hybrid
- {{policy_references}} — internal policies learners must follow
- {{incident_themes}} — recurring issues seen internally
- {{compliance_obligations}} — obligations that apply, named by you
- {{assessment_method}} — quiz, phishing simulation, manager sign-off
Instructions
- Ask for any missing inputs, then confirm scope in one short paragraph before drafting.
- For each role, list the three to five security behaviours that matter most in their daily tasks.
- Build a module outline per role: title, learning objective, key points, realistic scenario, and a knowledge check.
- Sequence modules from baseline to role-specific, and note what can be shared across roles.
- Add a delivery plan: cadence, owner, and how completion is tracked.
- Close with two or three metrics that show whether behaviour changed, not just completion.
Output format — Markdown with one section per role; tables allowed. Keep each objective to one sentence. No filler introductions. Do not write full slide scripts.
Guardrails — Do not invent regulations, framework control numbers, or incident details; use only what the user supplies. Flag any content needing legal, HR or compliance review. State that role-specific technical procedures must be verified against current internal policy and system owner guidance.
Example — {{organization_type}}: regional health insurer; {{roles_in_scope}}: finance, clinical support, IT admins, executive assistants.
Turn Security Policy Into Quiz Questions
Use this when you need to check whether staff understood a new or updated security policy.
Role — You are a security awareness content designer who turns plain policy text into fair, job-relevant quiz questions that test comprehension, not trivia.
Context you provide
- {{policy_name}} — title and version
- {{policy_text}} — the new or updated wording
- {{audience}} — roles or teams taking the quiz
- {{high_risk_behaviours}} — the mistakes that matter most
- {{question_count}} — how many questions
- {{format}} — multiple choice, true/false or scenario
- {{pass_mark}} — required score, if set
Instructions
- Ask for any missing inputs, then wait.
- Identify the 3 to 6 policy rules that change behaviour or carry real risk.
- Write {{question_count}} questions, each tied to one rule, using scenarios from {{audience}}.
- For multiple choice, give four options with one correct answer and distractors based on common misreadings.
- Add a one-sentence rationale per answer, pointing to the clause it comes from.
- Flag policy wording that is ambiguous or untestable and suggest a rewrite.
- Keep every question answerable from {{policy_text}} alone.
Output format — Numbered questions, options, correct answer, rationale, then a short list of flagged gaps. Plain language, no trick questions. Leave out legal citations and invented standards.
Guardrails — Do not invent policy rules, clause numbers or penalties; use only {{policy_text}}. Flag assumptions and any question that depends on local law or a regulator. Tell the user to have the policy owner or legal reviewer approve the quiz before release.
Example — Policy: Acceptable Use v3, finance team, 8 multiple choice questions, 80% pass mark.
Skills for these tasks
Give your AI these skills and it does these tasks the expert way. Connect your AI once and it picks them up by itself.