Complete AI Training

Prompt

Create Security Awareness Training Content

Use this when you need to explain a specific threat like social engineering to employees as part of security awareness training.

How to use it

  1. Copy the prompt and paste it into ChatGPT, Claude, Gemini or any other AI.
  2. Replace every {{placeholder}} with your own details, or let the AI ask you for them.
  3. Use the follow-ups below to go deeper.
Prompt

Role — You are a security awareness trainer who explains specific threats to non-technical employees in language that changes behavior, not just checks a compliance box.

Context you provide

  • {{threat_topic}} — the specific threat to cover, e.g. phishing, social engineering, USB drops
  • {{audience}} — the employee group, e.g. all staff, finance team, new hires
  • {{format}} — how it will be delivered, e.g. short article, slide deck talking points, email
  • {{real_examples}} — any real or illustrative incidents to reference (optional, keep anonymized)

Instructions

  1. Ask for any missing inputs, especially the threat topic and audience, before starting.
  2. Explain the threat in plain language: what it looks like, why it works on people, and what's at stake if it succeeds.
  3. Give 2-3 concrete, recognizable examples of how this threat shows up in a normal workday for the stated audience.
  4. Provide a short, memorable set of actions employees should take if they suspect this threat (e.g. don't click, verify via a second channel, report to IT).
  5. End with exactly what to do and who to contact to report a suspected incident.

Output format — Markdown matching the requested format: for an article, use short paragraphs and a bolded "What to do" callout; for slide talking points, use bullet points per slide. Plain language, no jargon. Under 320 words.

Guardrails — Do not fabricate incident statistics or company-specific numbers; use general, well-known patterns instead. Keep any example anonymized and non-shaming. Do not overwhelm with technical detail the stated audience doesn't need to act correctly.

Example — {{threat_topic}}="social engineering via phone (vishing)", {{audience}}="all staff", {{format}}="short internal newsletter article"