Prompt
Design Phishing Simulation Campaign
Use this when you need to design a phishing simulation campaign to test and train employee awareness.
How to use it
- Copy the prompt and paste it into ChatGPT, Claude, Gemini or any other AI.
- Replace every {{placeholder}} with your own details, or let the AI ask you for them.
- Use the follow-ups below to go deeper.
Role — You are a security awareness program designer who builds phishing simulations that educate employees without eroding trust in the security team.
Context you provide
- {{audience}} — who's being tested (all staff, a specific department, seniority level) and rough size
- {{threat_scenarios}} — the phishing tactics you want to simulate (e.g., credential harvest, invoice fraud, urgent-request pretexting)
- {{difficulty}} — how sophisticated the simulated emails should be, given the audience's current awareness level
- {{follow_up}} — what happens after someone clicks (training module, manager notification, none)
Instructions
- Ask for any missing inputs before starting.
- Design 2-3 email template outlines covering {{threat_scenarios}}, each with a believable pretext, sender, and call-to-action matched to {{difficulty}}.
- Define success metrics to track (click rate, report rate, credential-entry rate, time-to-report).
- Lay out the campaign timeline: launch window, reminder/no-repeat rules, and when results are shared.
- Specify {{follow_up}} actions and how they're communicated so the campaign reads as coaching, not punishment.
Output format — A campaign brief with sections: Scenarios (pretext and hook for each, described rather than written as ready-to-send email copy), Metrics, Timeline, and Follow-Up Plan. Keep under 350 words.
Guardrails — Do not produce ready-to-send phishing email copy that could be misused outside an authorized program; describe pretexts and structure instead. Recommend the campaign run only with documented authorization from security leadership and HR. Avoid scenarios that could cause real distress (e.g., fake emergencies, layoff notices).
Example — {{audience}}="all 150 employees, mixed awareness", {{threat_scenarios}}="fake IT password reset, executive wire-transfer request", {{difficulty}}="moderate, believable but with subtle red flags", {{follow_up}}="auto-enroll clickers in a 10-minute training module".