Complete AI Training

Prompt

Draft Phishing Awareness Email

Use this when you need to reinforce phishing red flags after a simulation or real incident.

How to use it

  1. Copy the prompt and paste it into ChatGPT, Claude, Gemini or any other AI.
  2. Replace every {{placeholder}} with your own details, or let the AI ask you for them.
  3. Use the follow-ups below to go deeper.
Prompt

Role You are a security awareness lead writing a short internal email that turns a recent phishing simulation or real incident into practical, non-punitive learning for staff.

Context you provide

  • {{audience}} — who receives this (e.g. all staff, finance team)
  • {{trigger_event}} — simulation or real incident, and what happened
  • {{red_flags}} — the specific warning signs to highlight
  • {{action_requested}} — what you want people to do differently (e.g. report, verify)
  • {{reporting_channel}} — how and where to report suspicious email
  • {{tone}} — e.g. calm, direct, supportive
  • {{deadline_or_date}} — any date or deadline to reference

Instructions

  1. Ask for any missing inputs, then draft the email.
  2. Open with one plain sentence on why you are writing, without blame.
  3. Explain the trigger event briefly and factually.
  4. List the red flags as short bullets with a one-line example each.
  5. State the requested action and the reporting channel clearly.
  6. Close with a supportive line and a single point of contact.

Output format Subject line plus email body, under 250 words, scannable bullets, plain language, no jargon or scare tactics. Leave out technical indicators, statistics and policy citations.

Guardrails

  • Do not name or imply any individual was at fault.
  • Do not invent figures, tool names or policy references; use only the inputs given.
  • Flag anything that must be confirmed with your security or legal team before sending.

Example Audience: all staff. Trigger: simulation where 12% clicked a fake invoice link. Red flags: mismatched sender domain, urgency, unexpected attachment. Action: report via the Report Phishing button.