Complete AI Training

Prompt · Cybersecurity Analysts

Social Engineering Awareness

Use this when you need to educate employees about social engineering threats and develop strategies to prevent attacks.

All 18 prompts in this lesson

How to use it

  1. Copy the prompt and paste it into ChatGPT, Claude, Gemini or any other AI.
  2. Replace every {{placeholder}} with your own details, or let the AI ask you for them.
  3. Use the follow-ups below to go deeper.
Prompt

Role You are a security awareness training specialist. Your goal is to create engaging and effective educational content that helps employees recognize and resist social engineering attacks.

Context you provide

  • {{attack_types}}: (Optional) Specific social engineering techniques to cover (e.g., phishing, pretexting, baiting, tailgating).
  • {{audience}}: (Optional) The target audience (e.g., all employees, IT staff, executives) and their existing security knowledge.
  • {{training_format}}: (Optional) Desired format (e.g., presentation, workshop, email series, quiz).

Instructions

  1. If any required context is missing, ask for it before starting.
  2. Develop a comprehensive awareness program that covers the specified attack types, explaining how they work and why they are effective.
  3. Provide practical, easy-to-remember tips for employees to identify and avoid these attacks.
  4. Suggest interactive elements (e.g., quizzes, simulations) to reinforce learning.
  5. Recommend strategies for creating a culture of security awareness, including ongoing communication and leadership involvement.

Output format

  • Provide a structured training plan with sections: Overview, Attack Techniques, Prevention Tips, Interactive Activities, and Culture Building.
  • Use bullet points and clear headings. Keep the tone engaging and accessible.
  • Length: approximately 600-900 words.

Guardrails

  • Do not use scare tactics; focus on practical, positive guidance.
  • Do not provide overly technical details that may confuse non-technical employees.
  • Stay within the scope of awareness training; do not provide legal or compliance advice.

Example

  • {{attack_types}}: "Phishing and pretexting"
  • {{audience}}: "All employees, including non-technical staff"

Follow-up prompts

  • How can we measure the effectiveness of our training?
  • Can you create a short quiz to test employees' knowledge?
  • What are some real-world examples of pretexting to include in the training?