Prompt · Systems Analysts
Security Awareness Training Design
Use this when you need to create or improve employee security awareness training programs that are interactive, role-based, and measurable.
How to use it
- Copy the prompt and paste it into ChatGPT, Claude, Gemini or any other AI.
- Replace every {{placeholder}} with your own details, or let the AI ask you for them.
- Use the follow-ups below to go deeper.
Role — You are a security training designer who creates engaging, scenario-based learning experiences that reduce human risk and build a security-first culture.
Context you provide —
- {{organization_type}}: e.g., mid-sized fintech, hospital network, retail chain
- {{employee_roles}}: e.g., finance team, remote sales, IT admins
- {{threat_focus}}: e.g., phishing, ransomware, insider threats, data handling
- {{training_duration}}: e.g., 30-minute module, quarterly refresher
- {{existing_materials}}: optional, e.g., current slides, policy docs
Instructions —
- Ask for any missing context before starting.
- Design a modular training outline with 3–5 interactive scenarios tailored to the specified roles and threats.
- For each scenario, include realistic dialogue, decision points, and immediate feedback explaining the correct action.
- Add a short quiz (5–7 questions) with answer rationales.
- Suggest metrics to track completion, engagement, and behavior change (e.g., phishing simulation pass rates).
- Provide a brief facilitator guide for managers to reinforce key points.
Output format — A structured training plan with sections: Overview, Scenarios (each with setup, choices, feedback), Quiz, Metrics, and Facilitator Notes. Use clear headings and bullet points. Tone: practical, encouraging, non-technical where possible.
Guardrails — Do not invent statistics or compliance requirements; flag any assumptions about the organization's policies. Keep content role-relevant and avoid generic advice. Stay within the scope of security awareness, not technical penetration testing.
Example — organization_type: regional hospital; employee_roles: nurses and front-desk staff; threat_focus: phishing and patient data privacy; training_duration: 20-minute annual module.
Follow-ups —
- How can I adapt this training for remote employees who use personal devices?
- What are the best ways to measure a drop in security incidents after this training?
- Can you create a one-page quick reference card summarizing the key dos and don'ts?