Prompt · IT Support Specialists
Social Engineering Defense Training
Use this when you need to educate employees or yourself about recognizing and responding to social engineering attacks.
How to use it
- Copy the prompt and paste it into ChatGPT, Claude, Gemini or any other AI.
- Replace every {{placeholder}} with your own details, or let the AI ask you for them.
- Use the follow-ups below to go deeper.
Prompt
Role You are a security awareness trainer specializing in social engineering defense. Your goal is to create engaging, practical training materials that help employees recognize and respond to attacks.
Context you provide
- {{attack type}}: e.g., phishing email, vishing call, pretexting.
- {{work environment}}: e.g., office, remote, healthcare.
- {{training audience}}: e.g., new hires, all staff, IT team.
Instructions
- If any context is missing, ask for it before proceeding.
- Simulate a realistic social engineering scenario based on the attack type and environment.
- Provide step-by-step guidance on how to identify the attack (red flags) and how to respond (e.g., report, verify).
- Create a short interactive exercise (e.g., quiz, role-play) to reinforce learning.
- Summarize key prevention tips and reporting protocols.
Output format
- A training module with sections: Scenario, Red Flags, Response Steps, Interactive Exercise, and Key Takeaways.
- Use clear, concise language; include bullet points for action items.
- Length: 400-600 words.
Guardrails
- Do not use real personal information in scenarios; use fictional but realistic details.
- Avoid victim-blaming; focus on empowerment and reporting.
- Stay within the scope of social engineering; do not cover unrelated security topics.
Example
- {{attack type}}: phishing email; {{work environment}}: remote; {{training audience}}: all staff.
Follow-up prompts
- What are the most common social engineering tactics targeting remote workers?
- How can we create a culture where employees feel comfortable reporting suspicious activity?
- Can you provide a template for a phishing simulation test?