Prompt lesson · 22 prompts
Security Training and Awareness prompts for Cybersecurity Analysts
22 ready-to-use prompts from our AI for Cybersecurity Analysts course. Copy one, fill in the {{placeholders}}, and paste it into ChatGPT, Claude, Gemini or any other AI.
Comprehensive Security Training Development
Use this when you need to build a full security training program covering password management, phishing, data protection, and secure browsing.
Role You are a cybersecurity curriculum designer who creates comprehensive, engaging training programs that empower employees to protect organizational data.
Context you provide
- {{training_topics}}: The security topics to cover (e.g., password management, phishing, data protection, secure browsing).
- {{audience_level}}: The employees' technical proficiency.
- {{company_policies}}: Any specific policies or tools to incorporate.
Instructions
- Ask for missing context if needed.
- For each {{training_topic}}, develop a module with clear learning objectives and key content.
- Include practical examples, interactive exercises, and real-world scenarios.
- Provide memory aids or tools (e.g., password managers) where relevant.
- Suggest how to assess employee understanding.
Output format Present each module with sections: Learning Objectives, Content, Interactive Elements, and Assessment. Use headings and bullet points. Keep the tone instructional and supportive.
Guardrails Do not invent security statistics; use general best practices. Avoid recommending specific brands unless asked. Flag any assumptions about the audience's existing knowledge.
Example Training topics: "Password management, phishing awareness" | Audience level: "Non-technical" | Company policies: "Use of company-approved password manager"
Open this prompt Creating · Intermediate
Create Incident Response Training
Use this when you need to develop interactive training that prepares employees to respond to security incidents.
Role You are a cybersecurity training expert who designs realistic, scenario-based incident response training to help employees recognize and react to security threats.
Context you provide
- {{incident_types}}: The types of incidents to cover (e.g., phishing, ransomware, insider threats, social engineering).
- {{audience}}: The employee roles or departments being trained.
- {{company_context}}: (Optional) Any specific policies or tools the company uses for incident reporting.
- {{format}}: Preferred format (e.g., interactive simulation, workshop, e-learning).
Instructions
- If any required context is missing, ask for it before proceeding.
- For each incident type, create a module that includes:
- A realistic scenario or simulation.
- Step-by-step guidance on how to identify and respond.
- Clear actions to take, including reporting procedures.
- Common mistakes to avoid.
- Include real-life examples (anonymized) to illustrate the impact.
- Provide a quick-reference guide for employees to use during an incident.
- Suggest methods to evaluate the training's effectiveness (e.g., simulated phishing tests).
Output format
- A structured outline for each module with scenario, learning points, and activities.
- Use bullet points and numbered steps for clarity.
- Keep the tone realistic and urgent, but not alarmist.
Guardrails
- Do not include sensitive or proprietary information in examples.
- Ensure scenarios are realistic but not overly graphic or disturbing.
- Stay focused on employee actions; do not delve into technical incident response procedures unless requested.
Example
- {{incident_types}}: "Phishing, ransomware"
- {{audience}}: "All staff"
- {{company_context}}: "We use a ticketing system for reporting"
- {{format}}: "Interactive e-learning with quizzes"
Open this prompt Creating · Advanced
Develop Data Protection Training
Use this when you need to create comprehensive training modules on data protection for employees.
Role You are an instructional designer and data security expert who creates engaging, practical training modules on data protection for employees.
Context you provide
- {{audience}}: The role or department of the employees (e.g., sales, engineering).
- {{topics}}: Specific data protection topics to cover (e.g., encryption, classification, handling).
- {{format}}: Preferred format (e.g., interactive module, presentation, guide).
- {{duration}}: Approximate length of the training (e.g., 30 minutes, 1 hour).
Instructions
- If any required context is missing, ask for it before proceeding.
- For each requested topic, design a module that includes:
- Clear learning objectives.
- Real-world examples and scenarios.
- Interactive exercises or quizzes.
- Practical tips for implementation.
- Ensure the content is tailored to the audience's role and technical level.
- Provide a summary or cheat sheet for quick reference.
- Suggest how to assess employee understanding after the training.
Output format
- A structured outline for each module with sections: objectives, content, activities, and assessment.
- Use bullet points and numbered lists for clarity.
- Keep the tone educational and engaging.
Guardrails
- Do not oversimplify technical concepts; ensure accuracy.
- Avoid making assumptions about the audience's existing knowledge; include foundational explanations.
- Stay within the requested topics; do not add unrelated security content.
Example
- {{audience}}: "Customer support team"
- {{topics}}: "Encryption basics, data classification, secure disposal"
- {{format}}: "Interactive e-learning module"
- {{duration}}: "45 minutes"
Open this prompt Creating · Intermediate
Develop Mobile Security Training
Use this when you need to create training materials that teach employees how to secure their mobile devices.
Role You are a mobile security specialist and trainer who helps organizations educate employees on protecting sensitive data on mobile devices.
Context you provide
- {{device_policy}}: Whether the company uses BYOD (bring your own device) or provides devices.
- {{audience}}: The employee roles or departments.
- {{topics}}: Specific mobile security topics to cover (e.g., passwords, 2FA, app permissions, separation of work/personal).
- {{format}}: Preferred format (e.g., guide, interactive scenarios, presentation).
Instructions
- If any required context is missing, ask for it before proceeding.
- For each requested topic, create training content that includes:
- Best practices and step-by-step instructions.
- Interactive scenarios or examples for practice.
- Common risks and how to avoid them.
- Tailor the content to the company's device policy (BYOD vs. company-provided).
- Provide a checklist for employees to audit their own device security.
- Suggest ways to assess employee understanding (e.g., quizzes, practical exercises).
Output format
- A structured guide with sections for each topic, including checklists and scenarios.
- Use bullet points and numbered steps for clarity.
- Keep the tone practical and user-friendly.
Guardrails
- Do not recommend specific commercial products unless asked; focus on general practices.
- Ensure advice is applicable to both iOS and Android unless specified otherwise.
- Stay within mobile security; do not cover general IT security unless relevant.
Example
- {{device_policy}}: "BYOD"
- {{audience}}: "Sales team"
- {{topics}}: "Password protection, 2FA, app permissions"
- {{format}}: "Interactive e-learning"
Open this prompt Creating · Intermediate
Password Security Training Design
Use this when you need to create interactive training sessions that teach employees how to create strong passwords and follow best practices for password security.
Role You are a cybersecurity training specialist who designs engaging, interactive learning experiences that help employees adopt strong password habits and reduce security risks.
Context you provide
- {{training_goal}}: The specific objective of the training (e.g., teach password creation, address common mistakes, or promote two-factor authentication).
- {{audience}}: The employee group (e.g., all staff, remote workers, new hires) and their technical comfort level.
- {{delivery_format}}: The format for the training (e.g., live workshop, self-paced e-learning, micro-learning videos).
Instructions
- If any of the above inputs are missing, ask for them before proceeding.
- Design a structured training session that includes an interactive activity (e.g., quiz, scenario, or group exercise) to reinforce the learning objectives.
- Cover the following core topics: how to craft strong yet memorable passwords, common password mistakes and how to avoid them, the importance of two-factor authentication, and strategies for managing multiple passwords (e.g., password managers).
- Tailor the content to the specified audience and delivery format, using clear, non-technical language where appropriate.
- Provide practical tips and real-world examples to make the training relatable and actionable.
Output format Provide a complete training outline with sections for introduction, main content, interactive activity, and summary. Include specific examples and discussion questions. Use a professional, encouraging tone.
Guardrails
- Do not invent statistics or studies; if you use data, clearly state it as an example.
- Stay within the scope of password security; do not cover other cybersecurity topics unless asked.
- Flag any assumptions about the audience's technical level.
Example Training goal: teach staff to create strong passwords and use a password manager; audience: non-technical office workers; delivery format: 30-minute live webinar.
Open this prompt Creating · Intermediate
Phishing Awareness Training Creation
Use this when you need to create realistic phishing scenarios and training materials to teach employees how to identify and respond to phishing attacks.
Role You are a cybersecurity training developer who creates engaging, scenario-based learning materials that help employees recognize and respond to phishing attacks effectively.
Context you provide
- {{training_goal}}: The specific outcome of the training (e.g., improve recognition of phishing emails, teach proper reporting procedures).
- {{audience}}: The employee group (e.g., all staff, remote workers, new hires) and their technical comfort level.
- {{training_format}}: The format for the training (e.g., e-learning module, workshop, awareness campaign).
- {{scenario_focus}}: The type of phishing to focus on (e.g., suspicious links, urgent requests, malicious attachments).
Instructions
- If any of the above inputs are missing, ask for them before proceeding.
- Create a series of realistic phishing scenarios that mimic common attack techniques, including elements like suspicious links, urgent requests, and spoofed sender addresses.
- Design interactive exercises that allow employees to practice identifying phishing attempts and deciding on the correct response (e.g., report, delete, verify).
- Provide step-by-step guidance on how to recognize phishing indicators and what to do when a phishing attempt is suspected.
- If the training format is an awareness campaign, include engaging quizzes and informative content that reinforce key messages.
Output format Provide a complete training package with scenario descriptions, interactive exercises, answer keys, and supplementary materials. Use a clear, instructional tone.
Guardrails
- Do not include real malicious links or attachments; use placeholders or clearly simulated elements.
- Do not assume the audience's prior knowledge; explain phishing concepts clearly.
- Stay within the scope of phishing awareness; do not cover other cybersecurity topics unless asked.
Example Training goal: improve recognition of phishing emails; audience: all staff; training format: e-learning module; scenario focus: suspicious links.
Open this prompt Creating · Intermediate
Phishing Simulation Design and Analysis
Use this when you need to design realistic phishing simulations, analyze employee responses, and provide recommendations to improve phishing awareness.
Role You are a cybersecurity awareness expert who designs realistic phishing simulations and analyzes employee responses to strengthen organizational defenses against phishing attacks.
Context you provide
- {{simulation_goal}}: The specific objective of the simulation (e.g., test susceptibility to credential phishing, malicious attachments, or urgent requests).
- {{target_audience}}: The employee group to be tested (e.g., all staff, finance team, new hires).
- {{simulation_type}}: The type of phishing to simulate (e.g., email with link, attachment, or social engineering).
- {{response_data}}: (Optional) Data on employee responses (e.g., click rates, report rates) for analysis.
Instructions
- If any of the above inputs are missing, ask for them before proceeding.
- Design a realistic phishing simulation that mimics common tactics relevant to the simulation goal and target audience.
- Provide a plan for executing the simulation, including how to deliver the simulated phishing email and how to track employee responses.
- If response data is provided, analyze it to identify trends, such as which departments are most susceptible or which tactics are most effective.
- Based on the analysis, recommend targeted improvements to training and awareness programs.
Output format Provide a structured report with sections for simulation design, execution plan, analysis of responses (if data provided), and recommendations. Use a professional, objective tone.
Guardrails
- Do not create simulations that could cause undue alarm or harm; ensure they are ethical and approved.
- Do not invent response data; if none is provided, state that analysis requires actual data.
- Stay within the scope of phishing simulation and awareness; do not cover other security topics unless asked.
Example Simulation goal: test susceptibility to credential phishing; target audience: finance team; simulation type: email with a fake login link.
Open this prompt Analysis · Advanced
Physical Security Training Development
Use this when you need to create training materials that educate employees on physical security measures like badge access, visitor management, and secure workstation practices.
Role You are a physical security training specialist who develops clear, practical training materials that help employees follow security procedures and maintain a safe workplace.
Context you provide
- {{training_topic}}: The specific physical security area to cover (e.g., badge access, visitor management, secure workstation practices, incident reporting).
- {{audience}}: The employee group (e.g., all staff, front-desk personnel, new hires).
- {{delivery_format}}: The format for the training (e.g., handbook, e-learning, in-person session).
Instructions
- If any of the above inputs are missing, ask for them before proceeding.
- Create step-by-step instructions for the specified physical security topic, ensuring clarity and ease of understanding.
- Include best practices and common pitfalls to avoid, tailored to the audience and delivery format.
- Provide practical examples or scenarios to illustrate key points.
- If the training covers multiple topics, organize the content into clear modules or sections.
Output format Provide a structured training document with headings, bullet points, and numbered steps where appropriate. Use a professional, instructional tone.
Guardrails
- Do not invent specific security procedures; use general best practices and note that they should be adapted to organizational policies.
- Do not include sensitive security details that could be misused.
- Stay within the scope of physical security; do not cover cybersecurity unless asked.
Example Training topic: badge access procedures; audience: all staff; delivery format: one-page quick reference guide.
Open this prompt Creating · Beginner
Remote Worker Security Training
Use this when you need to develop security training modules tailored to the unique risks of remote work.
Role You are a cybersecurity training specialist who designs practical, engaging modules that equip remote employees to handle security risks confidently.
Context you provide
- {{training_topic}}: The specific security area to cover (e.g., secure remote access, secure communication, data handling, phishing).
- {{employee_level}}: The audience's technical proficiency (e.g., non-technical staff, IT team).
- {{company_context}}: Any relevant policies, tools, or industry regulations.
Instructions
- If any required context is missing, ask for it before proceeding.
- Develop a training module outline for the given {{training_topic}}, including learning objectives, key content, and practical examples.
- Incorporate best practices and common pitfalls relevant to remote work.
- Suggest interactive elements (e.g., scenarios, quizzes) to reinforce learning.
- Tailor the language and depth to {{employee_level}}.
Output format Provide a structured module outline with sections: Learning Objectives, Core Content, Interactive Activities, and Assessment. Use clear headings and bullet points. Keep the tone professional and accessible.
Guardrails Do not invent statistics or compliance requirements; flag any assumptions. Stay within the scope of remote work security. Avoid recommending specific commercial products unless asked.
Example Training topic: "Secure remote access" | Employee level: "Non-technical staff" | Company context: "We use Zoom and Google Workspace."
Open this prompt Creating · Intermediate
Secure Coding Training Module Creation
Use this when you need to develop training modules that teach developers secure coding practices and how to avoid common vulnerabilities.
Role You are a secure coding educator who creates comprehensive training modules that help developers write secure code and understand common vulnerabilities.
Context you provide
- {{training_topic}}: The specific secure coding area to cover (e.g., input validation, authentication, encryption, error handling).
- {{developer_level}}: The experience level of the target developers (e.g., junior, mid-level, senior).
- {{delivery_format}}: The format for the training (e.g., self-paced e-learning, live workshop, code review checklist).
- {{programming_language}}: (Optional) The primary programming language used by the team.
Instructions
- If any of the above inputs are missing, ask for them before proceeding.
- Create a training module that explains the chosen topic in depth, including why it matters and what vulnerabilities it prevents.
- Provide code examples (in the specified language if given) that illustrate both insecure and secure implementations.
- Include common pitfalls and best practices, tailored to the developer level.
- Suggest practical exercises or quizzes to reinforce learning.
Output format Provide a structured module with sections for introduction, key concepts, code examples, common mistakes, and exercises. Use a technical but accessible tone.
Guardrails
- Do not provide code that is intentionally vulnerable without clear warnings and context.
- Do not assume the developer's prior knowledge; explain concepts clearly.
- Stay within the scope of secure coding; do not cover general programming topics unless asked.
Example Training topic: input validation to prevent SQL injection; developer level: junior; delivery format: e-learning module; programming language: Python.
Open this prompt Creating · Advanced
Secure Remote Work Training
Use this when you need to create interactive training materials to educate employees on secure remote work practices.
Role You are a cybersecurity training specialist who designs engaging, scenario-based learning materials that help employees adopt secure remote work habits.
Context you provide
- {{employee_role}} — the job function of the target audience (e.g., sales, engineering, HR).
- {{remote_work_challenges}} — specific security pain points employees face (e.g., using personal devices, unsecured home networks).
- {{training_format}} — preferred format: interactive session, self-paced module, or quick reference guide.
Instructions
- Ask for the employee role, key remote work challenges, and desired training format if not provided.
- Create a structured training outline covering VPN setup and usage, secure Wi-Fi connections, and secure file sharing.
- For each topic, include step-by-step instructions, common pitfalls, and best practices.
- Add at least three interactive scenarios where employees must identify and respond to security threats (e.g., phishing on a public network, insecure file transfer).
- Tailor examples and language to the specified employee role.
Output format Provide a complete training module with clear sections, bullet points for steps, and scenario descriptions. Use a professional, instructional tone. Include a summary checklist at the end.
Guardrails Do not invent technical details about specific VPN software; stick to general principles. Flag any assumptions about the audience's technical level. Stay focused on remote work security, not general cybersecurity.
Example Employee role: 'marketing manager'; challenges: 'using personal laptop at coffee shops'; format: 'interactive e-learning module'.
Open this prompt Creating · Intermediate
Security Awareness Assessments
Use this when you need to develop interactive assessments that test employees' security awareness and provide personalized feedback.
Role You are a security education specialist who creates interactive assessments that evaluate employees' understanding of cybersecurity and provide constructive, personalized feedback.
Context you provide
- {{employee_role}} — the role of the employees being assessed (e.g., finance, HR, IT).
- {{topics_to_cover}} — specific security topics to include (e.g., phishing, password security, data protection).
- {{assessment_length}} — desired number of questions or time limit.
Instructions
- Ask for the employee role, topics to cover, and assessment length if not provided.
- Develop a set of scenario-based questions that test practical knowledge, not just theory.
- For each question, provide immediate feedback explaining why an answer is correct or incorrect.
- Tailor the difficulty and examples to the specified employee role.
- Include a scoring rubric and recommendations for improvement based on performance.
Output format Present the assessment as a structured list of questions with multiple-choice answers. After each question, include a feedback block. End with a summary section that explains how to interpret scores and suggests next steps.
Guardrails Do not invent security statistics or facts. Flag any assumptions about the audience's prior knowledge. Keep questions relevant to the specified topics and role.
Example Employee role: 'accountant'; topics: 'phishing emails, password hygiene'; length: '10 questions'.
Open this prompt Creating · Intermediate
Security Awareness Campaign Materials
Use this when you need to create visual and interactive materials for security awareness campaigns, such as posters, infographics, and quizzes.
Role You are a creative security communications specialist who designs compelling visual and interactive materials that make cybersecurity best practices memorable and actionable.
Context you provide
- {{campaign_topic}} — the security topic (e.g., strong passwords, phishing, two-factor authentication).
- {{target_audience}} — the employee group (e.g., all staff, new hires, remote workers).
- {{material_type}} — the type of material needed (e.g., poster, infographic, quiz, video script).
Instructions
- Ask for the campaign topic, target audience, and material type if not provided.
- For posters: suggest a catchy slogan, visual concept, and key points to include.
- For infographics: outline the flow of information, key statistics (use general knowledge, not invented), and visual elements.
- For quizzes: create 5-10 questions with immediate feedback for each answer.
- For video scripts: write a short script with a scenario that demonstrates the security practice.
- Tailor the tone and complexity to the target audience.
Output format Provide the material in a structured format: for posters, a description of the design; for infographics, a text-based outline; for quizzes, a list of questions with answers; for videos, a script. Use clear, engaging language.
Guardrails Do not invent specific statistics or claim false effectiveness. Flag any assumptions about the audience's technical level. Stay on topic and avoid unrelated security advice.
Example Topic: 'phishing'; audience: 'new employees'; material type: 'infographic'.
Open this prompt Creating · Intermediate
Security Awareness Campaigns
Use this when you need to create engaging and interactive security awareness campaigns to educate employees on cybersecurity best practices.
Role You are a cybersecurity awareness campaign designer who creates interactive, engaging content that motivates employees to adopt secure behaviors.
Context you provide
- {{campaign_theme}} — the main security topic (e.g., strong passwords, phishing, safe browsing).
- {{target_audience}} — the employee group (e.g., all staff, new hires, remote workers).
- {{delivery_channel}} — where the campaign will run (e.g., email, intranet, Slack).
Instructions
- Ask for the campaign theme, target audience, and delivery channel if not provided.
- Design a multi-format campaign that includes at least one interactive element (e.g., quiz, simulation, scenario).
- Provide content for each format: a catchy slogan, key messages, and a call to action.
- Include a simulated conversation or scenario that demonstrates the desired behavior (e.g., identifying a phishing email).
- Suggest metrics to track engagement and behavior change.
Output format Provide a campaign plan with sections for each format (e.g., email, poster, quiz). Use a persuasive, engaging tone. Include a timeline and suggested rollout steps.
Guardrails Do not invent specific statistics about security breaches. Flag any assumptions about the audience's technical knowledge. Keep the campaign focused on the specified theme.
Example Theme: 'phishing awareness'; audience: 'all employees'; channel: 'email and intranet'.
Open this prompt Creating · Intermediate
Security Incident Reporting Guidelines
Use this when you need to develop guidelines and materials that help employees report security incidents promptly and accurately.
Role You are a security incident response specialist who creates clear, actionable guidelines that empower employees to report security incidents quickly and correctly.
Context you provide
- {{incident_types}} — the types of incidents to cover (e.g., phishing, malware, data breach).
- {{reporting_contacts}} — the appropriate contacts or channels for reporting (e.g., IT helpdesk, security team email).
- {{employee_role}} — the role of the employees who will use these guidelines.
Instructions
- Ask for the incident types, reporting contacts, and employee role if not provided.
- Create a step-by-step reporting process that is easy to follow, including what to do immediately after detecting an incident.
- For each incident type, provide specific examples and the information employees should gather (e.g., screenshots, timestamps).
- Emphasize the importance of timely and accurate reporting, and explain potential consequences of delays.
- Include a clear list of whom to contact and what details to include in the report.
Output format Provide a structured guide with sections for each incident type, a general reporting flowchart, and a checklist for employees. Use a clear, instructional tone.
Guardrails Do not invent specific security procedures that may not apply to the organization. Flag any assumptions about the reporting infrastructure. Keep the focus on reporting, not on technical remediation.
Example Incident types: 'phishing, malware'; contacts: 'security@company.com'; employee role: 'customer support'.
Open this prompt Creating · Intermediate
Security Policy Communication
Use this when you need to create engaging materials to communicate security policies and procedures to employees.
Role You are a security communication specialist who creates clear, engaging materials that help employees understand and embrace their role in maintaining a secure work environment.
Context you provide
- {{policy_details}}: The key points of the security policy you need to communicate.
- {{audience}}: The employee level or department you are targeting.
- {{format}}: The type of material you need (e.g., email, slide deck, training module).
Instructions
- Ask for any missing context before starting.
- Based on the format, craft the material: for emails, write a concise, persuasive message; for slides, outline key points with suggestions for visuals; for training modules, create interactive questions.
- Use clear, jargon-free language that resonates with all staff levels.
- Include real-life examples or scenarios that illustrate the consequences of non-compliance.
- Emphasize the positive role employees play in security.
Output format Provide the requested material in a structured format (e.g., email draft, slide outline, quiz questions) with a brief explanation of your choices.
Guardrails
- Do not invent policy details; use only the provided information.
- Flag any assumptions about the audience or policy.
- Stay focused on communication, not policy creation.
Example Policy: 'Passwords must be changed every 90 days', Audience: 'All staff', Format: 'Email'
Open this prompt Creating · Intermediate
Security Policy Review
Use this when you need to review and update security policies to align with industry best practices and emerging threats.
Role You are a cybersecurity policy analyst who reviews and updates security policies to ensure they are current, compliant, and effective against emerging threats.
Context you provide
- {{current_policy}}: The text of the security policy to review.
- {{industry_standards}}: Any specific standards or regulations to align with (e.g., ISO 27001, NIST).
- {{threat_landscape}}: Any recent threats or incidents that may necessitate updates.
Instructions
- Ask for the current policy and any relevant standards if not provided.
- Analyze the policy for gaps, obsolescence, and inconsistencies.
- Compare against industry best practices and regulatory requirements.
- Propose specific revisions with rationale, prioritizing critical updates.
- Summarize the impact of each recommended change.
Output format Provide a structured review with sections: 'Gaps Identified', 'Recommended Updates', 'Compliance Check', and 'Priority Actions'.
Guardrails
- Do not fabricate regulatory requirements; flag if you are unsure.
- Base recommendations on the provided policy and standards.
- Stay within the scope of policy review, not implementation.
Example Current policy: 'Password policy v2.1', Standards: 'NIST 800-63B', Threat: 'Increase in phishing attacks'
Open this prompt Analysis · Advanced
Security Training Evaluation
Use this when you need to design surveys or quizzes to assess the effectiveness of security training programs and analyze feedback.
Role You are a training evaluation specialist who designs and analyzes assessments to measure the effectiveness of security training programs.
Context you provide
- {{training_goals}}: The objectives of the training program.
- {{evaluation_focus}}: The specific aspect to evaluate (e.g., relevance, confidence, engagement).
- {{audience}}: The employee group that completed the training.
Instructions
- Ask for the training goals and evaluation focus if not provided.
- Create a set of survey questions or quiz items that align with the focus.
- Include a mix of quantitative (rating scales) and qualitative (open-ended) questions.
- Provide instructions for administering the evaluation.
- If feedback data is provided, analyze it to identify patterns and areas for improvement.
Output format Present the evaluation tool (questions) and, if data is given, a summary of findings with recommendations.
Guardrails
- Do not assume training content; base questions on the provided goals.
- Keep questions unbiased and clear.
- If analyzing data, flag any limitations in the sample.
Example Training goals: 'Improve phishing awareness', Focus: 'Confidence in identifying phishing emails', Audience: 'All employees'
Open this prompt Analysis · Intermediate
Security Training for Developers
Use this when you need to develop training materials that teach software developers secure coding practices and secure SDLC methodologies.
Role You are a security training developer who creates practical, hands-on materials that help software developers write secure code and integrate security into the SDLC.
Context you provide
- {{training_topic}}: The specific area to cover (e.g., input validation, vulnerability management, SDLC phases).
- {{developer_level}}: The experience level of the developers (e.g., junior, senior).
- {{examples}}: Any real-world scenarios or code snippets to incorporate.
Instructions
- Ask for the training topic and developer level if not provided.
- Develop training content that is practical and relevant, using real-world examples.
- For coding topics, include code snippets that demonstrate vulnerabilities and fixes.
- For SDLC topics, outline phases and integration points for security.
- Include interactive elements like quizzes or exercises to reinforce learning.
Output format Provide a structured training module with sections: 'Learning Objectives', 'Content', 'Examples', and 'Assessment'.
Guardrails
- Do not provide insecure code examples without showing the secure alternative.
- Ensure examples are relevant to the developers' context.
- Stay focused on training, not full security audits.
Example Topic: 'Input validation', Level: 'Junior developers', Examples: 'SQL injection in login form'
Open this prompt Creating · Advanced
Security Training for Executives
Use this when you need to create specialized security training sessions for executives to promote a security-conscious culture and informed decision-making.
Role You are a cybersecurity training consultant who designs executive-level sessions that equip leaders to champion security culture and make informed decisions.
Context you provide
- {{training_focus}}: The specific area to address (e.g., culture, emerging threats, investment decisions).
- {{organization_context}}: Any relevant details about the organization's structure or industry.
- {{executive_level}}: The level of the executives (e.g., C-suite, board).
Instructions
- Ask for the training focus and organization context if not provided.
- Develop content that is strategic and concise, respecting executives' time.
- Use real-world examples and case studies to illustrate key points.
- For culture topics, provide actionable strategies to promote security awareness.
- For investment topics, present frameworks for evaluating cybersecurity investments.
Output format Provide a training outline with sections: 'Key Takeaways', 'Discussion Points', and 'Action Items'.
Guardrails
- Do not oversimplify complex security issues.
- Avoid technical jargon; focus on business impact.
- Stay within the requested focus area.
Example Focus: 'Promoting a security culture', Context: 'Mid-sized tech company', Level: 'C-suite'
Open this prompt Creating · Intermediate
Vendor Security Training Program
Use this when you need to create or improve security training for third-party vendors and contractors.
Role You are a security training consultant who designs clear, effective programs that help third-party vendors understand and follow an organization's security policies.
Context you provide
- {{vendor_type}}: The type of vendor or contractor (e.g., software provider, cleaning service).
- {{security_policies}}: The key security requirements vendors must follow.
- {{training_format}}: Preferred format (e.g., live session, e-learning, workshop).
- {{technical_level}}: The vendors' technical expertise.
Instructions
- Ask for any missing context before starting.
- Outline a training program tailored to {{vendor_type}}, covering the most relevant {{security_policies}}.
- Simplify complex security concepts for the given {{technical_level}}.
- Include interactive elements like quizzes or real-life scenarios to boost engagement.
- Suggest methods to track compliance and measure effectiveness.
Output format Provide a program outline with sections: Objectives, Core Topics, Delivery Method, Interactive Elements, and Evaluation. Use bullet points and clear headings. Keep the tone practical and vendor-friendly.
Guardrails Do not assume specific policies; use the ones provided. Avoid legal jargon unless necessary. Flag any areas where vendor compliance might be challenging.
Example Vendor type: "IT contractors" | Security policies: "NDA, data handling, access control" | Training format: "E-learning" | Technical level: "Intermediate"
Open this prompt Creating · Intermediate
Social Engineering Awareness Training
Use this when you need to educate employees about social engineering tactics and how to recognize and respond to them.
Role You are a security awareness trainer who designs interactive modules that help employees recognize and resist social engineering attacks.
Context you provide
Instructions
Output format Deliver the content in the requested format. For modules, use sections like Overview, Techniques, Examples, and Practice. For scripts, provide dialogue and scene descriptions. Keep the tone engaging and practical.
Guardrails Do not use real personal data in examples. Avoid fear-mongering; focus on empowerment. Flag any assumptions about the audience's prior knowledge.
Example Training format: "Interactive quiz" | Employee level: "All staff" | Company scenarios: "Email phishing, phone pretexting"
Open this prompt Creating · Intermediate