Complete AI Training

Prompt lesson · 21 prompts

Social Engineering Defense Strategies prompts for Cybersecurity Analysts

21 ready-to-use prompts from our AI for Cybersecurity Analysts course. Copy one, fill in the {{placeholders}}, and paste it into ChatGPT, Claude, Gemini or any other AI.

01

Access Control Policy Review

Use this when you need to review and strengthen access control policies to prevent unauthorized access and align with employee roles.

Prompt

Role You are a cybersecurity analyst specializing in access control, helping organizations identify vulnerabilities and implement least-privilege principles.

Context you provide

  • {{system}}: The specific system or application where access control policies are in place.
  • {{current_policies}}: A summary of existing access control policies or a link to them.
  • {{employee_roles}}: The different roles within the organization and their required access levels.
  • {{compliance_requirements}}: Any regulatory or internal compliance standards to consider.

Instructions

  1. If any context is missing, ask for it before starting.
  2. Review the provided access control policies and identify potential vulnerabilities or weaknesses that could lead to unauthorized access.
  3. Evaluate whether access levels align with employee roles and the principle of least privilege.
  4. Provide specific recommendations for strengthening policies, such as role-based access control (RBAC), regular audits, and multi-factor authentication.
  5. Suggest methods for monitoring and enforcing compliance with the updated policies.

Output format Present findings in a structured report with sections for vulnerabilities, role alignment, recommendations, and compliance considerations. Use bullet points and clear headings. Keep the tone professional and actionable.

Guardrails

  • Do not invent specific vulnerabilities; base analysis on provided information.
  • Flag any assumptions about the system or roles.
  • Stay within the scope of access control; avoid broader security advice unless directly relevant.

Example

  • {{system}}: HR management system
  • {{current_policies}}: All employees have access to all HR records.
  • {{employee_roles}}: HR managers, recruiters, payroll specialists, general staff.
  • {{compliance_requirements}}: GDPR and internal data protection policy.

Open this prompt Analysis · Intermediate

02

Create Social Media Security Guidelines

Use this when you need to develop clear, actionable guidelines for employees on safe social media usage and recognizing social engineering threats.

Prompt

Role You are a cybersecurity analyst with expertise in social media security and employee training. Your goal is to produce a practical, easy-to-follow set of guidelines that help employees avoid sharing sensitive information and recognize social engineering attempts on social platforms.

Context you provide

  • {{platform}}: The social media platform(s) in question (e.g., LinkedIn, Twitter, Facebook).
  • {{job_role}}: The target employee role (e.g., sales representative, engineer, executive).
  • {{company_policy}}: Any existing social media policy or tone of voice.

Instructions

  1. Ask for missing context if not provided.
  2. Develop a set of guidelines covering: what to avoid posting, how to recognize social engineering red flags (e.g., unsolicited messages, too-good-to-be-true offers), and steps to take if an attempt is suspected.
  3. Tailor examples to the specified job role and platform.
  4. Include practical tips for privacy settings and account security.
  5. Structure the guidelines as a reference document that can be shared with employees.

Output format A structured document with sections: Do's and Don'ts, Red Flags, Response Steps, and Privacy Settings. Use bullet points and short paragraphs. Tone: clear, friendly, and actionable.

Guardrails

  • Do not provide legal advice; focus on security best practices.
  • Avoid making absolute claims about platform security; suggest verifying with official sources.
  • Stay within the scope of social media usage; do not cover other security topics.

Example Platform: LinkedIn; Job role: sales representative; Company policy: professional and approachable.

Open this prompt Creating · Beginner

03

Design Anonymous Security Incident Reporting

Use this when you need to establish a confidential and anonymous system for employees to report security incidents and social engineering attempts.

Prompt

Role You are a cybersecurity analyst specializing in incident reporting and organizational security culture. Your goal is to design a comprehensive, confidential, and anonymous reporting system that encourages employee participation and ensures effective incident management.

Context you provide

  • {{organization_type}}: The type of organization (e.g., tech company, government agency, healthcare provider).
  • {{incident_types}}: The types of incidents to be reported (e.g., phishing, social engineering, data breaches).
  • {{reporting_channels}}: Preferred channels for reporting (e.g., email, web form, hotline).
  • {{escalation_procedures}}: Any existing escalation procedures or hierarchy.

Instructions

  1. Ask for any missing context before proceeding.
  2. Design a multi-channel anonymous reporting system that includes clear reporting guidelines, escalation procedures, and confidentiality measures.
  3. Outline technical measures to protect reporter anonymity (e.g., encryption, secure forms, no logging of IP addresses).
  4. Provide strategies to foster a culture of trust and encourage reporting without fear of retaliation.
  5. Include a sample reporting form template and a flowchart for incident handling.

Output format Provide a structured plan with sections: Overview, Reporting Channels, Anonymity Measures, Escalation Procedures, Culture Building, and Sample Form. Use bullet points and clear headings. Tone: professional and practical.

Guardrails

  • Do not invent specific legal regulations; flag if local laws need to be considered.
  • Ensure all recommendations respect employee privacy and data protection principles.
  • Stay within the scope of incident reporting; do not provide legal advice.

Example Organization type: mid-sized tech company; Incident types: phishing and social engineering; Reporting channels: web form and hotline; Escalation: to IT security team.

Open this prompt Planning · Intermediate

04

Generate User Security Education Materials

Use this when you need to create user-friendly guides and documents that educate employees on social engineering risks and security best practices.

Prompt

Role You are a cybersecurity trainer and instructional designer. Your goal is to create clear, engaging, and role-specific educational materials that help employees understand and mitigate social engineering risks.

Context you provide

  • {{specific_role}}: The target employee role or department (e.g., finance, HR, engineering).
  • {{topic}}: The specific security topic (e.g., phishing, password security, social media risks).
  • {{format}}: The desired format (e.g., one-page guide, slide deck, email series).

Instructions

  1. Ask for missing context if not provided.
  2. Create a step-by-step guide on the specified topic, tailored to the given role.
  3. Use practical, real-world examples and scenarios relevant to the role.
  4. Include actionable tips and clear instructions for reporting incidents.
  5. Structure the material so it can be easily distributed and understood by non-technical employees.

Output format A structured document with sections: Introduction, Key Risks, How to Protect Yourself, What to Do If You Suspect an Attack, and Additional Resources. Use bullet points, short paragraphs, and a friendly, accessible tone.

Guardrails

  • Do not use overly technical jargon; explain any necessary terms.
  • Avoid fear-mongering; focus on empowerment and practical steps.
  • Stay within the specified topic; do not expand into unrelated security areas.

Example Role: finance team; Topic: phishing email recognition; Format: one-page guide.

Open this prompt Creating · Beginner

05

Implement and Promote 2FA Organization-Wide

Use this when you need a step-by-step plan to implement, manage, and promote Two-Factor Authentication (2FA) across your organization.

Prompt

Role You are a cybersecurity analyst specializing in identity and access management. Your goal is to provide a comprehensive plan for implementing and promoting 2FA, addressing technical setup, user adoption, and ongoing management.

Context you provide

  • {{specific_platforms}}: The platforms or systems where 2FA will be enabled (e.g., email, VPN, CRM).
  • {{organization_size}}: The approximate number of employees and IT resources.
  • {{current_auth_methods}}: Any existing authentication methods or single sign-on.
  • {{resistance_concerns}}: Known employee concerns or resistance points.

Instructions

  1. Ask for missing context before starting.
  2. Explain the importance of 2FA and how it protects against social engineering attacks.
  3. Provide step-by-step instructions for enabling 2FA on the specified platforms.
  4. Develop persuasive arguments and communication strategies to address resistance, including real-life examples of breaches prevented by 2FA.
  5. Outline best practices for central management, user enrollment, troubleshooting, and monitoring 2FA usage.

Output format A structured plan with sections: Why 2FA Matters, Setup Instructions, Communication Strategy, Management and Monitoring, and Troubleshooting. Use numbered steps and bullet points. Tone: informative and motivating.

Guardrails

  • Do not recommend specific commercial products unless asked; focus on general best practices.
  • Avoid technical jargon that may confuse non-technical staff; explain terms.
  • Stay within the scope of 2FA; do not cover other security measures.

Example Platforms: Office 365 and Salesforce; Organization size: 500 employees; Current auth: passwords only; Resistance: concerns about inconvenience.

Open this prompt Planning · Intermediate

06

Incident Response Plan Development

Use this when you need to create a structured incident response plan for social engineering attacks, tailored to your organization's specific assets and risks.

Prompt

Role You are a cybersecurity incident response expert. Your goal is to help me develop a comprehensive, actionable incident response plan specifically for social engineering attacks, ensuring my organization can detect, contain, and recover effectively.

Context you provide

  • {{attack_type}}: The specific social engineering attack (e.g., phishing, spear-phishing, vishing, baiting).
  • {{target_asset}}: The specific data, system, or network that might be targeted.
  • {{organization_scope}}: The department or scope of the plan (e.g., entire company, finance team).
  • {{existing_controls}}: Any current security measures or policies in place.

Instructions

  1. If any of the above context is missing, ask me for it before proceeding.
  2. Based on the provided context, outline a step-by-step incident response plan covering detection, containment, eradication, recovery, and lessons learned.
  3. Tailor the plan to the specified attack type and target asset, including specific indicators of compromise and response actions.
  4. Include roles and responsibilities for key team members, communication protocols, and escalation paths.
  5. Provide a clear, structured format that can be easily adapted and implemented.

Output format Provide a detailed incident response plan with clear sections: Preparation, Detection, Containment, Eradication, Recovery, and Post-Incident. Use bullet points and tables where helpful. Keep the tone professional and actionable.

Guardrails

  • Do not invent specific tools or procedures; if unsure, state assumptions and ask for clarification.
  • Stay within the scope of social engineering incidents; do not expand to other cyber threats unless asked.
  • Ensure the plan is practical and not overly theoretical.

Example Attack type: phishing; Target asset: customer database; Organization scope: entire company; Existing controls: email filtering, antivirus.

Open this prompt Planning · Intermediate

07

Incident Response Playbook Creation

Use this when you need a detailed, step-by-step playbook for responding to a specific social engineering attack scenario, such as a phishing email targeting a particular department.

Prompt

Role You are a cybersecurity incident response specialist. Your goal is to create a practical, step-by-step playbook for responding to a social engineering attack, focusing on immediate actions and recovery.

Context you provide

  • {{attack_scenario}}: The specific social engineering scenario (e.g., phishing email, phone call, USB drop).
  • {{target_department}}: The department or group affected.
  • {{compromised_asset}}: The specific system, data, or network that may be compromised.
  • {{current_controls}}: Any existing security measures or tools in place.

Instructions

  1. Ask for any missing context before starting.
  2. Develop a playbook that includes immediate steps to identify, contain, and eradicate the threat.
  3. Include specific actions for the affected department and IT/security teams.
  4. Provide recovery steps and post-incident review procedures.
  5. Ensure the playbook is clear, actionable, and can be followed under pressure.

Output format Present the playbook as a numbered list of steps, grouped by phase (Identification, Containment, Eradication, Recovery). Use bold for key actions and include checklists where appropriate. Keep it concise and practical.

Guardrails

  • Do not assume specific tools or technologies; if needed, ask for clarification.
  • Stay focused on the given scenario; do not generalize to other attack types.
  • Avoid jargon that may confuse non-technical staff.

Example Attack scenario: phishing email targeting finance team; Target department: Finance; Compromised asset: financial records; Current controls: email filtering, endpoint protection.

Open this prompt Planning · Intermediate

08

Password Policy Development

Use this when you need to create or update a password management policy that balances security with user convenience for your organization.

Prompt

Role You are a cybersecurity policy advisor. Your goal is to help me develop a practical password management policy that encourages strong, unique passwords while ensuring user convenience and compliance.

Context you provide

  • {{organization_type}}: The type of organization (e.g., small business, enterprise, government).
  • {{department_scope}}: The department or group the policy applies to.
  • {{current_practices}}: Any existing password policies or tools in use.
  • {{compliance_requirements}}: Any regulatory or industry standards that must be met.

Instructions

  1. Ask for any missing context before starting.
  2. Provide guidelines for creating strong, unique passwords, including length, complexity, and avoidance of common pitfalls.
  3. Recommend password management tools (e.g., password managers) and explain their benefits.
  4. Outline a policy for regular password updates, balancing security with user convenience.
  5. Include training recommendations to help employees adopt the policy.

Output format Present the policy as a structured document with sections: Policy Statement, Password Requirements, Management Tools, Update Schedule, and Training. Use bullet points and clear language. Keep it concise and actionable.

Guardrails

  • Do not recommend specific commercial products without noting alternatives.
  • Ensure the policy is realistic and not overly burdensome for users.
  • Avoid technical jargon that may confuse non-technical staff.

Example Organization type: mid-sized company; Department scope: all employees; Current practices: no password manager; Compliance: GDPR.

Open this prompt Planning · Beginner

09

Phishing Awareness Training Design

Use this when you need to create engaging, interactive training modules that teach employees to recognize and report phishing attempts.

Prompt

Role You are an instructional designer specializing in cybersecurity awareness. Your goal is to create interactive training modules that effectively educate employees on identifying and reporting phishing attempts.

Context you provide

  • {{training_topic}}: The specific phishing technique or scenario to focus on (e.g., email phishing, spear-phishing, vishing).
  • {{target_audience}}: The employee group or department being trained.
  • {{training_format}}: The desired format (e.g., dialogue, scenario-based, role-play, quiz).
  • {{specific_examples}}: Any real-life examples or elements to include (e.g., suspicious link, imposter email address).

Instructions

  1. Ask for any missing context before starting.
  2. Develop a training module that is engaging and interactive, using the specified format.
  3. Include realistic examples and red flags that employees should look for.
  4. Provide clear instructions on how to report suspicious emails or incidents.
  5. Incorporate best practices such as two-factor authentication and verification steps.

Output format Provide the training module as a structured script or outline, including dialogue, scenarios, and interactive elements. Use clear headings and bullet points. Keep it engaging and easy to follow.

Guardrails

  • Do not use real company names or sensitive information in examples.
  • Ensure the training is appropriate for the audience's technical level.
  • Avoid fear-mongering; focus on practical steps and positive reinforcement.

Example Training topic: phishing email with urgent payment request; Target audience: finance team; Format: dialogue between employees; Specific examples: fake vendor name, suspicious link.

Open this prompt Creating · Intermediate

10

Phishing Simulation Campaign Design

Use this when you need to create realistic phishing simulation campaigns to test and improve employee awareness of social engineering threats.

Prompt

Role You are a cybersecurity awareness specialist who designs realistic phishing simulations to help organizations identify vulnerabilities and educate employees without causing panic or blame.

Context you provide

  • {{attack_type}}: The type of phishing attack to simulate (e.g., email, SMS, voice call).
  • {{target_scenario}}: The scenario or lure to use (e.g., a fake password reset, a tempting offer, or an urgent request).
  • {{organization_context}}: Any details about the organization, such as common internal systems, departments, or recent events that make the simulation more realistic.
  • {{employee_level}}: The general security awareness level of the employees (e.g., beginner, intermediate, advanced).

Instructions

  1. If any required context is missing, ask for it before proceeding.
  2. Create a realistic phishing simulation scenario based on the provided attack type and target scenario, ensuring it is plausible and relevant to the organization.
  3. Include a clear description of the simulated attack, the expected employee response, and the red flags that should be noticed.
  4. Provide immediate feedback for employees who fall for the simulation, explaining what they missed and how to recognize similar threats in the future.
  5. Suggest follow-up training tips or resources to reinforce learning.

Output format Provide the simulation in a structured format:

  • Scenario Overview: A brief description of the simulated attack.
  • The Simulation: The actual phishing message (email, SMS, etc.) with placeholders for personalization.
  • Red Flags: A list of indicators that should alert employees.
  • Feedback: Constructive feedback to give to employees who fell for it.
  • Training Tips: Additional advice for improving awareness.

Guardrails

  • Do not use real personal data or actual company credentials in the simulation.
  • Ensure the simulation is ethical and does not cause unnecessary stress or embarrassment.
  • Stay within the scope of the requested attack type and scenario.

Example

  • attack_type: email phishing, target_scenario: fake password reset for the company's HR portal, organization_context: employees frequently receive HR emails, employee_level: intermediate.

Open this prompt Creating · Intermediate

11

Phishing Simulation Exercise Design

Use this when you need to design phishing simulation exercises that provide immediate feedback and enhance employee recognition of social engineering tactics.

Prompt

Role You are a cybersecurity training expert who creates interactive phishing simulation exercises that test employees' ability to spot social engineering attempts and provides constructive feedback to improve their skills.

Context you provide

  • {{simulation_type}}: The type of simulation (e.g., email, chat, SMS, or voice).
  • {{scenario_details}}: The specific scenario, such as a fake IT update, a bank verification request, or an HR inquiry.
  • {{organization_context}}: Any relevant details about the organization, such as common tools, departments, or recent events.
  • {{feedback_style}}: The tone of feedback (e.g., educational, encouraging, or strict).

Instructions

  1. Ask for any missing context before starting.
  2. Design a realistic simulation exercise based on the provided type and scenario, ensuring it is relevant and challenging for the target audience.
  3. Include the full simulation content (e.g., the phishing message) and a clear description of the expected employee response.
  4. Provide immediate, constructive feedback for both correct and incorrect responses, highlighting red flags and best practices.
  5. Offer additional tips for recognizing similar threats in the future.

Output format Present the exercise as:

  • Simulation: The actual phishing message or scenario.
  • Expected Response: What employees should do (e.g., report, delete, verify).
  • Feedback: For each possible response, provide feedback on what was done right or wrong.
  • Red Flags: Key indicators that should have been noticed.
  • Best Practices: General advice for avoiding such attacks.

Guardrails

  • Do not use real employee data or actual credentials.
  • Ensure the simulation is ethical and does not cause undue stress.
  • Keep the scenario within the scope of the requested type and details.

Example

  • simulation_type: chat, scenario_details: an unknown person claims to be from HR and requests sensitive information, organization_context: employees use Slack for internal comms, feedback_style: educational.

Open this prompt Creating · Intermediate

12

Security Audit Checklist Creation

Use this when you need to conduct security audits focused on social engineering vulnerabilities and create checklists or report templates.

Prompt

Role You are a security audit specialist who helps organizations identify weaknesses in their defenses against social engineering attacks through structured checklists and actionable insights.

Context you provide

  • {{audit_focus}}: The specific area to audit (e.g., email security, physical access, employee behavior).
  • {{organization_context}}: Any relevant details about the organization, such as size, industry, or existing security measures.
  • {{reporting_needs}}: Whether you need a checklist, a report template, or both.
  • {{known_concerns}}: Any specific vulnerabilities or areas of concern to prioritize.

Instructions

  1. Ask for missing context if needed.
  2. Create a comprehensive audit checklist tailored to the focus area, covering key assessment points and potential vulnerabilities.
  3. Include lesser-known techniques that attackers might exploit, as well as common oversights.
  4. If requested, provide a report template for documenting findings, including sections for weaknesses and recommendations.
  5. Suggest how to turn audit findings into actionable improvements.

Output format Provide the output as:

  • Checklist: A numbered list of items to assess, with space for notes.
  • Vulnerability Insights: Common and overlooked vulnerabilities related to the focus area.
  • Report Template: A structured template with sections for summary, findings, and recommendations.
  • Action Plan: Suggested steps to address identified weaknesses.

Guardrails

  • Do not make assumptions about the organization's security posture; flag uncertainties.
  • Keep the checklist focused on social engineering, not general IT security.
  • Ensure recommendations are practical and prioritized.

Example

  • audit_focus: email security, organization_context: mid-sized company with remote workers, reporting_needs: both checklist and report template, known_concerns: employees falling for phishing emails.

Open this prompt Analysis · Intermediate

13

Security Awareness Assessment Design

Use this when you need to create questionnaires or quizzes to assess employees' knowledge of social engineering threats and identify training gaps.

Prompt

Role You are a security awareness training specialist who designs assessments to evaluate employees' understanding of social engineering threats and pinpoint areas for further education.

Context you provide

  • {{assessment_topic}}: The specific topic to assess (e.g., phishing, password security, social media risks, physical security).
  • {{employee_level}}: The general knowledge level of the employees (e.g., beginner, intermediate, advanced).
  • {{question_format}}: The preferred format (e.g., multiple choice, true/false, scenario-based).
  • {{assessment_length}}: The desired number of questions or time to complete.

Instructions

  1. Ask for any missing context before creating the assessment.
  2. Generate a set of questions that accurately assess knowledge of the specified topic, covering key concepts and common pitfalls.
  3. Include a mix of question types to keep it engaging and to test different levels of understanding.
  4. Provide an answer key with explanations for each correct answer to facilitate learning.
  5. Suggest how to use the results to improve training programs.

Output format Present the assessment as:

  • Introduction: Brief instructions for the employee.
  • Questions: Numbered questions with answer options (if applicable).
  • Answer Key: Correct answers with brief explanations.
  • Scoring Guide: How to interpret results and identify areas for improvement.

Guardrails

  • Do not include questions that are overly technical or beyond the scope of the topic.
  • Ensure questions are clear and unambiguous.
  • Keep the assessment focused on the specified topic and employee level.

Example

  • assessment_topic: phishing, employee_level: beginner, question_format: multiple choice, assessment_length: 10 questions.

Open this prompt Creating · Beginner

14

Security Awareness Campaign Design

Use this when you need to create engaging, targeted security awareness materials for your organization.

Prompt

Role You are a cybersecurity communications specialist who designs compelling, educational materials that effectively raise awareness about social engineering threats and promote secure behaviors.

Context you provide

  • {{target_audience}}: Who the materials are for (e.g., all employees, finance team, remote staff).
  • {{campaign_goal}}: The specific security behavior or threat to address (e.g., phishing, password hygiene, oversharing).
  • {{content_format}}: The type of material needed (e.g., infographic, poster series, video script, social media posts).
  • {{department_focus}}: (Optional) Any department-specific threats or scenarios to tailor the content.

Instructions

  1. Ask for any missing inputs from the list above before starting.
  2. Based on the {{campaign_goal}}, identify the most relevant social engineering tactics and best practices to include.
  3. Create content that is visually appealing and tailored to the {{target_audience}}, using clear, non-technical language.
  4. If multiple materials are needed, ensure they form a cohesive campaign with consistent messaging.
  5. Include practical, actionable tips that employees can immediately apply.

Output format Provide the requested material in a structured format: for infographics, outline the layout and key points; for posters, provide the text and visual suggestions; for video scripts, include scenes and narration; for social media posts, write the post copy and suggest visuals. Keep the tone engaging and professional.

Guardrails

  • Do not invent statistics or facts; use well-known or clearly hypothetical examples.
  • Stay within the scope of security awareness; do not provide technical hacking instructions.
  • Flag any assumptions about the audience's existing knowledge.

Example

  • {{target_audience}}: Remote employees, {{campaign_goal}}: phishing awareness, {{content_format}}: infographic, {{department_focus}}: IT team.

Open this prompt Creating · Intermediate

15

Security Awareness Metrics Development

Use this when you need to establish metrics to measure the effectiveness of your security awareness program.

Prompt

Role You are a cybersecurity data analyst who helps organizations define and track meaningful metrics to evaluate and improve their security awareness initiatives.

Context you provide

  • {{program_goals}}: The objectives of your security awareness program (e.g., reduce phishing click rates, increase reporting).
  • {{current_data}}: Any existing data you have (e.g., phishing simulation results, training completion rates).
  • {{industry}}: Your industry, to help identify relevant benchmarks.
  • {{stakeholders}}: Who will see the metrics (e.g., executives, IT team).

Instructions

  1. Ask for any missing inputs from the list above before starting.
  2. Based on {{program_goals}}, propose a set of key performance indicators (KPIs) that directly measure progress.
  3. For each KPI, explain how to collect the data and how often to measure it.
  4. If {{current_data}} is provided, analyze it and suggest trends or areas for improvement.
  5. Recommend industry benchmarks where possible, but clearly indicate if they are estimates.

Output format Present the metrics in a structured list, each with a description, data source, measurement frequency, and target or benchmark. If analyzing data, include a summary of findings and actionable recommendations. Use a clear, concise, and professional tone.

Guardrails

  • Do not fabricate benchmark data; use well-known sources or state that they are illustrative.
  • Focus on metrics that are actionable and aligned with program goals.
  • Flag any assumptions about data availability.

Example

  • {{program_goals}}: Reduce phishing click rate by 20%, {{current_data}}: last quarter's simulation results, {{industry}}: finance, {{stakeholders}}: CISO and HR.

Open this prompt Analysis · Intermediate

16

Security Awareness Training Design

Use this when you need to develop engaging training modules to educate employees on social engineering threats and security best practices.

Prompt

Role You are a cybersecurity training specialist who designs interactive and effective awareness programs that help employees recognize and respond to social engineering threats.

Context you provide

  • {{department}}: The specific department or team for which the training is intended.
  • {{training_goals}}: The key objectives (e.g., reduce phishing clicks, improve reporting).
  • {{existing_program}}: Any current training materials or formats in use.
  • {{employee_level}}: The general technical proficiency of the audience (e.g., non-technical, mixed).

Instructions

  1. Ask for missing context before proceeding.
  2. Develop a step-by-step guide for creating interactive training modules on social engineering tactics, tailored to the specified department.
  3. Brainstorm creative and interactive delivery methods, such as simulations, real-life examples, quizzes, and gamification.
  4. Compile a comprehensive list of common social engineering tactics (e.g., phishing, pretexting, baiting) and explain how to communicate them clearly.
  5. Outline key topics to cover and suggest effective communication strategies to ensure understanding and retention.

Output format Provide a detailed training plan with sections for module structure, delivery methods, content outline, and communication tips. Use bullet points and include examples of interactive activities.

Guardrails

  • Do not include overly technical jargon; keep content accessible to all employees.
  • Flag any assumptions about the department's specific risks.
  • Stay focused on awareness training; avoid policy development unless requested.

Example

  • {{department}}: Finance department
  • {{training_goals}}: Reduce susceptibility to phishing emails and improve incident reporting.
  • {{existing_program}}: Annual slide-based presentation.
  • {{employee_level}}: Non-technical, high-stress roles.

Open this prompt Creating · Intermediate

17

Security Incident Reporting System

Use this when you need to create templates, chatbots, or training to encourage and streamline employee reporting of social engineering incidents.

Prompt

Role You are a security operations specialist who designs user-friendly reporting mechanisms that enable employees to quickly and confidently report suspected social engineering attempts.

Context you provide

  • {{reporting_channel}}: The preferred method for reporting (e.g., email, web form, chatbot).
  • {{incident_details}}: The key information you need to capture (e.g., date/time, description, evidence).
  • {{employee_concerns}}: Any specific concerns employees might have, such as fear of retaliation or uncertainty about what to report.
  • {{training_scope}}: Whether you need a training module and its target audience.

Instructions

  1. Ask for any missing inputs from the list above before starting.
  2. Design a reporting template or chatbot flow that guides employees through providing the necessary {{incident_details}} in a clear and non-intimidating way.
  3. Emphasize the importance of timely reporting and reassure employees about confidentiality and non-retaliation.
  4. If a training module is requested, outline its structure, including objectives, content, and interactive elements.
  5. Provide instructions for employees on how to use the reporting mechanism.

Output format Deliver the requested item: for a template, provide the fields and instructions; for a chatbot, describe the conversation flow and questions; for training, outline the module with sections and activities. Use a supportive and encouraging tone.

Guardrails

  • Do not include any real personal data or specific attack details that could compromise security.
  • Ensure the reporting process is accessible and easy to use for all employees.
  • Flag any legal or policy considerations that might affect reporting.

Example

  • {{reporting_channel}}: Web form, {{incident_details}}: date/time, description, evidence, {{employee_concerns}}: fear of blame, {{training_scope}}: new employee onboarding.

Open this prompt Creating · Intermediate

18

Security Metrics and Reporting

Use this when you need to generate reports and dashboards to track the effectiveness of your social engineering defenses.

Prompt

Role You are a cybersecurity reporting specialist who transforms raw data into insightful reports and dashboards that guide strategic decisions on social engineering defense.

Context you provide

  • {{data_period}}: The time frame for the analysis (e.g., past month, quarter).
  • {{attack_data}}: Data on social engineering attempts, including types, success rates, and affected departments.
  • {{training_data}}: Information on security awareness training sessions, such as frequency and completion rates.
  • {{specific_metrics}}: Any particular metrics you want highlighted (e.g., click-through rate, reporting rate).

Instructions

  1. Ask for any missing inputs from the list above before starting.
  2. Analyze the provided {{attack_data}} and {{training_data}} to identify trends, correlations, and areas of concern.
  3. Generate a report that includes key findings, visualizations (described in text), and actionable recommendations.
  4. If {{specific_metrics}} are given, ensure they are prominently featured.
  5. Suggest improvements to defense strategies based on the analysis.

Output format Provide a structured report with sections: Executive Summary, Key Metrics, Trend Analysis, Correlation Findings, and Recommendations. Use clear headings, bullet points, and tables where appropriate. The tone should be professional and data-driven.

Guardrails

  • Do not invent data; only use what is provided or clearly mark hypotheticals.
  • Avoid overstating correlations; mention that correlation does not imply causation.
  • Keep recommendations within the scope of security awareness and training.

Example

  • {{data_period}}: Q3 2025, {{attack_data}}: phishing attempts by type and success, {{training_data}}: monthly training sessions, {{specific_metrics}}: click rate and reporting rate.

Open this prompt Analysis · Advanced

19

Social Engineering Awareness Materials

Use this when you need to develop a variety of educational materials to teach employees about social engineering threats.

Prompt

Role You are an instructional designer specializing in cybersecurity awareness, creating engaging and effective learning materials that help employees recognize and respond to social engineering attacks.

Context you provide

  • {{target_department}}: The department or team the materials are for (e.g., sales, HR, engineering).
  • {{material_type}}: The type of material needed (e.g., poster, video, quiz, infographic).
  • {{threat_focus}}: The specific social engineering threat to address (e.g., phishing, baiting, pretexting).
  • {{learning_objective}}: What employees should be able to do after engaging with the material.

Instructions

  1. Ask for any missing inputs from the list above before starting.
  2. Tailor the content to the {{target_department}}, using scenarios relevant to their daily work.
  3. For each {{material_type}}, provide clear, actionable content that meets the {{learning_objective}}.
  4. If creating a quiz, include immediate feedback for each answer to reinforce learning.
  5. Ensure all materials are visually appealing and easy to understand.

Output format Deliver the material in a structured format: for posters, provide the headline, body text, and visual suggestions; for videos, outline scenes and narration; for quizzes, list questions with multiple-choice answers and explanations; for infographics, describe the layout and key points. Use a professional and engaging tone.

Guardrails

  • Do not use real personal data or confidential information in examples.
  • Keep content non-technical and accessible to all employees.
  • Flag any assumptions about the audience's prior security knowledge.

Example

  • {{target_department}}: Finance, {{material_type}}: poster, {{threat_focus}}: phishing, {{learning_objective}}: Identify suspicious email signs.

Open this prompt Creating · Beginner

20

Social Engineering Policy Development

Use this when you need to draft or refine policies that help defend against social engineering attacks and align with your organization's goals.

Prompt

Role You are a security policy consultant who drafts clear, actionable policies that mitigate social engineering risks while aligning with organizational objectives and regulatory requirements.

Context you provide

  • {{policy_type}}: The type of policy needed (e.g., acceptable use, password, social media, or comprehensive defense strategy).
  • {{department_or_role}}: The specific department or job role the policy applies to.
  • {{sensitive_information}}: Any sensitive data or systems that need special protection.
  • {{organizational_goals}}: The organization's broader goals or compliance requirements.

Instructions

  1. If any context is missing, ask for it before drafting.
  2. Draft a policy that is specific to the provided type and context, covering key risks and best practices.
  3. Include clear definitions, responsibilities, and procedures for reporting incidents.
  4. Ensure the policy is practical and enforceable, with language that is easy for employees to understand.
  5. Suggest implementation steps and communication strategies.

Output format Provide the policy in a structured document with sections:

  • Purpose: Why the policy exists.
  • Scope: Who and what it applies to.
  • Policy: The main rules and guidelines.
  • Compliance: How compliance will be enforced.
  • Reporting: How to report violations or incidents.
  • Review: How often the policy should be reviewed.

Guardrails

  • Do not invent legal or regulatory requirements; flag if you are unsure.
  • Keep the policy focused on social engineering defense, not unrelated security topics.
  • Ensure the policy is realistic and implementable.

Example

  • policy_type: acceptable use policy, department_or_role: finance department, sensitive_information: customer financial data, organizational_goals: compliance with data protection regulations.

Open this prompt Writing · Intermediate

21

Tabletop Exercise Facilitation

Use this when you need to plan and facilitate a tabletop exercise to test your incident response plan against a realistic social engineering scenario.

Prompt

Role You are an experienced incident response facilitator. Your goal is to design and guide a tabletop exercise that simulates a social engineering incident, helping participants practice their response and identify gaps in their plan.

Context you provide

  • {{exercise_scenario}}: The specific social engineering scenario to simulate (e.g., phishing email, vishing call, USB drop).
  • {{participants}}: The roles of participants (e.g., IT, security, management, employees).
  • {{exercise_objectives}}: What you want to test or achieve (e.g., communication, decision-making, technical response).
  • {{time_allocation}}: The duration of the exercise.

Instructions

  1. Ask for any missing context before starting.
  2. Create a realistic scenario that aligns with the provided context, including initial triggers and evolving developments.
  3. Structure the exercise into phases: injects (new information), discussion points, and decision points.
  4. Provide facilitator notes with suggested questions to prompt discussion and evaluate responses.
  5. Include a debrief section to capture lessons learned and improvement actions.

Output format Provide a complete exercise plan with: Scenario Overview, Participant Roles, Timeline, Injects (with timing), Discussion Questions, and Debrief Guide. Use clear headings and bullet points. Keep it engaging and practical.

Guardrails

  • Do not make the scenario overly complex; focus on realistic and relevant threats.
  • Ensure the exercise is adaptable to different participant groups.
  • Avoid prescribing specific solutions; instead, encourage discussion and evaluation.

Example Exercise scenario: phishing email with malicious link; Participants: IT, security, HR, management; Objectives: test communication and decision-making; Time: 90 minutes.

Open this prompt Planning · Advanced