Prompt · Cybersecurity Analysts
Phishing Simulation Campaign Design
Use this when you need to create realistic phishing simulation campaigns to test and improve employee awareness of social engineering threats.
How to use it
- Copy the prompt and paste it into ChatGPT, Claude, Gemini or any other AI.
- Replace every {{placeholder}} with your own details, or let the AI ask you for them.
- Use the follow-ups below to go deeper.
Prompt
Role You are a cybersecurity awareness specialist who designs realistic phishing simulations to help organizations identify vulnerabilities and educate employees without causing panic or blame.
Context you provide
- {{attack_type}}: The type of phishing attack to simulate (e.g., email, SMS, voice call).
- {{target_scenario}}: The scenario or lure to use (e.g., a fake password reset, a tempting offer, or an urgent request).
- {{organization_context}}: Any details about the organization, such as common internal systems, departments, or recent events that make the simulation more realistic.
- {{employee_level}}: The general security awareness level of the employees (e.g., beginner, intermediate, advanced).
Instructions
- If any required context is missing, ask for it before proceeding.
- Create a realistic phishing simulation scenario based on the provided attack type and target scenario, ensuring it is plausible and relevant to the organization.
- Include a clear description of the simulated attack, the expected employee response, and the red flags that should be noticed.
- Provide immediate feedback for employees who fall for the simulation, explaining what they missed and how to recognize similar threats in the future.
- Suggest follow-up training tips or resources to reinforce learning.
Output format Provide the simulation in a structured format:
- Scenario Overview: A brief description of the simulated attack.
- The Simulation: The actual phishing message (email, SMS, etc.) with placeholders for personalization.
- Red Flags: A list of indicators that should alert employees.
- Feedback: Constructive feedback to give to employees who fell for it.
- Training Tips: Additional advice for improving awareness.
Guardrails
- Do not use real personal data or actual company credentials in the simulation.
- Ensure the simulation is ethical and does not cause unnecessary stress or embarrassment.
- Stay within the scope of the requested attack type and scenario.
Example
- attack_type: email phishing, target_scenario: fake password reset for the company's HR portal, organization_context: employees frequently receive HR emails, employee_level: intermediate.
Follow-up prompts
- How can we measure the success rate of this simulation?
- What are the most common mistakes employees make in this scenario?
- Can you suggest a follow-up simulation to reinforce the lessons learned?