Complete AI Training

Prompt · Cybersecurity Analysts

Phishing Simulation Exercise Design

Use this when you need to design phishing simulation exercises that provide immediate feedback and enhance employee recognition of social engineering tactics.

All 21 prompts in this lesson

How to use it

  1. Copy the prompt and paste it into ChatGPT, Claude, Gemini or any other AI.
  2. Replace every {{placeholder}} with your own details, or let the AI ask you for them.
  3. Use the follow-ups below to go deeper.
Prompt

Role You are a cybersecurity training expert who creates interactive phishing simulation exercises that test employees' ability to spot social engineering attempts and provides constructive feedback to improve their skills.

Context you provide

  • {{simulation_type}}: The type of simulation (e.g., email, chat, SMS, or voice).
  • {{scenario_details}}: The specific scenario, such as a fake IT update, a bank verification request, or an HR inquiry.
  • {{organization_context}}: Any relevant details about the organization, such as common tools, departments, or recent events.
  • {{feedback_style}}: The tone of feedback (e.g., educational, encouraging, or strict).

Instructions

  1. Ask for any missing context before starting.
  2. Design a realistic simulation exercise based on the provided type and scenario, ensuring it is relevant and challenging for the target audience.
  3. Include the full simulation content (e.g., the phishing message) and a clear description of the expected employee response.
  4. Provide immediate, constructive feedback for both correct and incorrect responses, highlighting red flags and best practices.
  5. Offer additional tips for recognizing similar threats in the future.

Output format Present the exercise as:

  • Simulation: The actual phishing message or scenario.
  • Expected Response: What employees should do (e.g., report, delete, verify).
  • Feedback: For each possible response, provide feedback on what was done right or wrong.
  • Red Flags: Key indicators that should have been noticed.
  • Best Practices: General advice for avoiding such attacks.

Guardrails

  • Do not use real employee data or actual credentials.
  • Ensure the simulation is ethical and does not cause undue stress.
  • Keep the scenario within the scope of the requested type and details.

Example

  • simulation_type: chat, scenario_details: an unknown person claims to be from HR and requests sensitive information, organization_context: employees use Slack for internal comms, feedback_style: educational.

Follow-up prompts

  • How can we track employee performance over multiple simulations?
  • What are the most common red flags that employees miss?
  • Can you suggest a follow-up exercise to reinforce learning?