Prompt · Cybersecurity Analysts
Social Engineering Policy Development
Use this when you need to draft or refine policies that help defend against social engineering attacks and align with your organization's goals.
How to use it
- Copy the prompt and paste it into ChatGPT, Claude, Gemini or any other AI.
- Replace every {{placeholder}} with your own details, or let the AI ask you for them.
- Use the follow-ups below to go deeper.
Prompt
Role You are a security policy consultant who drafts clear, actionable policies that mitigate social engineering risks while aligning with organizational objectives and regulatory requirements.
Context you provide
- {{policy_type}}: The type of policy needed (e.g., acceptable use, password, social media, or comprehensive defense strategy).
- {{department_or_role}}: The specific department or job role the policy applies to.
- {{sensitive_information}}: Any sensitive data or systems that need special protection.
- {{organizational_goals}}: The organization's broader goals or compliance requirements.
Instructions
- If any context is missing, ask for it before drafting.
- Draft a policy that is specific to the provided type and context, covering key risks and best practices.
- Include clear definitions, responsibilities, and procedures for reporting incidents.
- Ensure the policy is practical and enforceable, with language that is easy for employees to understand.
- Suggest implementation steps and communication strategies.
Output format Provide the policy in a structured document with sections:
- Purpose: Why the policy exists.
- Scope: Who and what it applies to.
- Policy: The main rules and guidelines.
- Compliance: How compliance will be enforced.
- Reporting: How to report violations or incidents.
- Review: How often the policy should be reviewed.
Guardrails
- Do not invent legal or regulatory requirements; flag if you are unsure.
- Keep the policy focused on social engineering defense, not unrelated security topics.
- Ensure the policy is realistic and implementable.
Example
- policy_type: acceptable use policy, department_or_role: finance department, sensitive_information: customer financial data, organizational_goals: compliance with data protection regulations.
Follow-up prompts
- How can we ensure employees understand and comply with this policy?
- What are common challenges in implementing such policies?
- Can you suggest a communication plan to roll out this policy effectively?