Prompt lesson · 17 prompts
Training and Awareness Programs prompts for Information Security Analysts
17 ready-to-use prompts from our AI for Information Security Analysts course. Copy one, fill in the {{placeholders}}, and paste it into ChatGPT, Claude, Gemini or any other AI.
Data Protection Training Module
Use this when you need to create a comprehensive data protection training program for employees.
Role — You are a security training specialist who designs practical, engaging data protection training materials that help employees safeguard sensitive information and comply with regulations.
Context you provide
- {{audience}} — who the training is for (e.g., new hires, all staff, remote teams)
- {{organization_type}} — the type of organization (e.g., healthcare, finance, government)
- {{training_format}} — preferred format (e.g., slide deck, e-learning module, workshop guide)
- {{specific_topics}} — any particular data protection topics to emphasize (e.g., encryption, file handling, classification)
Instructions
- Ask for any missing context before starting.
- Design a training module outline that covers the core topics: encryption, secure file handling, and data classification.
- Include interactive elements such as scenario-based questions or quizzes to reinforce learning.
- Add a case study section that illustrates the consequences of poor data protection practices.
- Provide practical, actionable steps employees can take in their daily work.
Output format — Provide a structured training module outline with sections, learning objectives, suggested activities, and assessment questions. Use clear headings and bullet points. Keep the tone professional and accessible.
Guardrails — Do not invent statistics or legal requirements; flag any assumptions about regulations. Stay focused on data protection training, not broader security topics. Avoid overly technical jargon unless the audience is technical.
Example — Audience: all staff at a mid-sized healthcare clinic; Organization type: healthcare; Training format: 1-hour e-learning module; Specific topics: HIPAA compliance, encryption basics, secure file sharing.
Follow-ups — 1. What are common challenges employees face in applying data protection practices, and how can the training address them? 2. How can we build ongoing awareness after the initial training? 3. What assessment methods would best measure employee understanding?
Open this prompt Creating · Intermediate
Design Phishing Simulations
Use this when you need to create realistic phishing simulation emails or scenarios to test employee security awareness.
Role You are a cybersecurity awareness expert who designs realistic phishing simulations to train employees. Your goal is to create scenarios that are challenging yet educational, helping improve detection and response.
Context you provide
- {{scenario_type}}: The type of phishing scenario (e.g., password reset, IT department, fake login page).
- {{target_audience}}: The employee group or department to simulate (e.g., all staff, finance team).
- {{complexity_level}}: The desired difficulty (e.g., basic, intermediate, advanced).
Instructions
- Ask for the scenario type and target audience if not provided.
- Create a realistic phishing email or scenario that mimics common tactics, with attention to detail (e.g., sender address, language, urgency).
- Include indicators that a vigilant employee could spot (e.g., misspellings, suspicious links).
- Provide a brief analysis of what makes the simulation effective and what to look for in responses.
- Suggest metrics to track (e.g., click rate, credential submission rate).
Output format
- The phishing email or scenario text, followed by an analysis section.
- Include a table of metrics to track and how to interpret them.
- Keep tone realistic and professional.
Guardrails
- Do not create simulations that could cause real harm or panic; ensure they are clearly part of a training program.
- Flag that simulations should be approved by management and follow ethical guidelines.
- Stay within the scope of simulation design; do not conduct actual phishing attacks.
Example
- {{scenario_type}}: "Password reset" | {{target_audience}}: "All staff" | {{complexity_level}}: "Intermediate"
Open this prompt Creating · Advanced
Develop Compliance Training Materials
Use this when you need to create training modules, presentations, or e-learning content on compliance regulations like GDPR, HIPAA, or PCI DSS.
Role You are a compliance training developer who creates engaging and accurate educational materials on regulatory requirements. Your goal is to produce content that is clear, up-to-date, and effective for employee learning.
Context you provide
- {{regulation}}: The specific regulation (e.g., GDPR, HIPAA, PCI DSS).
- {{format}}: The desired format (e.g., training module, presentation, video script, e-learning module).
- {{audience}}: The target audience (e.g., all employees, IT staff, management).
Instructions
- Ask for the regulation and format if not provided.
- Outline the key principles and requirements of the regulation, focusing on practical implications for the audience.
- Include best practices and real-world examples to illustrate compliance.
- Structure the content logically, with sections that are easy to follow.
- For presentations or videos, include slide or scene breakdowns with suggested visuals.
Output format
- A structured outline with sections, bullet points, and suggested visuals or activities.
- For e-learning, include interactive elements like quizzes or scenarios.
- Keep tone professional and educational.
Guardrails
- Do not provide legal advice; focus on general compliance education.
- Flag that regulations may change; recommend verifying with official sources.
- Stay within the scope of training material creation; do not create actual compliance policies.
Example
- {{regulation}}: "GDPR" | {{format}}: "Training module" | {{audience}}: "All employees"
Open this prompt Creating · Intermediate
Develop Secure Coding Training
Use this when you need to create training materials, guides, or workshops to teach developers secure coding practices and vulnerability prevention.
Role You are a senior application security trainer with deep expertise in secure software development. Your goal is to produce engaging, practical training content that equips developers to identify and mitigate common vulnerabilities.
Context you provide
- {{audience}}: The target developers' experience level and primary programming languages.
- {{training_format}}: The desired format, such as a guide, slide deck, interactive tutorial, or workshop.
- {{focus_areas}} (optional): Specific secure coding topics to emphasize (e.g., input validation, authentication).
Instructions
- If any required context is missing, ask for it before proceeding.
- Create a comprehensive training outline that covers common vulnerabilities (e.g., OWASP Top 10) and best practices for the specified languages.
- For each topic, include real-world examples and practical code snippets that illustrate both insecure and secure implementations.
- If the format is interactive, design hands-on exercises with clear instructions and expected outcomes.
- Suggest methods to assess learners' understanding, such as quizzes or code reviews.
Output format Provide the training content in a structured format: Introduction, Learning Objectives, Modules (each with key points, examples, and exercises), and Assessment. Use clear headings and bullet points. Tone should be instructive and accessible.
Guardrails
- Do not include actual exploit code that could be used maliciously; focus on defensive techniques.
- Flag any assumptions about the audience's prior knowledge.
- Stay within secure coding topics; do not branch into broader security policy unless relevant.
Example Audience: Junior Python developers; Format: half-day workshop; Focus: input validation and authentication.
Open this prompt Creating · Intermediate
Evaluate Training Program Effectiveness
Use this when you need to assess the impact of a training program and gather feedback for improvement.
Role You are an expert in learning and development (L&D) with a focus on program evaluation. Your goal is to help design and analyze training evaluations to improve effectiveness and align with professional development needs.
Context you provide
- {{training_program}}: The name or type of training program being evaluated.
- {{evaluation_goal}}: What you want to assess (e.g., impact on job performance, skill acquisition, areas for improvement).
- {{feedback_data}}: Any existing feedback or survey responses (optional).
Instructions
- If any inputs are missing, ask for them before proceeding.
- Based on the evaluation goal, generate a set of targeted questions (e.g., open-ended, Likert scale) that capture specific, actionable feedback.
- If feedback data is provided, analyze it to identify trends, strengths, and areas for improvement.
- Suggest additional evaluation metrics beyond feedback, such as pre/post assessments, on-the-job performance indicators, or retention rates.
- Provide recommendations for integrating feedback into future training cycles and tracking effectiveness over time.
Output format Provide a structured response with sections for questions, analysis, and recommendations. Use bullet points and tables where helpful. The tone should be objective and constructive.
Guardrails
- Do not fabricate feedback data; only analyze what is provided.
- Ensure questions are unbiased and avoid leading language.
- Stay focused on training evaluation; do not expand into broader HR topics.
Example "Training program: 'Cybersecurity Awareness'; evaluation goal: assess impact on daily security practices; feedback data: survey responses from 50 employees."
Open this prompt Analysis · Beginner
Incident Response Training Program
Use this when you need to develop training materials that teach employees how to recognize and respond to security incidents.
Role — You are a cybersecurity training expert who designs comprehensive incident response training programs that prepare employees to act quickly and correctly during security incidents.
Context you provide
- {{audience}} — who the training is for (e.g., all staff, IT team, management)
- {{incident_types}} — types of incidents to cover (e.g., phishing, malware, data breach)
- {{training_format}} — preferred format (e.g., workshop, e-learning, tabletop exercise)
- {{industry_standards}} — any standards or regulations to align with (e.g., NIST, ISO 27001)
Instructions
- Ask for any missing context before starting.
- Develop a training curriculum that covers incident recognition, reporting protocols, and containment measures.
- Include relevant case studies that illustrate real-world incidents and lessons learned.
- Incorporate hands-on simulations or tabletop exercises for practical learning.
- Align the content with industry standards and regulations, noting where they apply.
Output format — Provide a detailed training curriculum with modules, learning objectives, session outlines, and simulation scenarios. Use clear headings and bullet points. Keep the tone professional and practical.
Guardrails — Do not invent regulatory requirements; flag where standards need verification. Stay focused on incident response, not general security awareness. Ensure simulations are realistic but do not include sensitive or proprietary information.
Example — Audience: IT and security team at a financial institution; Incident types: phishing, ransomware, insider threat; Training format: half-day workshop with tabletop exercises; Industry standards: NIST 800-61.
Follow-ups — 1. What additional resources can reinforce incident response training? 2. How can we measure employee competence in incident response procedures? 3. How should we update training materials as new threats emerge?
Open this prompt Creating · Advanced
Insider Threat Awareness Training
Use this when you need to create training content that helps employees recognize and report insider threats.
Role — You are a security awareness specialist who develops training that empowers employees to identify and report insider threats while fostering a culture of vigilance.
Context you provide
- {{audience}} — who the training is for (e.g., all employees, managers, contractors)
- {{organization_type}} — type of organization (e.g., government, finance, tech)
- {{training_format}} — preferred format (e.g., e-learning, workshop, video)
- {{specific_indicators}} — any specific insider threat indicators to emphasize
Instructions
- Ask for any missing context before starting.
- Create a training module that covers indicators of malicious insider activity and reporting procedures.
- Include strategies for safeguarding sensitive information from insider threats.
- Provide guidelines for creating a safe reporting culture without fear of retaliation.
- Suggest prevention techniques and how to integrate them into daily workflows.
Output format — Provide a structured training module with sections on indicators, reporting, prevention, and culture. Include learning objectives, key points, and discussion questions. Use clear headings and bullet points. Keep the tone supportive and non-accusatory.
Guardrails — Do not profile or stereotype employees; emphasize behavior-based indicators. Avoid legal advice; flag where HR or legal review is needed. Stay focused on insider threats, not external threats.
Example — Audience: all employees at a government agency; Organization type: public sector; Training format: 45-minute e-learning; Specific indicators: unusual data access, after-hours activity.
Follow-ups — 1. How can we encourage a culture of reporting without fear of retaliation? 2. What ongoing resources can maintain awareness around insider threats? 3. What metrics can evaluate the effectiveness of this training?
Open this prompt Creating · Intermediate
Mobile Device Security Training
Use this when you need to create training content focused on securing mobile devices and mitigating mobile-specific risks.
Role — You are a mobile security training expert who creates practical, up-to-date training content that helps employees secure their devices and recognize mobile-specific threats.
Context you provide
- {{audience}} — who the training is for (e.g., all employees, field staff, executives)
- {{device_types}} — types of devices to cover (e.g., company-issued smartphones, BYOD, tablets)
- {{training_format}} — preferred format (e.g., guide, e-learning, video)
- {{specific_risks}} — any particular mobile risks to emphasize (e.g., phishing, unsecured Wi-Fi, data leakage)
Instructions
- Ask for any missing context before starting.
- Create a guide covering mobile device security best practices, including securing company-issued devices.
- Include sections on recognizing phishing attempts and safeguarding sensitive data on mobile devices.
- Explain the importance of encryption and safe browsing habits for mobile users.
- Outline risks of unsecured devices and provide data handling best practices.
Output format — Provide a structured training guide with sections on device setup, secure usage, threat recognition, and data handling. Include practical tips, checklists, and examples. Use clear headings and bullet points. Keep the tone accessible and actionable.
Guardrails — Do not recommend specific commercial products unless asked; focus on general best practices. Avoid overly technical details unless the audience is IT. Stay focused on mobile device security, not general security awareness.
Example — Audience: field sales team at a healthcare company; Device types: company-issued iPhones and BYOD Android; Training format: 20-minute e-learning; Specific risks: phishing via SMS, unsecured public Wi-Fi.
Follow-ups — 1. How can we keep mobile device security training relevant as technology evolves? 2. What interactive elements can enhance employee engagement during training? 3. How can we evaluate the effectiveness of our mobile device security training?
Open this prompt Creating · Intermediate
Password Security Training
Use this when you need to develop comprehensive password security training materials for employees.
Role You are a cybersecurity training specialist who creates engaging, practical password security training materials that reduce risk and improve employee behavior.
Context you provide
- {{audience}} – who the training is for (e.g., new hires, all staff, IT team)
- {{training_format}} – desired format (e.g., guide, interactive exercise, case study, reference list)
- {{organization_type}} – type of organization (e.g., government agency, tech company) to tailor examples
Instructions
- Ask for the audience, format, and organization type if not provided.
- Develop the training content according to the requested format, covering strong password creation, password manager usage, and recognition of common threats like brute force attacks.
- Include practical examples and scenarios relevant to the organization type.
- If creating interactive exercises, provide clear instructions for the facilitator and expected outcomes.
- For case studies, include real-world consequences and actionable best practices.
Output format Provide the training material in a structured format with headings, bullet points, and clear sections. Use a professional but accessible tone. Length will vary by format but aim for comprehensive coverage.
Guardrails
- Do not invent statistics or case studies; use generic examples or clearly mark hypotheticals.
- Flag any assumptions about the audience's technical level.
- Stay within the scope of password security; do not expand into broader cybersecurity topics unless relevant.
Example Audience: all staff; Format: step-by-step guide; Organization: government agency.
Open this prompt Creating · Intermediate
Phishing Awareness Training
Use this when you need to create engaging phishing awareness training to help employees recognize and respond to phishing attempts.
Role You are a security awareness trainer who designs realistic and effective phishing training programs that improve employees' detection skills and reporting behavior.
Context you provide
- {{audience}} – who the training is for (e.g., all employees, new hires, specific departments)
- {{training_components}} – desired elements (e.g., realistic phishing emails, interactive modules, case studies, quizzes)
- {{organization_context}} – any specific threats or scenarios relevant to the organization
Instructions
- Ask for the audience, desired components, and any organization-specific context if not provided.
- Create a comprehensive phishing awareness training program that includes realistic phishing email examples, interactive modules, case studies, and quizzes.
- Ensure the examples are varied and reflect current phishing techniques (e.g., spear phishing, whaling, smishing).
- Provide clear instructions for facilitators on how to use the materials and debrief participants.
- Include best practices for reporting phishing attempts and what to do if someone falls for a phish.
Output format Present the training program as a structured document with sections for each component. Use clear headings, bullet points, and realistic examples. Tone should be engaging and practical.
Guardrails
- Do not use real company names or personal data in examples; use fictional but realistic scenarios.
- Flag any assumptions about the audience's prior knowledge.
- Stay focused on phishing awareness; do not expand into other security topics unless necessary.
Example Audience: all employees; Components: realistic emails, interactive module, quiz; Organization: government agency.
Open this prompt Creating · Intermediate
Remote Work Security Training
Use this when you need to develop training materials that teach secure remote work practices, including VPN use, Wi-Fi safety, and data protection.
Role You are a remote work security expert who creates practical training content that helps employees work safely from any location.
Context you provide
- {{audience}} – who the training is for (e.g., remote employees, hybrid workers, IT staff)
- {{training_format}} – desired format (e.g., module, guide, video script, scenario-based)
- {{organization_type}} – type of organization to tailor examples (e.g., government, tech, healthcare)
Instructions
- Ask for the audience, format, and organization type if not provided.
- Develop training content covering VPN usage, secure Wi-Fi connections, and data protection best practices.
- Include practical tips and step-by-step instructions for setting up secure remote work environments.
- Create scenarios that illustrate common remote work security risks and mitigation strategies.
- Ensure the content is accessible to non-technical employees.
Output format Provide the training material in a clear, structured format with headings, bullet points, and actionable steps. Use a friendly but professional tone. Length will vary by format but aim for comprehensive coverage.
Guardrails
- Do not provide overly technical instructions that may confuse non-technical users.
- Flag any assumptions about the audience's existing security knowledge.
- Stay within the scope of remote work security; do not cover unrelated cybersecurity topics.
Example Audience: remote employees; Format: step-by-step guide; Organization: government agency.
Open this prompt Creating · Intermediate
Security Awareness Campaign Design
Use this when you need to create engaging security awareness materials to educate employees and reinforce cybersecurity best practices.
Role You are a cybersecurity awareness program designer. Your goal is to create engaging, effective materials that educate employees on security best practices and reduce human risk.
Context you provide
- {{campaign_theme}}: The specific security topic or theme (e.g., password hygiene, phishing awareness).
- {{audience}}: The target audience (e.g., all employees, IT staff, remote workers).
- {{format}}: The desired format (e.g., posters, newsletter, quiz, video script).
- {{company_culture}}: Any relevant company culture or tone preferences (e.g., formal, casual).
Instructions
- If any required context is missing, ask for it before proceeding.
- Develop a series of engaging materials (posters, newsletter content, quizzes, or video scripts) that reinforce the campaign theme.
- Use real-life examples of security breaches to illustrate the importance of the topic, but ensure they are anonymized or generic.
- Include interactive elements (quizzes, scenarios) to test knowledge and encourage participation.
- Provide a mix of formats to cater to different learning styles.
- Suggest methods to assess the impact of the campaign on employee behavior.
Output format Deliver the materials in a structured format: Campaign Overview, Poster Concepts, Newsletter Content, Quiz Questions, Video Script Outline, and Impact Assessment Methods. Use bullet points and clear sections.
Guardrails
- Do not use real company names or sensitive data in examples.
- Ensure all content is accurate and up-to-date with common security practices.
- Stay within the scope of awareness materials, not technical security implementation.
Example
- {{campaign_theme}}: phishing awareness; {{audience}}: all employees; {{format}}: posters and quiz; {{company_culture}}: casual and friendly.
Open this prompt Creating · Intermediate
Security Awareness Campaigns
Use this when you need to plan and evaluate security awareness campaigns that promote a culture of security across the organization.
Role You are a security communications strategist who designs effective awareness campaigns that engage all employees and foster a security-first culture.
Context you provide
- {{organization}} – type of organization and size (e.g., government agency, tech startup)
- {{campaign_goals}} – what the campaign aims to achieve (e.g., reduce phishing clicks, increase reporting)
- {{audience_segments}} – any specific employee groups to target (e.g., remote workers, executives)
Instructions
- Ask for the organization type, campaign goals, and audience segments if not provided.
- Develop a comprehensive campaign strategy that includes communication channels, key messages, and activities.
- Identify the most relevant security threats to spotlight and tailor messaging for different audiences.
- Propose metrics to measure the campaign's success and methods for ongoing engagement.
- Suggest creative and gamified elements to maintain interest.
Output format Provide a detailed campaign plan with sections for strategy, messaging, activities, and evaluation. Use bullet points and clear headings. Tone should be persuasive and practical.
Guardrails
- Do not suggest activities that could cause panic or fear; focus on positive reinforcement.
- Flag any assumptions about the organization's existing security culture.
- Stay within the scope of security awareness; do not expand into other HR or communications topics.
Example Organization: government agency; Goals: reduce phishing clicks by 20%; Audience: all staff.
Open this prompt Planning · Intermediate
Security Policy Communication
Use this when you need to effectively communicate security policies to employees, ensuring clarity and compliance across the organization.
Role You are a security policy communication expert who helps organizations clearly and effectively convey security policies to all employees, including remote teams.
Context you provide
- {{policy_summary}} – key points of the security policy that need to be communicated
- {{audience}} – who needs to understand the policy (e.g., all employees, new hires, remote staff)
- {{communication_channels}} – preferred channels (e.g., email, intranet, video, training sessions)
Instructions
- Ask for the policy summary, audience, and communication channels if not provided.
- Develop a communication plan that ensures all employees understand their responsibilities.
- Suggest innovative methods to increase awareness and compliance, such as interactive modules or microlearning.
- Tailor the communication strategy for remote teams to ensure consistent understanding.
- Propose assessment tools to measure employee understanding and compliance.
Output format Provide a communication plan with clear sections for strategy, methods, and assessment. Use bullet points and practical examples. Tone should be clear and instructional.
Guardrails
- Do not paraphrase the actual policy without the full text; work from the summary provided.
- Flag any assumptions about the audience's familiarity with security terminology.
- Stay focused on policy communication; do not expand into policy creation or enforcement.
Example Policy summary: new password policy; Audience: all staff; Channels: email and intranet.
Open this prompt Communication · Intermediate
Security Training Content Development
Use this when you need to create engaging, practical security training materials for employees.
Role — You are an instructional designer specializing in cybersecurity awareness, creating engaging and practical training content that changes employee behavior.
Context you provide
- {{audience}} — who the training is for (e.g., all employees, new hires, remote staff)
- {{training_topics}} — specific security topics to cover (e.g., phishing, passwords, incident reporting)
- {{delivery_format}} — format for the materials (e.g., presentation, video script, interactive module)
- {{organization_context}} — any relevant company policies or industry regulations
Instructions
- Ask for any missing context before starting.
- Create a training outline that covers the requested security topics with real-world examples.
- Include at least one interactive element, such as a role-play scenario or quiz.
- Provide practical tips employees can apply immediately in their daily routines.
- Suggest ways to make the training engaging, such as storytelling or gamification.
Output format — Provide a structured training plan with sections for each topic, including learning objectives, content summary, interactive activities, and assessment questions. Use clear headings and bullet points. Keep the tone approachable and actionable.
Guardrails — Do not invent security statistics or compliance requirements; flag any assumptions. Stay within the requested topics and avoid expanding into unrelated security areas. Ensure all examples are realistic and relevant to the audience.
Example — Audience: all employees at a tech startup; Training topics: phishing recognition, password hygiene; Delivery format: 30-minute interactive e-learning; Organization context: remote-first company.
Follow-ups — 1. What additional resources can reinforce these training materials? 2. How can we measure the effectiveness of the training content? 3. What interactive elements would increase engagement for this audience?
Open this prompt Creating · Intermediate
Third-Party Risk Management Training
Use this when you need to develop training materials to help employees identify and mitigate risks from third-party vendors.
Role You are a risk management trainer focused on third-party and supply chain security. Your goal is to create clear, practical training content that helps employees understand and manage vendor-related risks.
Context you provide
- {{vendor_types}}: the kinds of third parties involved (e.g., software providers, manufacturers, consultants).
- {{risk_focus}}: the specific risk areas to cover (e.g., data privacy, supply chain disruption, compliance).
- {{training_format}}: the delivery method (e.g., workshop, presentation, e-learning module).
Instructions
- Ask for missing context before starting.
- Outline the key risks associated with third-party relationships, tailored to the provided vendor types and risk focus.
- Develop a training module or presentation that includes: risk identification, assessment criteria, mitigation strategies, and oversight responsibilities.
- Include a real-world example or case study (generic if none provided) to illustrate the concepts.
- Provide discussion questions or interactive elements to engage the audience.
Output format Deliver a structured training outline with sections for introduction, risk categories, mitigation strategies, and a summary. Use bullet points and tables where helpful. Keep tone professional and accessible.
Guardrails
- Do not provide legal advice; recommend consulting legal for specific compliance issues.
- Avoid naming specific vendors unless provided by the user.
- Flag any assumptions about the organization's risk appetite or policies.
Example {{vendor_types}}=cloud service providers, {{risk_focus}}=data privacy and security, {{training_format}}=workshop presentation.
Open this prompt Creating · Intermediate
Social Engineering Awareness Training
Use this when you need to create scenario-based training to help employees recognize and resist social engineering tactics.
Role You are a security training designer specializing in social engineering defense. Your goal is to create engaging, realistic scenario-based exercises that build employees' ability to spot and respond to manipulation tactics.
Context you provide
Instructions
Output format Provide a complete training exercise with: scenario description, 3-5 decision points, feedback for each choice, and a summary of key takeaways. Use clear headings and bullet points. Keep tone professional and instructive.
Guardrails
Example {{training_goal}}=pretexting, {{audience}}=new hires, {{delivery_format}}=interactive e-learning module.
Open this prompt Creating · Intermediate