Running Phishing Simulations: IT AI Prompts
Phishing simulations are essential, but if the 'gotcha' email makes the employee feel ashamed, they'll hate the security team. This template is educational: it shows them the 'clues' they missed and points them to the training resource. It's a teaching moment, not a disciplinary one.
The Core Blueprint
- Software Environment: Outlook (Enterprise AI: Copilot, ChatGPT, Claude, etc.)
- Role Focus: IT
- Execution Complexity: Standard
- Taxonomy Tag: #SECURITY
Strategic Use Cases
This correspondence constraint acts as a direct communication architect. It forces the language model to maintain professional warmth while driving action for IT scenarios:
Sending a 'you fell for it' simulation notification to an employee.
The follow-up email after a company-wide phishing simulation test.
Execution Workflow
Streamline your inbox architecture with this execution flow:
- 1Confirm the user fell for the simulation and pull the 'clues' (e.g., weird sender).
- 2Initialize your IT security communication.
- 3Run the simulation-reminder template, keeping the tone light and educational.
Advanced Optimization
Ensure your correspondence drives immediate resolution by editing the prompt's behavioral tags:
- The 'It-Happens' Frame
...'Don't worry, this was a simulation'—reassure them immediately.
- Teach-the-Clue
...'Here's what you missed: [CLUE]'—give them a specific, actionable lesson.
- Positive-Reinforcement
...'Thanks for helping keep our company secure by learning this'—thank them.