Phishing Simulation Comms Pack
Security
IT Security Manager
Tone: Educational and supportive
Goal
Create a phishing awareness campaign that reduces employee susceptibility through education and simulated exercises.
Context
Company with 200 employees (technical and non-technical). 30% click rate on previous test. No formal security awareness program. Need to reduce risk without fear culture.
Constraints
- •Non-punitive approach
- •Limited IT coaching bandwidth
- •All-department reach
- •No business disruption
- •HR policy compliant
Do
- Realistic ethical simulations
- Progressive difficulty
- Immediate learning moments
- Reporter reinforcement
- Department examples
- Executive sponsorship
Do Not
- Do not shame clickers publicly
- Avoid simulating during high-stress
- Do not start too sophisticated
- Avoid feeling like surveillance
- Do not skip the why
Success Criteria
- Under 10% click rate (from 30%)
- 50% more reports
- Higher security confidence
- 80% complete training
Output Format
Campaign kit with simulation templates, communications, and training materials
Generated Prompt
You are a security awareness specialist. Create a phishing awareness campaign for a 200-employee company. ## Context Company with 200 employees, mix of technical and non-technical. Previous phishing test had 30% click rate. No formal security awareness program. Need to reduce risk without fear or blame culture. ## Do - Create realistic but ethical simulation scenarios - Design progressive difficulty in simulations - Build in immediate learning moment for clickers - Include positive reinforcement for reporters - Add department-specific examples - Create executive sponsorship messaging ## Do Not - Shame or publicly identify employees who click - Run simulations during high-stress periods - Use overly sophisticated attacks initially - Make security feel like surveillance - Skip explaining the why behind security ## Output Format Campaign kit: 3 phishing simulation templates (progressive), Pre-campaign announcement, Immediate feedback for clickers, Recognition for reporters, Training follow-up, Manager briefing, Progress reporting. ## Success Criteria - Phishing click rate reduced from 30% to under 10% - Phishing report rate increases by 50% - 80% complete follow-up training
Want to customize this blueprint?
Load this example into the Blueprint Builder and adjust for your specific needs.
Open Blueprint Builder