Engage - Maximizing the effectiveness of AI Phishing Template Generator

This article provides guidance and usage tips for getting the most value from the Engage AI Phishing Template Generator and should be read together with the main feature article: Engage - AI Phishing Template Generator

Overview

The Engage AI Phishing Template Generator helps you quickly create realistic phishing simulation emails using natural language prompts.

Instead of writing every simulation template from scratch, you describe the scenario you want to test (for example, “an IT security alert asking the user to verify a suspicious login”), and the generator produces a suggested email that you can further refine.

This article focuses on:

  • How to write clear, effective prompts
  • Examples of prompts aligned to common scenarios and industries
  • Important content and privacy considerations when using AI

Key Principles for Writing Strong Prompts

When you create prompts for the AI Phishing Template Generator, keep the following principles in mind.

Define the “story” clearly

Your prompt should answer:

  1. Who appears to send the email?
  • Examples: IT, HR, a courier, a bank, an executive, accounts payable, and a healthcare provider.
  1. Why now?
  • Examples: an upcoming deadline, an account lockout, a missed delivery, a required policy acknowledgement.

This helps the generator produce a coherent scenario rather than a generic message.

Example

“IT security alert about suspicious sign-in from overseas; user must verify account within 24 hours or the account will be locked.”

Focus on one clear action

Each template should drive a single primary action that matches the attack vector you select in the UI (for example, a malicious link).

Typical actions:

  • Verify or confirm account details
  • Open a document
  • View a file or message
  • Update payroll or banking details
  • Acknowledge a policy or complete training

Avoid mixing multiple competing actions in one email (e.g., “open the file and also call this number and reply with details”), as this reduces clarity and learning value.

Use generic wording where needed

In many environments, you may need to avoid real trademarks or brand names in your prompts.

To support this:

  • Use phrases like “major cloud provider," “professional networking site," or “internal HR portal” instead of specific brand names, if your policy requires it.
  • Focus on the type of service and the user impact, not the specific vendor.

Example

“Security alert from a major cloud provider about unusual sign-in activity; user must verify their account via a link within 24 hours.”

Match the scenario to the industry

The generator allows you to choose an industry. Use this setting to align tone and context with your audience:

  • Healthcare – patient portals, lab results, appointment reminders
  • Finance – payment approvals, account notices, invoices
  • Energy / Utilities – service interruptions, billing notifications
  • Professional services – client document sharing, contract signature

Use the Additional instructions field sparingly for nuance (for example, “formal tone," “targeting executives," and "short, urgent style”).

Protect personal and sensitive data

When creating prompts:

  1. Do not include real personally identifiable information (PII), such as:
  • Real employee names and surnames
  • Real email addresses
  • Customer account numbers or other sensitive data
  1. Use placeholder or generic references instead:
  • “Your line manager”
  • “HR portal”
  • “Customer account portal”

This keeps simulations realistic while maintaining privacy and data protection standards.

Example Prompts by Scenario

Use the following examples as inspiration. Prompts should generally be under 500 characters.

In the UI, users should still select:

  • Attack vector
  • Difficulty
  • Scenario
  • Industry
  • Language

The prompt simply adds contextual detail.

  1. Microsoft / Identity

“Emulate a Microsoft 365-style security alert about a sign-in from an unusual country; user must verify identity within 24 hours or the account will be locked, using a link.”

“Fake Teams or SharePoint-style notification that a confidential file was shared externally and needs immediate review via a link.”

  1. HR / Payroll

“HR message telling the user that their payroll details must be confirmed before the next run; include a deadline and a link to update direct deposit information.”

“Mandatory HR policy acknowledgement email with a training compliance deadline this week and a link to complete attestation.”

  1. Shipping / Delivery

“Notification from a parcel carrier about a missed delivery; user must reschedule or arrange reshipment within 48 hours using a link. Use a courier-style tone without naming a real carrier.”

  1. Finance / Executive

“Urgent email from the CEO while traveling, requesting an immediate wire transfer or vendor payment; user is told to respond or use the link in this email only.”

“Accounts payable-style email about an overdue invoice with a link to a payment portal, warning about potential service interruption.”

  1. Healthcare

“Patient portal-style notification that new test results are available or that there is a message from the care team; the user must log into the portal to view it. Ensure it is clearly for simulation use only.”

(Confirm alignment with your compliance and training policies before using healthcare-themed simulations.)

  1. Professional Network

“A professional networking site-style message that a subscription or trial is expiring soon; the user must renew to avoid losing premium features, using a link.”

Avoid naming specific platforms if your policy restricts real brand use.

  1. Compliance / IT

“IT notices that multi-factor authentication or device registration must be renewed for compliance/audit; non-compliance will remove email access until resolved. Include a link to re-register."

  1. Legal / Documents

“Notification that a contract requires urgent electronic signature; include an e-sign request and a short deadline to review and sign via a link.”

  1. Gift Cards / Fraud (advanced use)

These scenarios can be powerful for advanced users but may not fit every organization.

“Email from IT or ‘security’ asking the user to urgently purchase gift cards to support a ‘verified incident response’; use only if your awareness program and policies allow this scenario.”

Use this type of scenario selectively and only where it aligns with your culture and risk appetite.

Additional Tips for Program Owners

  • Start with simpler scenarios for early campaigns (e.g., basic credential phishing) before introducing more complex or niche threats.
  • Review generated content before use to ensure it matches your tone, policy, and legal requirements.
  • Iterate on prompts if the output is too generic or not aligned with your audience—small changes to the “who” and “why” often improve results significantly.
  • Align with learning objectives: choose prompts that reinforce specific behaviors you want to develop, such as verifying URLs, questioning urgent payment requests, or checking HR notifications via trusted channels.

See Also...

Was this article helpful?
0 out of 0 found this helpful

Comments

0 comments

Please sign in to leave a comment.