Home · Business · IT, Data & Security · Cybersecurity

PARTLY

As of 13 August 2026, AI can only partly train your staff in cybersecurity.

This still needs a person who signs their name to it.

Can you do it?

15 minutesto a draft.

1 hourto something you’d act on.

Cost, all in£0

Skill neededchat-fluent

Who has to check ita colleague

What the alternative costsThe supplied tool data gives no price for a human cybersecurity training service.

If this goes wrong: staff learn an inaccurate or irrelevant process, continue to mishandle a real attack and your organisation deals with the resulting breach.

What to actually do

  1. Hand it to a person

    The route this page recommends

    A person who owns the outcome does this end to end, worth it when the failure is dear.

  2. Use a tool built for this

    Second choice
  3. Do it yourself

    The distant third

    A chat interface, chat-fluent skill, and roughly 1 hour until you can act on the result.

    How to actually do it

    1. Open your organisation's current security policies, incident-reporting instructions and relevant NCSC guidance, then gather only the sections staff need to follow.
    2. Ask your IT or security lead for the staff roles, systems, common risks, reporting route, training length and learning objectives, and record any items they cannot confirm.
    3. Paste the gathered information into the prompt, replacing each bracketed slot and removing passwords, personal data, confidential incident details and live credentials.
    4. Paste the generated lesson plan, scenarios, questions and handout into a working document, then compare every instruction with your current policies and reporting route.
    5. Ask your IT or security lead to check the technical claims, examples and escalation instructions against the organisation's actual systems and controls before staff see them.
    6. Run the knowledge check with a small staff group, collect the questions they get wrong, and ask the model to revise only those explanations using the approved policy text.
    7. Deliver or configure the approved session, send the handout through your normal internal channel, and record completion and the results of the knowledge check.

    Prompt

    Act as a cybersecurity training designer for a UK organisation. Create a practical staff training session using only the information below and current, authoritative UK guidance. Do not invent policies, systems, incidents, legal duties, statistics or technical controls. Flag anything that needs confirmation by our IT or security lead.
    
    Organisation: [brief description]
    Staff roles and technical confidence: [description]
    Systems and services staff use: [list]
    Known risks or recent incidents: [list, or state none]
    Current security policies and reporting route: [paste the relevant text]
    Training length and format: [for example, 30-minute online session]
    Learning objectives: [list]
    
    Produce:
    1. A plain-English lesson plan with timings.
    2. A short explanation of password managers, multi-factor authentication, software updates, device security, safe handling of data, suspicious links and reporting incidents, but include only topics relevant to the information supplied.
    3. Three realistic UK workplace scenarios with the correct action and an explanation of why.
    4. Ten multiple-choice questions with answers and explanations.
    5. A one-page staff handout stating exactly what staff should do if they suspect phishing, lose a device or disclose information to the wrong person.
    6. A short knowledge check and a method for the security lead to measure completion and understanding.
    
    Separate confirmed facts, assumptions and items requiring approval. Keep the language suitable for non-specialists. Do not ask staff to paste passwords, personal data, confidential incident details or live security credentials into the training tool.

    Open it prefilled in ChatGPT or Claude, or copy it into Gemini, which takes no prefill link.

What it gets wrong

  • AI cannot know which threats are most relevant to your organisation unless someone supplies accurate internal context.
  • It cannot confirm that its instructions match your live systems, permissions, policies and incident-reporting route.
  • It cannot replace a security lead who decides how staff should respond to an unusual or ambiguous incident.
  • It cannot prove that staff will change their behaviour after completing a lesson.
  • It does not carry responsibility if inaccurate training contributes to a security incident.

What caps this at PARTLY: judgement under ambiguity, verification cost and stakes of error.

How we scored this

Five axes, each scored nought to two by hand: ten means AI carries the task cleanly, and the thresholds that turn a total into YES, PARTLY or NO are published in the methodology. Each axis name links to its definition.

AxisScore (0–2)
Output2
Inputs1
Verification1
Liability1
Effort delta1
Total6 / 10

FAQ

Can AI create cybersecurity training for my employees?
Yes, it can draft lesson plans, scenarios, quizzes and handouts for common topics such as phishing, passwords, multi-factor authentication and incident reporting. You still need a security lead to adapt and approve the material against your actual systems and policies.
Can AI deliver cybersecurity training to my staff?
It can support delivery through a chatbot, written course or interactive quiz. It cannot reliably answer every organisation-specific question or tell whether staff will act correctly during a real incident, so keep human oversight and a clear reporting route.
Is AI-generated cybersecurity training safe to use at work?
It is suitable for a first draft if you provide approved source material and remove confidential information. Check every technical instruction, reporting route and claim before use, because a confident mistake can leave staff following the wrong process.
What should I give AI to create staff security training?
Give it the staff roles, systems they use, relevant risks, approved policies, reporting instructions, training format and learning objectives. Do not provide passwords, personal data, confidential incident details or live security credentials.

Nearby answers

Assessed by gpt-5.6-luna (gpt-5.6-luna) on 2026-08-13, second-checked by an independent model. Wrong somewhere? Email [email protected] and it gets re-checked.

The newsletter

AI news, new answers and product picks, straight to your inbox.