Beyond Awareness: Building Cybersecurity Judgement
It is 4:42pm and a finance assistant is clearing the last invoices before the payment run closes. A supplier update looks familiar enough to approve.
Elsewhere, a manager receives an access request from someone already involved in the project, while a shared file appears from a recognised name inside an active conversation.
Nothing looks dramatic. Everything appears to fit the work.
That is why these moments matter.
People rarely face cybersecurity decisions in isolation. They are completing tasks, supporting colleagues and responding to requests that feel routine, useful and expected.
The question is seldom, “Is this a cyber threat?”
It is more often, “Do I carry on, or stop something that appears to make sense?”
Awareness can help people recognise common threats, but recognition alone is not enough when the deadline is real, the request feels legitimate or the approved checking route is difficult to use.
Someone may know a change should be verified and still continue because the process is slow, the culture rewards speed or the person needed to approve the next step is unavailable.
The Cyber Rebels Five-Domain Model was built for that gap. It develops the capabilities people need to recognise, verify, act, escalate and judge under real working conditions, while keeping the surrounding environment visible so process and system failures are not reduced to individual blame.
Why this framework matters
Most organisations do not struggle because nobody has heard the advice before.
The harder question is whether that advice can be applied while work is moving: during deadlines, interruptions, senior requests, customer pressure, payment processes and familiar system prompts.
That is where awareness can begin to thin out. Not necessarily because people have forgotten what they know, but because the situation does not feel unusual enough to interrupt the task. The request fits. The route looks normal. Acting now feels helpful.
Sometimes the missing capability is recognition, verification or escalation. Training can help people practise those decisions before the pressure is real.
At other times, the person already knows what a safer response would look like, but the organisation makes it difficult to take. The verification route may be slow, responsibility unclear or the control poorly matched to the task. People may also have learned that raising uncertainty creates more difficulty than carrying on.
Those are not the same problem.
The Five-Domain Model helps Cyber Rebels distinguish between them. It considers what the person needs to recognise or do while also examining whether the organisation provides the time, tools, authority and support needed to make that response realistic.
This makes training more useful because it can be directed at genuine capability and judgement needs. It also prevents organisational friction from being mislabelled as carelessness, weak awareness or a failure to follow the rules.
The purpose is not to turn employees into cybersecurity specialists. It is to help people make sound decisions within their own roles and help organisations create conditions in which those decisions are supported.
A framework for decisions made during real work
The Five-Domain Model gives structure to the judgement people need when cyber risk appears inside ordinary activity.
It does not treat cybersecurity as a list of threats to remember. It connects the capabilities needed before, during and after a decision.
A person may first need to notice that an ordinary-looking situation deserves attention. They may then need to confirm something through an independent route, complete the task without relying on an unsafe workaround, or raise uncertainty before the situation becomes clearly serious.
Where the rules, responsibilities and pressures do not point neatly in one direction, professional judgement brings those capabilities together.
These decisions do not happen separately from the workplace. Someone may be interrupted, lack authority, work across inaccessible systems or receive mixed signals about whether speed or checking matters more. The framework keeps those conditions within the discussion rather than treating the decision as though it happened in a vacuum.
The aim is not to make people suspicious of everything they see. That would make ordinary work harder without creating proportionate control. It is to help people recognise when something deserves a pause, a check or a conversation—and help the organisation make those actions practical.
The five domains are connected because real decisions are connected.
A payment change may involve recognition, independent verification, payment controls, escalation and judgement about whether the task should continue. A shared document may involve trust, permissions, team habits and the availability of a clear route for checking where it came from.
Together, the domains help teams move beyond knowing about cyber risk. They create a clearer way to understand the decision, the conditions shaping it and the response that fits.
What changes in practice
The model is designed to improve the conversation around cyber decisions.
Instead of asking only whether something looked suspicious or whether a rule was followed, teams can examine what made the action feel reasonable and whether the expected safer route was realistic at the time.
A payment request may have fitted the supplier conversation but still needed confirmation through a separate route. A person may have understood the reporting process but been uncertain about who would own the response. A shortcut may have solved an immediate problem because the approved system was unavailable.
These conversations make it possible to separate a capability gap from a process problem.
Someone may need more practice recognising an unusual request. Equally, the organisation may need a faster verification route, clearer ownership or stronger support from managers when somebody pauses.
The framework does not assume that every difficult decision needs more training. It helps identify whether the appropriate response sits with learning, process, technology, workload, leadership, governance—or a combination of them.
This also supports a more constructive response after something has happened. Rather than beginning with why a person made the wrong choice, the organisation can examine the task they were trying to complete, what made the request believable and which pressures or expectations shaped the decision.
It can then consider what the person could reasonably have done differently and what needs to change around them to make that response easier next time.
The value of the model is not additional cybersecurity vocabulary. It is a practical structure for understanding how decisions form and where intervention will genuinely help.
Domain One: Contextual Risk Recognition
Contextual Risk Recognition is the ability to notice when cyber risk appears to belong inside normal work.
This is where many incidents begin. Not with a flashing warning sign, but with something that fits the task already underway.
An email lands while someone is clearing messages before a meeting. A payment change arrives when the payment was expected. A shared file appears during a project discussion. A system prompt interrupts an action the person has completed many times before.
Nothing immediately feels wrong.
The person is not choosing between something obviously safe and something obviously dangerous. They are deciding whether to continue with work that appears legitimate or interrupt it without yet knowing whether there is a problem.
Carrying on can feel entirely reasonable. The sender is familiar, the timing fits and a delay may affect a colleague, customer, learner, patient or supplier.
Recognition therefore depends on more than spotting suspicious wording. It involves noticing when urgency, familiarity, authority or the surrounding task is reducing scrutiny.
It also depends on whether the environment allows attention to be redirected. Someone working through interruptions, alert overload or an inaccessible interface may miss a signal that would be clearer in calmer conditions. Repeated warnings may also teach people to dismiss messages that rarely require action.
The capability is not constant suspicion. It is the ability to recognise when something can fit naturally into the work and still deserve attention.
Where that capability is missing, training can help people practise recognising the decision point. Where the signal is buried by poor design, excessive workload or conflicting expectations, the organisation must address those conditions rather than expecting vigilance to compensate indefinitely.
Domain Two: Verification & Control Discipline
Verification and Control Discipline is the ability to check before acting, even when something already looks legitimate.
Picture a supplier email arriving just before a payment run. The company name is correct. The wording is ordinary. The change requested is straightforward. Updating the details would allow the task to be completed on time.
The difficulty is not necessarily that the person does not understand verification. It is that the request already looks believable.
Something can look right without having been confirmed.
A payment change may appear to come from a trusted supplier. A reset prompt may resemble a recognised system. A request for information may fit a conversation already taking place.
This domain helps people distinguish familiarity from verification and identify when confirmation through a separate route is proportionate. That might mean using a known contact detail, checking outside the original message or following an agreed approval route.
But verification is not only an individual behaviour. The route must exist and be usable.
An organisation cannot reasonably expect staff to verify quickly if contact details are difficult to find, responsibilities are unclear or the approved route regularly delays urgent work. A process that depends on an unavailable manager may encourage improvisation. A control that adds substantial effort to a routine task may be bypassed because the work still needs to be completed.
The model therefore considers whether the person knows when and how to check, and whether the organisation has made that check realistic.
The aim is not for every action to receive the same level of scrutiny. It is for important decisions to be supported by verification that fits the risk, the role and the pace of the work.
Domain Three: Secure Operational Behaviour
ecure Operational Behaviour concerns the everyday ways work is completed: how accounts are used, information is shared, devices are managed, access is controlled and temporary solutions become routine.
This domain lives in decisions that often feel too small to matter.
A password is saved because entering it repeatedly creates friction. A file is shared more widely because several people need quick access. An update is postponed because the device is needed for a meeting. A personal account is used because the approved system is unavailable.
None of those actions begins with an intention to create risk.
They are usually adaptations to something in the work: a difficult tool, a tight deadline, an unavailable resource or a process that does not fit the task as well as the informal alternative.
That distinction matters.
Telling people to avoid shortcuts is unlikely to solve a recurring problem when the approved route remains slower, inaccessible or unreliable. The behaviour may create risk while also revealing something important about the surrounding system.
The domain helps people recognise when convenience is beginning to replace control and understand the longer-term effect of repeating an apparently minor workaround.
It also helps organisations look beyond the action itself. A useful response explores why the workaround helped, what task it made possible and which part of the approved route needs to become easier, quicker or more accessible.
Where an individual habit is the main issue, training and reinforcement can help. Where people are adapting to broken tools, unrealistic workload or poorly designed processes, the response must improve those conditions as well.
Secure operational behaviour becomes more consistent when the safer route supports the work rather than asking people to choose between security and getting the job done.
Domain Four: Incident Judgement & Escalation
Incident Judgement and Escalation is the ability to act on uncertainty before a situation becomes clearly serious.
Someone clicks a link, then pauses. The page did not load properly, but nothing else seems to have happened. A file opens strangely and then appears to work. A message feels slightly unusual, but it may simply be badly written.
This is where many people hesitate.
They are not usually deciding whether to hide a confirmed incident. They are deciding whether the uncertainty is significant enough to raise.
That hesitation makes sense. People do not want to waste somebody’s time, interrupt important work or make a minor concern sound more serious than it is. They may also worry that reporting the issue will draw attention to their own action.
This domain helps people understand that escalation can begin before certainty. Raising a concern does not require them to diagnose the incident or prove that harm has occurred. It gives someone with the appropriate responsibility the opportunity to assess it while the information is still available.
Confidence to escalate, however, depends on what happens after somebody speaks up.
A reporting route may exist but be difficult to find. Concerns may be passed between teams without ownership. People may receive no response and conclude that reporting was unnecessary. Managers may focus on who clicked rather than what needs to happen next.
Those experiences shape future behaviour.
The model therefore considers both the capability to recognise and raise uncertainty and the organisational response that follows. People need to know where to go, what information is useful and what they can reasonably do while waiting. The organisation needs to provide clear ownership and a proportionate, supportive response.
Escalation becomes part of responsible work when people can raise a small concern without having to label it a major incident or defend why they asked for help.
Domain Five: Professional Cyber Judgement
Professional Cyber Judgement brings the other four domains together when the answer is not obvious.
A manager wants to keep a project moving, but an access request does not quite sit right. A finance team member wants to avoid delaying a supplier, but the payment change needs checking. A frontline employee wants to help, but the information being requested is sensitive.
The decision is not whether to follow security or ignore it.
It is what the right response looks like given the task, the pressure, the person’s responsibility and what is known at that moment.
Rules and guidance remain important, but they cannot remove every judgement call. People still need to interpret the situation, decide which control fits and recognise when the issue has moved beyond their role.
Professional judgement also includes noticing when the organisation has created an unreasonable choice.
A person should not be expected to balance service continuity and security alone when authority is unclear. They should not have to invent an exception because nobody owns the decision. Nor should they be blamed for using a workaround when the task cannot be completed through the approved route and no supported alternative exists.
The domain helps people combine recognition, verification, secure working and escalation. It also helps managers understand the authority, support and boundaries people need in order to make those decisions well.
The intended capability is not perfect decision-making. It is the ability to make a proportionate choice, explain the reasoning, recognise the limits of one’s role and seek support when the situation requires wider ownership.
Cybersecurity then becomes part of professional judgement rather than a separate subject considered only during formal training.
How the Model Shapes Cyber Rebels Training
The Five-Domain Model sits underneath how Cyber Rebels designs and delivers training, but it does not assume that training is the answer to every problem.
Each session begins with the decisions people are likely to make in their actual roles. Rather than explaining threats in isolation and expecting people to recall the advice later, the training explores where those threats become difficult to recognise: during a rushed approval, a familiar request, a shared-document discussion, a system prompt, a payment change or an uncertain moment someone is not sure whether to report.
The domains help us understand where the difficulty sits.
A person may need more practice recognising risk in context or knowing when a separate check is proportionate. A workaround may have become normal because it solves a genuine operational problem. The reporting route may be unclear, or the person may lack the authority needed to resolve the situation being placed in front of them.
The same analysis considers whether the organisation makes the better action realistic. A verification route needs to be usable. Responsibilities need to be understood. Systems and controls must fit the work, and people need visible support when they pause or raise uncertainty.
Most workplace situations involve more than one domain, alongside conditions that training cannot repair on its own.
A supplier payment change may require recognition, independent verification, an agreed process, early escalation and judgement about whether the task should continue. If no workable confirmation route exists, that remains part of the problem.
A remote team may need better judgement around shared platforms and informal requests, alongside clearer access ownership or more usable collaboration tools. A leadership team may need to strengthen escalation and accountability while also clarifying who can accept risk, approve an exception or support a decision that cannot be resolved by the person facing it.
This is why the model separates capability from organisational enablement.
Training is used where people need opportunities to recognise, interpret, verify, practise or judge. Process, technology, workload, leadership and governance issues are identified separately so they can receive the response they actually require.
The content changes according to the role and environment, but the purpose remains consistent: helping people understand the decision while helping organisations see what must exist around them for the better response to become normal.
The intended result is not simply that people know more. It is stronger capability to recognise, verify, act, escalate and judge during real work, alongside a clearer understanding of whether the organisation enables those behaviours or quietly makes them harder.