Cyber Rebels

Incident response plan checklist with yes ticked.
Resources, Templates & Tools
Andy Longhurst

Why Every UK SME Needs a Cyber Incident Response Plan

A supplier calls to question a change to your bank details. At almost the same time, someone in the office says they cannot access a shared folder, and another team member mentions that a mailbox has started sending unusual replies. Nothing has been confirmed. No one yet knows whether the

Explore Insight »
social engineering tactics
Threat Intelligence & Real-World Attacks
Andy Longhurst

The Art of Human Hacking: Understanding Social Engineering Threats

An employee is working through a task that needs to be completed before the end of the day. It’s routine work, the kind that involves moving between emails, systems, and documents, keeping things progressing without delay. Messages are being processed, requests are being handled, and decisions are being made quickly

Explore Insight »
Darkweb Banner
Threat Intelligence & Real-World Attacks
Andy Longhurst

The Dark Web Decoded: Unveiling the Underbelly of the Internet.

Why the Dark Web Still Gets Misunderstood The dark web is often discussed in extremes. It is either framed as a hidden world of criminal activity or dismissed as something distant and irrelevant to everyday life. In practice, it sits somewhere in between, but most people never really engage with

Explore Insight »
Person reviewing message alert on laptop
Cyber Culture & Behaviour
Andy Longhurst

AI Can Detect Threats — But It Can’t Fix Human Decisions

The Moment That Doesn’t Look Like Risk A message comes through on Teams. It appears to be from someone senior: short, direct, and straightforward. They need something sorted quickly. There is a sense of urgency, but nothing that feels unusual or out of character. Requests like this happen all the

Explore Insight »
Contrast between training and real work environments.
Cyber Culture & Behaviour
Andy Longhurst

How Employees Actually Make Security Decisions at Work

The Reality of Workplace Decisions There’s an assumption built into most cybersecurity training. That when an employee is faced with something suspicious, they will recognise the moment, pause what they are doing, and apply what they have been taught. That they will step out of the flow of work, assess

Explore Insight »
The Cyber Rebels Five-Domain Model framework for behaviour-led cybersecurity training
Cyber Rebels Updates
Andy Longhurst

What Is Behaviour-Led Cybersecurity Training?

In our previous article, Why Knowledge Alone Isn’t Enough, we explored why traditional cybersecurity awareness training often fails to prevent real-world cyber incidents. Cybersecurity incidents are frequently attributed to human error. An employee clicked a malicious link, approved a fraudulent payment, or shared information with someone they believed to be

Explore Insight »
Shopping cart close