How We Keep You Safe
Cybersecurity training can involve uncertainty, mistakes, sensitive information and situations people may feel uncomfortable discussing. How those moments are handled matters just as much as the material being taught.
We want people to be able to take part, ask questions and explore difficult decisions without being embarrassed, singled out or made to feel that they should already know the answer. Different levels of technical confidence are expected, and the session should remain useful whether someone works with technology every day or rarely thinks about cybersecurity at all.
The same care applies to the organisation commissioning the training. We keep the information we ask for proportionate, respect confidentiality and professional boundaries, consider accessibility and safeguarding where relevant, and use clear routes when something needs to be handled outside the training conversation.
Keeping people safe does not mean removing every difficult subject or pretending cybersecurity is risk-free. It means creating the conditions for those subjects to be discussed responsibly.
Safe participation and sensitive conversations
Cybersecurity can become personal very quickly. Someone may have clicked something suspicious, trusted a convincing message, shared information through the wrong route or nearly taken an action that later looked much easier to question.
We do not use embarrassment as a teaching tool.
Our sessions are designed to be calm, respectful and no-blame. We do not single people out, deliberately catch participants out or turn an individual mistake into a public lesson. Responsibility still matters, but understanding why an action made sense at the time gives us something much more useful to work with than simply telling somebody they should have known better.
Questions are encouraged, including the ones people may feel awkward asking. Someone might be unsure what to do after clicking a link, whether an unusual request is significant enough to report or how they are supposed to challenge something that appears to come from a senior colleague. Those are exactly the kinds of uncertainties worth exploring.
We also recognise that not everything belongs in the room.
If a conversation moves into a live organisational incident, sensitive personal information, safeguarding, wellbeing or another issue that should not be explored openly with the group, we keep appropriate boundaries. We do not turn a sensitive disclosure into training content simply because it arose during the session.
Where something needs different ownership, we help make that boundary clear so it can move through the appropriate organisational route.
For sessions involving young people or audiences with particular safeguarding requirements, the content and participation approach are adjusted accordingly. Where accessibility, participation or safeguarding needs are known beforehand, discussing them during planning gives us the best chance to make appropriate arrangements before the session begins.
Information, privacy and the delivery environment
Making training relevant can involve learning something about your organisation, the audience and the situations people are likely to encounter.
That does not mean we need unrestricted access to internal information.
We ask for information because it has a purpose. That might be understanding the roles in the room, how a particular process works or the type of situation you would like reflected in the training. If something is not necessary to plan or deliver the session, there is no benefit in collecting it simply because it is available.
The same principle applies to examples. A real situation can sometimes make useful context, but identifying individuals, customers or sensitive organisational details is rarely necessary to understand the decision underneath it. Where information can be anonymised or discussed more generally without losing what makes the example useful, that is normally the better route.
Online and on-site delivery also bring different practical considerations.
For online sessions, we agree the platform and joining arrangements beforehand. For on-site delivery, we work within the access, confidentiality, security and practical requirements of the organisation we are visiting. Information, screens, documents and conversations should not become unnecessarily exposed simply because training is taking place.
Cyber Rebels applies information-security and data-minimisation principles to the information used across planning and delivery. The formal detail sits in our policies and Supplier Assurance material rather than being reproduced in full on this page.
Professional boundaries and organisational responsibility
A training session can sometimes reveal something bigger than the question that brought us into the room.
Participants may describe a verification route that nobody can realistically use. A discussion may reveal uncertainty about who owns escalation. A workaround may exist because the approved system repeatedly prevents legitimate work from being completed.
Those observations can be useful, but they do not automatically become participant failures and they do not automatically become another training requirement.
Cyber Rebels is responsible for planning and delivering the agreed training professionally, managing the learning environment appropriately and handling the information entrusted to us for that purpose.
Your organisation remains responsible for its own systems, policies, controls, safeguarding arrangements, authority structures, escalation routes and operational decisions.
That distinction helps protect everyone involved.
If the session brings an organisational issue into view, we can make it visible and help clarify what appears to be happening. We do not pretend that a training session can replace a process change, management decision, technical control or safeguarding response that properly belongs elsewhere.
The same applies when somebody raises a live concern. There are times when the responsible thing to do is stop exploring it as a learning example and make sure the right person or process takes ownership instead.
Good training should help people develop judgement. It should not blur the boundaries around who is responsible for decisions that sit outside their role.
Need reassurance before training?
This page explains what safe and responsible delivery means in practice. Some organisations understandably need more formal evidence before engaging a training provider, while others simply want to talk through a practical concern before the session.
Our Supplier Assurance Pack brings together the information used for procurement and due-diligence checks, including relevant governance, safeguarding, information-security and professional-assurance material. You can also review the underlying policies directly where your organisation needs the formal source rather than a summary.
If there is something we should understand before working with your organisation — an accessibility requirement, safeguarding consideration, information-handling concern or a question about how someone will be able to participate — let us know.
We would much rather talk it through while we are planning and make the right arrangement than leave somebody wondering whether the session will work for them.
Talk to Us About Training