Ongoing support for the decisions that keep returning
A team completes cybersecurity training. The session lands well. People leave with a clearer way to talk about the moments they need to notice, question and verify.
Then work gets busy again.
A finance request needs approving before the end of the day. A shared document needs sending before a client call. A new starter asks how access is normally requested. A familiar-looking message arrives at just the right point in the process.
Nothing feels unusual enough to stop the work.
The decision is to keep things moving.
That decision makes sense. The training has not necessarily been forgotten. It is competing with the rhythm, pressure and familiarity of normal work.
Protect+ is ongoing cyber awareness support built for that reality. It helps organisations keep cyber judgement active after training, so safer decisions remain connected to everyday work rather than something people only consider when cybersecurity is mentioned directly.
Why ongoing cyber awareness support matters
Cybersecurity training is often treated as something with a clear end point. A session is delivered, attendance is recorded, and the organisation feels reassured that the issue has been addressed.
In practice, awareness has to keep working after the session has ended.
Deadlines return. Processes change. New tools are introduced. People join the team and learn by watching how others work. Shortcuts appear because they help people get things done. A request that once would have stood out can begin to feel normal because it now mirrors how the organisation communicates.
Weaker cyber decisions do not always mean that people have forgotten what they learned. They can form because the situation in front of them feels workable. The request fits the task. The person seems trusted. The action feels helpful. Stopping to check can feel unnecessary, awkward or slower than the work appears to allow.
That is how awareness drifts.
Not suddenly. Not necessarily because the original training failed. It drifts because work keeps moving around it.
Protect+ gives organisations a practical rhythm for keeping awareness connected to current working conditions. It creates space to revisit decision points, refresh shared language, support new starters, respond to emerging patterns and keep verification, escalation and judgement visible without restarting training from the beginning each time.
It is not a managed security service. It does not monitor systems, provide technical oversight or replace internal IT controls. Protect+ focuses on the decisions people continue to make inside normal work, especially when speed, trust, familiarity and responsibility shape what feels reasonable.
Where the surrounding process makes a safer action difficult, reinforcement alone is not the whole answer. Protect+ can help bring that friction into view, but the organisation may still need to make verification routes, reporting expectations, management support or working processes clearer and easier to use.
Inside Protect+
Protect+ is built around regular reinforcement rather than repeated generic awareness content.
The support can include refresher sessions, new-starter onboarding, awareness guidance, scenario review, practical resources and light advisory support, depending on the plan selected and the needs of the organisation.
The aim is not to say the same thing every month. It is to keep the right conversations alive as the organisation changes.
A refresher session might revisit a payment change that looks legitimate because it matches an existing supplier. It might explore a document-sharing request that feels routine because the client relationship is real. It might look at a shortcut that has become common because it helps the team move faster, or help managers make checking feel like part of helping rather than blocking.
These moments are explored calmly and practically. The focus is on what the person was trying to do, why the decision felt reasonable, what pressure was present, and where a pause, check or escalation would make the next decision clearer.
Protect+ can also support new starters. Awareness drift is not only about existing staff losing focus. It is also about new people entering the organisation and learning the informal version of how work gets done. If secure expectations are not made visible early, new starters may copy habits before they understand which routes are safe, which checks matter and when to ask.
Between sessions, support time can be used for awareness questions, scenario discussion, policy-in-practice queries, small-group guidance or practical awareness activity. This gives teams somewhere to sense-check uncertainty before it turns into guesswork.
Where useful, Protect+ can be shaped around the Cyber Rebels Five-Domain Model: risk recognition, verification, secure habits, escalation and professional judgement under pressure. In ongoing support, that means helping teams keep those behaviours active as workflows, roles, systems and pressures change.
Ongoing support shaped around your organisation
Protect+ is not a monthly content feed with your logo added to it.
The support is shaped around the decisions your team is actually making, because awareness does not drift in the same way everywhere. The pressures, routines and shortcuts that begin to feel normal depend on the work, the systems people use and the responsibilities they are carrying.
In a finance team, the pattern may form around payment changes, invoice approvals or supplier details. The request may look familiar, arrive at the expected point in the process and carry just enough urgency to make checking feel like an unnecessary delay.
In legal and professional services environments, the decision may involve sharing a document, responding to a client or handling a request that appears to come from a trusted contact. Confidentiality matters, but so do responsiveness, client expectations and the need to keep work progressing.
The pressures look different again in education, healthcare, care and community settings. Staff may be handling personal information, shared systems, safeguarding-related communication or urgent support needs. When someone appears to need help, pausing can feel difficult, even when the request or route being used deserves a closer look.
Retail, e-commerce, travel and hospitality teams often work at speed across bookings, customer data, payments, account changes and platform-based requests. Remote and hybrid teams may face the same decisions through chat messages, shared folders, cloud platforms, home networks and informal workarounds that have become part of the working day.
None of these situations needs to look dramatic for awareness to drift. They simply become familiar. A route works, so it is used again. A shortcut saves time, so it begins to feel normal. A request matches the work closely enough that questioning it feels less necessary.
That is why Protect+ is shaped around the organisation rather than delivered as repeated generic training. The support can follow the decisions, pressures and changes that matter to the team now, while keeping cyber judgement connected to the reality of the sector and the way work is actually being done.
Who Protect+ is designed for
Protect+ is for organisations that understand cyber awareness cannot be set once and then left to look after itself.
It is particularly useful for teams that have already invested in training and do not want that work to fade as people, systems, processes and pressures change. The challenge is rarely that staff have forgotten everything they learned. More often, the working environment has moved on. New tools are introduced, responsibilities shift, informal shortcuts appear and familiar decisions begin to feel routine again.
This is especially relevant for small and medium-sized organisations, where people often hold several responsibilities and decisions need to be made quickly. Someone handling finance may also be managing suppliers. A manager may be approving access while supporting a busy team. A new starter may learn how work is done by watching colleagues rather than by following a perfect written process.
In those conditions, risk is rarely created by carelessness. It forms through workload, trust, familiarity and the need to keep work moving. A request fits the task. A shortcut appears to save time. A colleague seems to know the process. Nothing feels serious enough to justify stopping, even when a check would be useful.
Protect+ also suits regulated, trust-based and service-led organisations where staff regularly handle sensitive information, payments, system access, client communication, personal data, safeguarding information or operational decisions. In these environments, the same type of decision may be interpreted differently across teams, locations or levels of experience. Ongoing support helps keep the organisation’s expectations visible without reducing every situation to a rigid rule.
It can be particularly valuable while an organisation is growing, onboarding new starters, working remotely or operating across several locations. It also provides a useful route when previous training is no longer discussed as naturally as it once was, or when managers recognise that awareness needs to remain part of everyday work rather than reappearing only at the next annual session.
The strongest fit is an organisation that does not want to keep restarting awareness from zero. Protect+ creates a steady rhythm of reinforcement, practical guidance and live support, helping teams revisit the decisions that continue to appear as the organisation changes.
The focus remains on behaviour, judgement and the conditions surrounding the decision. Protect+ is not technical monitoring, and it does not replace security controls or internal IT support. It helps organisations keep safer decision-making active between formal training sessions, while making it easier to notice where processes, expectations or support routes may also need attention.
Compare Protect+ plans
Protect+ is available at three levels of ongoing support. Each plan combines a different amount of monthly support time with live refresher training.
The right fit depends on how often your team needs reinforcement, how much support is useful between sessions and how widely decisions need to stay aligned across the organisation.
You do not need to choose a plan before speaking to us. We can help you compare the options against the way your team works.
Essentials
For smaller teams that need a steady rhythm of awareness support.-
Up to 2 hours of onboarding and awareness support each month
-
One two-hour refresher session each quarter
-
Up to 40 participants per refresher
-
Email support for awareness and policy questions
-
Curated resources and awareness updates
Growth
For growing organisations that need more regular reinforcement and support.-
Up to 4 hours of onboarding, awareness and decision-support time each month
-
One two-hour refresher session every two months
-
Up to 40 participants per refresher
-
One Half-Day Cybersecurity Workshop each year
-
Priority support by email and phone
-
Priority scheduling and optional topic focus
Enterprise
For organisations that need wider coverage, more frequent support or greater alignment across teams.-
Up to 8 hours of onboarding, awareness and advisory support each month
-
One two-hour refresher session each month
-
Up to 40 participants per refresher
-
One Full-Day Cybersecurity Training Programme each year
-
Dedicated trainer contact
-
Tailored content shaped around your sector, workflows, responsibilities and decision pressures
Monthly support time can be used flexibly for new-starter onboarding, small-group guidance, scenario discussions, awareness questions, policy-in-practice queries, light advisory input or other practical awareness activity agreed with Cyber Rebels.
What happens when awareness drifts into assumption
Organisations do not always notice awareness drift straight away because it rarely arrives as an obvious failure.
A process changes slightly. A new tool becomes part of the normal workflow. A manager answers a question quickly because the team is busy. A new starter copies the way access is requested because that is what they have seen others do. A team begins handling a particular request in the same way each time because the route works and nobody has had a reason to challenge it.
Taken separately, none of these moments feels serious enough to stop the work.
Awareness has not disappeared. People may still remember the training and understand the principles behind it. What changes is the way those principles are interpreted inside the current working environment. Assumptions begin to carry more of the decision.
That is where inconsistency can develop. Two people may handle the same situation differently because they have learned different versions of the process. A near-miss may go undiscussed because nothing harmful happened. A shortcut may become accepted because it saves time, while confidence grows that the organisation has already dealt with the issue through previous training.
Meanwhile, the work has moved on.
The issue is not that people have stopped caring or become careless. It is that behaviour is no longer being refreshed against the systems, pressures and expectations people are working with now.
Protect+ brings those moments back into view before they become too familiar to notice. It gives teams a regular opportunity to look at what has changed, where different assumptions may be forming and whether the routes people are expected to use still make sense in practice.
The aim is not to question every routine or turn ordinary work into a security exercise. It is to keep the decisions that matter visible enough that teams can recognise when something deserves a pause, a check or a conversation.
Keeping awareness active without creating more noise
Ongoing awareness support should not feel like being pulled through the same training again and again.
Protect+ is designed to fit around the work rather than compete with it. The support remains light enough to be practical, but regular enough to stop important decisions fading into the background. It uses realistic situations, calm discussion and focused reinforcement rather than fear, blame or repetition for its own sake.
The conversation develops as the organisation changes.
At one point, the most useful focus may be supplier requests, payment changes or invoice approvals. Later, the pressure may sit around access, document sharing, new starters or a platform the team has recently adopted. Another session may need to explore reporting uncertainty, escalation or the way managers respond when someone pauses a task to verify something.
This allows Protect+ to follow the work rather than repeat a fixed programme regardless of what is happening inside the organisation.
The purpose is not to create more messages, reminders or content for people to ignore. It is to keep cyber judgement current by returning to the decisions that still matter and making space for teams to discuss how those decisions are changing.
The support is designed to help people recognise situations sooner, ask more useful questions, verify through agreed routes and discuss uncertainty without feeling that they are slowing the work down. It also helps organisations notice when the expected route is unclear, awkward or unrealistic.
For safer decisions to become consistent, people need more than reminders. They need verification and reporting routes that work, expectations that are understood and visible support when they take the time to check.
A practical conversation about ongoing support
Protect+ usually begins with a practical conversation about how cyber awareness is currently being maintained across your organisation.
That may include previous training, team size, new-starter support, remote or hybrid working, recurring decision points and where people may be beginning to rely on assumption rather than active judgement.
We can also look at how regularly awareness needs refreshing, what kind of support would be useful between sessions and whether one of the existing Protect+ plans fits the way your organisation works.
You do not need to decide on a plan before the conversation.
The useful starting point is to identify what has already been covered, what has changed since then and which decisions need to stay visible as work continues.
From there, it becomes easier to choose the right rhythm of reinforcement and support.
Talk through how cyber support needs to work across your organisation