
Andy Longhurst
- Email: [email protected]
I’m a cybersecurity educator and digital skills specialist, and most of my work has centred on one question: why can people know the right security advice and still find it difficult to use when real work is happening?
Over the past decade, I’ve worked with SMEs, charities, corporate teams and public-sector organisations. Across very different environments, I kept seeing similar situations: people dealing with familiar requests, competing priorities and everyday pressure, where the decision made complete sense from their point of view at the time. That became a big part of the thinking behind Cyber Rebels.
My background in adult education and assessment has shaped the other side of that work. I’m interested in making cybersecurity understandable without oversimplifying it, creating space for people to question what they are being told and helping them practise judgement rather than simply remember rules. That is why our training is built around discussion, realistic situations and the way work actually happens.
My professional development spans cybersecurity, IT, education, assessment and leadership, alongside professional membership of BCS and the Chartered Institute of Information Security. Those different strands give me a useful mix of technical understanding, education experience and a practical view of how people make decisions.
Ultimately, the aim is simple: make cybersecurity something people can use while they are doing their jobs, not something that only makes sense when they are sitting in a training session.
My professional skills sit across cybersecurity, digital education and behavioural risk, with a focus on how those areas come together in real working environments.
I design and deliver practical cybersecurity training, develop realistic scenarios and translate technical concepts into clear, usable guidance for people with different roles and levels of experience. A big part of that is helping people recognise where risk appears inside ordinary work, rather than treating cybersecurity as something separate from the job.
I also work with organisations around the conditions surrounding those decisions, including verification, access, escalation, reporting and the way responsibilities are understood. That matters because better outcomes do not come from individual knowledge alone; the process around the person has to support the decision as well.
My background in adult education and assessment shapes how that work is structured. I think carefully about how people learn, how much information they actually need, and how to make sessions practical enough for people to question, discuss and apply what they are learning rather than simply listen to it.
That combination of technical understanding, teaching experience and behavioural thinking is what I bring to Cyber Rebels: making cybersecurity clearer, more usable and better connected to the decisions people are already making at work.