Cyber Rebels

The Smart Way to Stay Secure: Why Cyber Security Retainers Are the Future of Business Protection

Glowing infinity symbol amid digital data streams.

For too long, cybersecurity awareness has been treated like an annual task. Once a year, teams complete a refresher, hear familiar advice about phishing, passwords and data safety, and then return to business as usual. For a while, it works. People recognise the examples. They talk about checking links, questioning payment changes, being careful with […]

For too long, cybersecurity awareness has been treated like an annual task. Once a year, teams complete a refresher, hear familiar advice about phishing, passwords and data safety, and then return to business as usual.

For a while, it works. People recognise the examples. They talk about checking links, questioning payment changes, being careful with shared files and reporting anything that feels unusual. The session feels useful because the risks are clear in the room.

Then Tuesday arrives.

A supplier request lands while someone is trying to close off the month. A shared document needs sending before a client call. A new starter is waiting for access so they can actually begin work. A familiar-looking message appears just as somebody is trying to finish a task before their next meeting.

Nothing about those moments feels like a cybersecurity decision. They feel like normal work.

That is where awareness can start to drift. Not because people do not care, and not necessarily because the training failed. The problem is that the real decision happens later, when the work is moving, the request looks reasonable and stopping to check can feel like the less useful thing to do.

People get busy. New employees join and learn how things are normally done. Tools and processes change. Shortcuts appear because they help work move faster. What seemed obvious during a training session can become much harder to recognise when it appears inside a real task several months later.

That is why ongoing cyber awareness support can be useful. Rather than expecting one training point to carry the whole year, it gives organisations a way to revisit the decisions that appear as people, tools and working conditions change.

Cyber Rebels’ Protect+ ongoing cyber awareness support is one way of doing that. It combines regular reinforcement, new-starter support and practical guidance throughout the year. Explore Protect+ ongoing cyber awareness support.

Why annual cyber awareness can drift

It is tempting to describe awareness drift as people forgetting their training. Sometimes memory will be part of it, but that explanation is too simple.

Imagine a finance team member dealing with an expected supplier payment. A request arrives asking for a change to the bank details. The supplier is real. The payment is expected. The wording fits the conversation already taking place and the month-end deadline is getting closer.

The person does not have to forget everything they know about cybersecurity to approve the change. The request simply fits the work closely enough that independent verification feels less necessary.

The same thing can happen when a manager approves access for somebody who needs to start work, when a colleague opens a document from a familiar contact or when somebody accepts a login prompt because they are trying to get back into the system.

These decisions are not automatically careless. They make sense in context.

That is the part annual awareness has to survive.

Training can give people useful knowledge, examples and ways to respond. Policies can establish expectations. Technical controls can stop or limit certain actions. But work continues to change around all of them.

A new communication platform changes how colleagues contact one another. A new supplier changes a finance process. Hybrid working creates a more informal route for sharing something quickly. A growing team means people no longer know every colleague personally. A workaround that solved a genuine operational problem starts becoming the normal way of doing things.

The question is no longer simply whether somebody remembers the rule. It is whether the organisation keeps bringing important decisions back into view as the conditions around them change.

What a cyber security retainer changes

A cyber security retainer creates a different rhythm.

Instead of cybersecurity awareness disappearing between annual training dates, there are planned opportunities to revisit it as the organisation develops. New starters can be introduced to expectations earlier. Existing teams can refresh decisions that have become routine. Managers can discuss situations that do not fit neatly into a policy. Emerging issues can be explored without waiting for the next annual session.

The value is not in repeating the same warning more often.

It is in keeping the conversation connected to what people are actually doing.

A payment-change example may need revisiting because the organisation has changed suppliers. Document sharing may deserve another look because a team has moved to a different platform. A growing organisation may need to think about how access requests are verified now that people can no longer rely on recognising every name.

Regular reinforcement can also expose a different kind of problem: situations where people know what the safer action is, but the organisation makes that action difficult.

If somebody is expected to verify a request but there is no practical verification route, more reminders will not solve the problem. If staff are told to escalate uncertainty but managers consistently reward speed, the surrounding signal needs attention. If a workaround exists because the approved process is too slow to use during real work, training alone cannot remove the reason the workaround appeared.

Good ongoing support should help an organisation see that distinction rather than treating every risky decision as an employee awareness problem.

Why ongoing support makes business sense

Cyber risk is not limited to occasional dramatic incidents. Organisations make decisions about information, payments, access, accounts, suppliers and digital systems every day.

The UK Government’s Cyber Security Breaches Survey 2025/2026 found that 43% of businesses and 28% of charities reported identifying some form of cyber security breach or attack during the previous 12 months. The survey is careful to note that it can only measure incidents organisations identified and were willing to report, so those figures should be treated as evidence of the scale of the issue rather than a complete count of everything that occurred.

That does not mean every organisation needs the same cybersecurity response, or that a retainer prevents those incidents. It does show why cybersecurity cannot sensibly be treated as something that matters for one training day and then disappears for the rest of the year.

The practical case for ongoing awareness support is much closer to everyday operations.

A growing business does not need to restart its approach every time somebody joins. Managers have somewhere to bring awareness questions that appear between formal training points. Teams can revisit the decisions that matter as systems and processes change. The organisation can maintain a clearer record of ongoing awareness activity rather than relying entirely on one annual event.

There is also value in continuity.

If support is already planned, the organisation is not repeatedly deciding whether it is time to think about awareness again. The conversation has a place in the calendar and can move with the business.

For a retainer with a fixed monthly scope, the cost of that support is also easier to plan. What it should not be confused with is incident-response cover, technical monitoring or managed security. Those are different requirements and should be treated as such.

A retainer should support the decision, not just repeat the topic

One of the weaknesses of traditional awareness is that cybersecurity topics can become detached from the moments in which people actually need them.

A team can know what phishing is and still struggle with a convincing request from a genuine compromised account. They can understand the principle of least privilege and still approve access because somebody needs to get a job done. They can know that payment changes should be verified and still rely on the email thread because everything else about the request looks right.

The useful question is not simply, “Have we covered phishing this year?”

It is, “What will make somebody pause when this particular request looks completely normal?”

That changes what ongoing support needs to do.

Instead of endlessly cycling through a list of cybersecurity topics, organisations can revisit the points where judgement matters: recognising when familiarity is reducing scrutiny, checking through an independent route, handling uncertainty without feeling that work has to stop, knowing when to escalate and making sure the organisation supports those actions when somebody uses them.

The working conditions matter too.

If people are encouraged to verify but verification takes fifteen minutes while the task is measured in seconds, that friction matters. If new starters learn the informal process from colleagues before anybody explains the approved route, that matters. If a manager treats questioning a request as unnecessary delay, that matters.

Awareness is stronger when the person and the organisation are both part of the conversation.

What ongoing cyber awareness support can and cannot do

A cyber security retainer can provide useful continuity, but it is important not to turn it into something it is not.

Ongoing awareness support can create regular opportunities to refresh decisions, discuss situations that have appeared in the organisation, support new starters, answer practical awareness questions and keep verification, escalation and judgement visible as work changes.

It can also help organisations notice recurring friction. If the same question keeps appearing, the answer may not be another reminder. The process, system, authority or support route may need to change.

What awareness support cannot do is replace the wider cybersecurity controls an organisation needs.

Training does not replace secure configuration, access management, backups, patching, monitoring, incident response, business continuity, suitable technical support or appropriate governance. Nor does repeatedly telling somebody to make a better decision fix a process that makes the better decision unrealistic.

The point of ongoing support is not to make staff personally responsible for everything that might go wrong.

It is to keep the human decision layer visible alongside the technology, processes and organisational conditions that shape it.

Where Protect+ fits

Protect+ is Cyber Rebels’ ongoing cyber awareness support programme for organisations that do not want awareness to disappear after a training session.

It is built around regular reinforcement rather than repeating generic content. Depending on the plan and the organisation’s needs, support can include live refresher sessions, new-starter onboarding, awareness guidance, scenario review, practical resources and time for awareness or policy-in-practice questions.

The support is shaped around the organisation because awareness does not drift in exactly the same way everywhere.

For a finance team, the important decision may involve supplier changes and payment approval. In professional services, it may be document sharing or client communication. In education or healthcare, care, urgency and sensitive information can interact. Remote teams may depend more heavily on chat platforms, shared folders and informal digital workarounds.

The common point is not the cyber topic. It is the decision somebody is making while trying to do their job.

Protect+ keeps returning to those decisions as the organisation changes. It can also help make process friction visible where reinforcement is not enough on its own.

It is not a managed security service. It does not monitor systems, provide technical oversight or replace internal IT controls.

For organisations already recognising the problem described in this article, the full Protect+ service page explains what the programme includes, how the three levels of support differ and where each may fit. See how Protect+ works and compare the plans.

From annual awareness to ongoing judgement

The future of business protection will still involve technology. Organisations need appropriate technical controls, secure systems, good governance and people who know how to use the routes available to them.

But technology does not remove the decisions happening around it.

Someone still decides whether a request is genuine enough to act on. A manager decides whether access should be approved. A colleague decides whether a document can be shared. A finance team decides whether a change needs independent verification. Somebody notices that a situation does not quite feel right and decides whether they have enough reason to raise it.

Those decisions happen while work is already moving.

That is why annual awareness can only ever be one part of the answer. A good training session can create a strong starting point, but the organisation around it keeps changing. People join. Tools change. Pressures shift. Shortcuts emerge. Familiarity grows.

Ongoing support gives organisations a way to revisit those decisions without pretending that everybody needs to start from the beginning each time.

The aim is not constant suspicion. It is not to make every routine task feel dangerous or ask people to stop work whenever something is slightly unusual.

It is to make the useful pause easier to recognise and easier to use: checking a payment change through a known route, questioning an unexpected access request, involving somebody else when the context does not sit quite right or escalating uncertainty before guesswork takes over.

That is a more realistic way to think about ongoing cyber awareness.

Not as an annual message people are expected to remember indefinitely, but as part of how an organisation keeps judgement connected to the work people are actually doing.

Keep cyber awareness active with Protect+

If your organisation already invests in cybersecurity training but wants a practical way to keep those decisions visible between formal sessions, Protect+ provides regular reinforcement, new-starter support and ongoing awareness guidance shaped around the way your team works.

 

Director of Training and Development, Cyber Rebels. Andy Longhurst is the founder of Cyber Rebels and a cybersecurity practitioner and educator focused on how risk actually shows up in real organisations. His work sits at the intersection of digital safety, education, and practical risk management — helping teams understand not just what policies say, but what happens in the moments where decisions are made under pressure. With a background spanning adult education, web development, and technical consultancy, Andy specialises in translating complex security concepts into clear, usable understanding. Rather than focusing solely on tools or compliance frameworks, his approach centres on human behaviour, judgement, and the systems that shape everyday choices. He delivers live, interactive cyber awareness training for organisations of all sizes, from small businesses and education providers to public-sector teams and larger organisations operating in complex risk environments. Outside of delivery, Andy spends his time analysing emerging attack patterns, refining training design, and exploring how organisations can build resilience that holds up in the real world — usually with a strategically sized cup of tea close to hand.

Shopping cart close