How Booking Cybersecurity Training With Cyber Rebels Works
A clear, collaborative process designed to reduce uncertainty rather than add to it.
Step 1
Getting in Touch
It usually starts with a question.
Some organisations come to us with a clear idea of what they need. Others are less certain and want to sense-check whether training is the right next step. Both are common.
When you get in touch, we focus on answering what you’ve asked, clearly and without assumption, so you can decide what makes sense for your organisation.
There’s no obligation at this stage. It’s simply a conversation to understand your situation and whether training is likely to be useful.
Step 2
Understanding Your Environment
If training looks appropriate, we’ll invite you to complete our Cyber Security Awareness Questionnaire.
This isn’t an audit or a test. There are no right or wrong answers, and no expectation that everything is already in place. The questions are designed to help you describe how your organisation actually operates — where decisions move quickly, where pressure builds, and where actions are most likely to be taken without being fully checked.
Across different sectors, this step often brings clarity. What starts as a general concern about cyber risk becomes something more specific, grounded in how work is actually happening day to day.
Step 3
Shaping the Training
Using your responses, we develop a clear training scope.
The aim is to make sure the session reflects your environment and priorities rather than relying on generic content. The scope sets out what we recommend covering, what will sit outside the session, how the training will be delivered and what it is designed to help people recognise, discuss or practise.
This is where a general concern about cyber risk can be connected more clearly to the way work is actually happening. A rushed approval, an informal workaround or an unclear reporting route may point to a capability that training can strengthen. It may also reveal a process, control or management expectation that needs attention elsewhere.
At this stage, everything remains flexible. You can adjust the scope, refine it or decide not to proceed.
Step 4
Confirming the Details
Once the scope is agreed, we send over the invoice along with our Training Services Agreement.
This sets out the practical details of the training — including delivery arrangements and responsibilities on both sides — so everything is clear before moving forward.
While approval and payment are handled on your side, we begin preparing the session based on what has been agreed, ensuring the training reflects your organisation from the outset.
Step 5
Preparing the Session
Preparation happens before delivery, not on the day.
We use the agreed scope to shape the session, selecting relevant examples, building realistic scenarios, and preparing discussion points that reflect how cyber risk is likely to appear in your day-to-day work.
Because we’ve seen how these situations show up across different organisations, the focus is always on making the session feel familiar and relevant rather than generic.
We also confirm practical arrangements in advance, whether that’s scheduling, platform access for online sessions, or room and equipment requirements for on-site delivery. Taking care of this early helps everything run smoothly.
Step 6
Delivery: Online or On-Site
Training is delivered live, either online or on-site.
For online sessions, you can use your own video conferencing platform or have us host. If you prefer your own system, you can invite us as a presenter. If we’re hosting, we’ll provide joining details and confirm access arrangements in advance.
For on-site sessions, we confirm the setup ahead of time — including room layout, Wi-Fi, and display equipment — so everything is ready to go.
This flexibility allows the training to fit around how your organisation already operates, rather than requiring you to adapt to a fixed format.
Step 7
The Training Experience
Sessions are practical, interactive and grounded in the decisions people make during ordinary work.
Rather than beginning with rules or asking people to memorise lists of threats, the training explores situations that feel routine: a familiar request arriving during a busy task, a change that appears to fit an existing conversation or an uncertain moment when someone is not sure whether to pause or carry on.
Participants examine what made the action feel reasonable, what deserved checking and what a proportionate response could look like. The discussion also keeps the surrounding conditions visible. An unclear process, difficult control or conflicting management signal should not be treated as an individual awareness failure.
Sessions are shaped around the Cyber Rebels Five-Domain Model. This develops contextual risk recognition, verification, secure operational behaviour, early escalation and professional judgement under pressure.
The five domains are connected because real decisions are connected. A payment change may involve noticing that something deserves attention, confirming it through a separate route, following the agreed process and deciding whether to escalate before the payment continues.
Where the difficulty sits with knowledge or judgement, the session gives people space to practise. Where the safer action is made difficult by workload, technology, unclear authority or an unusable process, that condition remains part of the conversation rather than being scored as participant weakness.
Through realistic scenarios and shared discussion, participants can test how they would respond while the task is still moving and leave with clearer language for recognising, checking and raising uncertainty.
Step 8
After the Session
Following the training, we issue a certificate of completion for the organisation, with individual certificates available where required.
We also invite feedback from participants and organisers. This helps us understand which situations felt most relevant, where people needed more clarity and how future delivery could better reflect the organisation’s working environment.
A useful immediate indicator is often the way people discuss decisions at the end of the session. Participants may be better able to explain why a request felt normal, identify where a check was needed or recognise when an issue should move beyond their role.
These are intended capabilities rather than guarantees of lasting change. Whether they become part of everyday work also depends on what happens around the person after the session: whether verification routes are usable, responsibilities are clear and managers support people when they pause or raise uncertainty.
Where ongoing reinforcement would be helpful, we can discuss how the learning might be revisited without simply repeating the same training.
A Process Designed to Feel Manageable
The process is deliberately structured to be calm, transparent, and collaborative from start to finish.
You remain in control of what’s delivered, how it’s delivered, and whether you proceed at each stage. The aim isn’t to rush decisions, but to make sure the training you receive is genuinely useful.