An organisation's security depends on the people who govern it, manage it and live it every day.
Developing skills is a cornerstone of a strong security and resilience culture. But every role carries different responsibilities, risks and training needs: those who decide must understand obligations and impacts, those who operate must recognise threats, and those who oversee a function must know how to protect it.
That is why our offering is structured into three tracks: strategic training for top management, behavioural training for the entire workforce, and dedicated programmes for individual teams and functions. Each track is built around the organisation's objectives and fits into its skills development plans.
Strategic training for decision-makers
With the NIS2 Directive, cybersecurity has become a direct responsibility of management bodies. In Italy, Legislative Decree 138/2024 requires them to approve cybersecurity risk-management measures, oversee their implementation and undergo specific training. In the financial sector, the DORA Regulation sets out similar obligations.
Our programmes turn a compliance obligation into an advantage: they give board members, directors and senior executives the tools to understand cyber risk, assess its business impact and make informed decisions.

Content
- Regulatory framework: NIS2, DORA, CRA, AI Act and GDPR, focusing on the obligations and responsibilities of top management
- Cyber risk as business risk: financial, reputational and legal impacts
- Security governance: roles, delegation, board reporting
- Crisis management and business continuity: leadership's role during an incident
- Supply chain security and responsibilities towards suppliers and customers
Format
Executive sessions on site or online, crisis simulation workshops (tabletop exercises) for the board, and one-to-one mentoring for key roles such as CISOs and compliance managers.
Outcome
Documented training aligned with regulatory requirements, and a leadership team able to engage with technical functions and exercise effective oversight.
Cybersecurity is also a matter of mind
Most attacks don't break into a system: they persuade a person. Urgency, authority, trust, habit, fatigue: these are the psychological levers social engineering relies on. No technology, on its own, can neutralise them.
Our programme on the psychology of cybersecurity explains why we make mistakes, not just what not to do. It goes beyond traditional awareness training: instead of listing rules, it works on the cognitive and emotional mechanisms behind human error, turning awareness into lasting behaviour.
In Italy, the cognitive and behavioural side of security is still largely overlooked. Rexilience brings it into its offering alongside strategic and technical training, with a programme that has already been successfully tested in an academic setting.

Content
- How attackers think: the manipulation techniques behind phishing, vishing and fraud
- The cognitive biases that make us vulnerable: haste, overconfidence, deference to authority
- Stress, workload and distraction as risk factors
- Recognising a manipulation attempt and responding the right way
- From individual error to shared culture: reporting without fear
Format
Classroom or online sessions, short modules to include in annual training plans, open webinars, and phishing simulations linked to the course content.
Outcome
A more aware workforce, better able to recognise threats, which also supports the NIS2 requirement for regular employee training.
A tailored programme for every team
Every business function has its own obligations, risks and weak spots. This track combines, in essential form, the strategic perspective of our top-management training with the behavioural focus of our workforce programme, selecting only what truly matters for that team's work.
The result is focused, sustainable training: less generic content, more attention to what the team decides, manages and risks every day.

What changes · Risk management, incident notification obligations, business continuity
What to watch · Overconfidence in their own tools, handling exceptions under pressure
What changes · Responsibility for payment flows and financial data
What to watch · Urgent or "top-down" requests, business email compromise (BEC), fake suppliers
What changes · Protecting employee data, onboarding and offboarding
What to watch · Malicious applications and documents, requests for sensitive data
What changes · Supplier security and contractual requirements
What to watch · Trust in long-standing suppliers, changes of bank details or contact person
What changes · Role in crisis management
What to watch · Impulsive reactions during an incident, impersonation on social channels
Format
Short theory-based sessions, online or on site, dedicated to a single team. Self-assessment questionnaires before and after the programme measure awareness levels and help fine-tune the content.
Outcome
Each team understands the obligations and risks that directly concern it and can recognise the behaviours that expose it the most.
Mentoring for key roles
Tailored mentoring supports the professional growth of key people such as CISOs, IT and compliance managers, and functional managers. It offers ongoing dialogue, hands-on support and leadership development, guided by professionals who work on security and compliance projects every day.
Our approach
Key points
Let's build your organisation's training programme together
Tell us about your roles, objectives and regulatory obligations, and we will propose the right combination of tracks.