Training and
Mentoring

An organisation's security depends on the people who govern it, manage it and live it every day.

Developing skills is a cornerstone of a strong security and resilience culture. But every role carries different responsibilities, risks and training needs: those who decide must understand obligations and impacts, those who operate must recognise threats, and those who oversee a function must know how to protect it.

That is why our offering is structured into three tracks: strategic training for top management, behavioural training for the entire workforce, and dedicated programmes for individual teams and functions. Each track is built around the organisation's objectives and fits into its skills development plans.

Track 01 · Top management and governance

Strategic training for decision-makers

With the NIS2 Directive, cybersecurity has become a direct responsibility of management bodies. In Italy, Legislative Decree 138/2024 requires them to approve cybersecurity risk-management measures, oversee their implementation and undergo specific training. In the financial sector, the DORA Regulation sets out similar obligations.

Our programmes turn a compliance obligation into an advantage: they give board members, directors and senior executives the tools to understand cyber risk, assess its business impact and make informed decisions.

Trainer presenting a session for senior management to a group of executives at a meeting table

Content

  • Regulatory framework: NIS2, DORA, CRA, AI Act and GDPR, focusing on the obligations and responsibilities of top management
  • Cyber risk as business risk: financial, reputational and legal impacts
  • Security governance: roles, delegation, board reporting
  • Crisis management and business continuity: leadership's role during an incident
  • Supply chain security and responsibilities towards suppliers and customers

Format

Executive sessions on site or online, crisis simulation workshops (tabletop exercises) for the board, and one-to-one mentoring for key roles such as CISOs and compliance managers.

Outcome

Documented training aligned with regulatory requirements, and a leadership team able to engage with technical functions and exercise effective oversight.

Track 02 · Workforce

Cybersecurity is also a matter of mind

Most attacks don't break into a system: they persuade a person. Urgency, authority, trust, habit, fatigue: these are the psychological levers social engineering relies on. No technology, on its own, can neutralise them.

Our programme on the psychology of cybersecurity explains why we make mistakes, not just what not to do. It goes beyond traditional awareness training: instead of listing rules, it works on the cognitive and emotional mechanisms behind human error, turning awareness into lasting behaviour.

In Italy, the cognitive and behavioural side of security is still largely overlooked. Rexilience brings it into its offering alongside strategic and technical training, with a programme that has already been successfully tested in an academic setting.

Trainer addressing a room of employees during a behavioural training session

Content

  • How attackers think: the manipulation techniques behind phishing, vishing and fraud
  • The cognitive biases that make us vulnerable: haste, overconfidence, deference to authority
  • Stress, workload and distraction as risk factors
  • Recognising a manipulation attempt and responding the right way
  • From individual error to shared culture: reporting without fear

Format

Classroom or online sessions, short modules to include in annual training plans, open webinars, and phishing simulations linked to the course content.

Outcome

A more aware workforce, better able to recognise threats, which also supports the NIS2 requirement for regular employee training.

Track 03 · Teams and functions

A tailored programme for every team

Every business function has its own obligations, risks and weak spots. This track combines, in essential form, the strategic perspective of our top-management training with the behavioural focus of our workforce programme, selecting only what truly matters for that team's work.

The result is focused, sustainable training: less generic content, more attention to what the team decides, manages and risks every day.

Trainer discussing with a small working group around a table during a team training session
IT and security

What changes · Risk management, incident notification obligations, business continuity

What to watch · Overconfidence in their own tools, handling exceptions under pressure

Finance and administration

What changes · Responsibility for payment flows and financial data

What to watch · Urgent or "top-down" requests, business email compromise (BEC), fake suppliers

HR

What changes · Protecting employee data, onboarding and offboarding

What to watch · Malicious applications and documents, requests for sensitive data

Procurement and supply chain

What changes · Supplier security and contractual requirements

What to watch · Trust in long-standing suppliers, changes of bank details or contact person

Communications

What changes · Role in crisis management

What to watch · Impulsive reactions during an incident, impersonation on social channels

Format

Short theory-based sessions, online or on site, dedicated to a single team. Self-assessment questionnaires before and after the programme measure awareness levels and help fine-tune the content.

Outcome

Each team understands the obligations and risks that directly concern it and can recognise the behaviours that expose it the most.

Mentoring for key roles

Tailored mentoring supports the professional growth of key people such as CISOs, IT and compliance managers, and functional managers. It offers ongoing dialogue, hands-on support and leadership development, guided by professionals who work on security and compliance projects every day.

Our approach

ExperientialReal cases, hands-on labs and simulations, not just theory
TailoredEvery track starts from the organisation's objectives and context
IntegratedProgrammes fit into the organisation's skills development plans
FlexibleOn site, online, webinars or blended formats

Key points

Strategic training for top management and governance, aligned with NIS2 and DORA
A programme on the psychology of cybersecurity for the entire workforce
Dedicated programmes for individual teams, with self-assessment questionnaires
Experiential approach with simulations and real cases
Hands-on mentoring for key roles and leadership
Integration with skills development plans

Let's build your organisation's training programme together

Tell us about your roles, objectives and regulatory obligations, and we will propose the right combination of tracks.

Contact us

If you need further information about our services, please fill in the form below. We will get back to you as soon as possible.