From Infodump to Transformation: Re-imagining Digital Security Training
Izebel (Security and Privacy Consultant / Volunteer Organizer · Techies for Reproductive Justice)
BSides Seattle 2026 · Day 1 · Track 2
Overview
Isabelle, a security and privacy consultant with a background in public health education who has trained thousands of people over 15 years, delivered an interactive session challenging the security community to fundamentally rethink how it teaches digital security to non-technical audiences. Drawing on their dual background -- nonprofit public health work (HIV prevention, intimate partner violence education) and cybersecurity practice -- Isabelle argues that the standard corporate training model (death by PowerPoint, checklist compliance, tool evangelism) fails community members and at-risk populations who need security knowledge most urgently.

Key moments
- 0:00 Isabelle's origin story: public health to cybersecurity via EFF workshop
- 8:00 What's not working: death by PowerPoint, tool evangelism, overwhelm
- 14:00 Misplaced expectations and the gatekeeping problem
- 20:00 The LeVar Burton principle: how participants feel when they leave
- 24:00 Neuroscience hacks: 90-min max, spaced repetition, humor, color
- 26:00 Paulo Freire: problem posing and critical consciousness in security
- 32:00 Audience techniques: Fake Mike phishing, AI post-click conversations
- 38:00 Decision fatigue and the tech doula model for hands-on guidance
From Infodump to Transformation: Re-imagining Digital Security Training
Speakers: Isabelle, Security and Privacy Consultant / Volunteer Organizer, Techies for Reproductive Justice
Conference: BSides Seattle 2026
YouTube: https://www.youtube.com/watch?v=KLgMvtyfNh8
Overview
Isabelle, a security and privacy consultant with a background in public health education who has trained thousands of people over 15 years, delivered an interactive session challenging the security community to fundamentally rethink how it teaches digital security to non-technical audiences. Drawing on their dual background -- nonprofit public health work (HIV prevention, intimate partner violence education) and cybersecurity practice -- Isabelle argues that the standard corporate training model (death by PowerPoint, checklist compliance, tool evangelism) fails community members and at-risk populations who need security knowledge most urgently.
The talk is framed around a shift from the "banking model of education" (depositing knowledge into passive recipients) to transformative pedagogy inspired by Paulo Freire, the Brazilian educator and philosopher. Isabelle presented specific pedagogical frameworks -- problem posing, dialogue and co-learning, critical consciousness, and knowledge-action-reflection loops -- alongside neuroscience-backed tactics for information retention, then facilitated an extended audience discussion where practitioners shared their own techniques and challenges.
This is not a technical security talk in the conventional sense. It is a talk about the human infrastructure required to make technical security knowledge effective, particularly for communities facing real surveillance threats from state actors, data brokers, and intimate partners.
Background
▶ Watch: Isabelle's origin story: public health to cybersecurity via EFF workshop (0:00)
Isabelle's path to cybersecurity began out of necessity. Working in nonprofit for 15 years (starting at less than $12,000/year), they moonlit as a model and began learning security and privacy tactics to protect themselves from the vulnerabilities that dual career created. They were often the unofficial tech person in their nonprofit workplace, but did not identify as technical until 2020, when they attended a workshop by the Electronic Frontier Foundation and the Hacking Hustling collective.
That workshop was transformative because it placed technical education (encryption, backdoors) in political context (the Lawful Access to Encrypted Data Act) and was taught by women and queer people. Within a month, Isabelle was building cybersecurity guides for activists, learning about mesh networking, and teaching others. Six years later, they run a security and privacy consultancy, organize with Techies for Reproductive Justice, and work for a cybersecurity and IT company.
The problem Isabelle observes is that many security professionals going into community training are applying corporate training paradigms that do not work: information overload in single sessions, tool recommendations without frameworks, checklist approaches, context-removed hypothetical scenarios, talking at rather than with participants, and no mechanism for follow-up or repetition.
Key Findings
▶ Watch: Misplaced expectations and the gatekeeping problem (14:00)
The talk surfaced several key insights from both Isabelle's experience and the audience's collective knowledge:
What is not working in security training: Death by PowerPoint. Being overly technical with non-technical audiences. Talking at people without engagement opportunities. Context-removed hypothetical scenarios. Not stating learning objectives. Treating training as an annual compliance checkbox. No repetition or practice opportunities. Overwhelming participants with too much information. Leaving people more anxious than when they arrived. Tool evangelism without frameworks (exemplified by a neighbor who bought a "burner" iPhone and logged in with all the same accounts, defeating the purpose entirely).
What makes effective education: Interactivity and personal experience over passive consumption. Tailored experiences that adapt as questions arise. Real recognition and celebration of wins. Learning in community (backed by neuroscience research showing improved learning with real people). Eye contact and human presence. Creating feelings of curiosity, motivation, and capability.
Neuroscience-backed tactics: 90 minutes is the maximum effective attention span. Spaced repetition is critical -- in public health education, six touches was the threshold for behavior change. Reducing cognitive load (simple slides, few words, color, simple graphics that can be understood in four seconds or less). Humor drives engagement and action (Isabelle's most effective slide is a simple image that makes people laugh about password reuse, after which they approach her to set up a password manager). Emotional connection before content delivery.
Decision fatigue emerged as a major insight from audience discussion. Even when people understand the "why" of a tool like a password manager, they become paralyzed by the "which one" question -- Googling password managers returns six or seven options with different technical tradeoffs, and people simply don't act. Isabelle addresses this as a "tech doula" through Techies for Reproductive Justice: sitting down one-on-one, walking through installation step by step, celebrating wins, and reinforcing that the person is capable.
Technical Deep Dive
▶ Watch: Neuroscience hacks: 90-min max, spaced repetition, humor, color (24:00)
The technical contribution of this talk is pedagogical rather than cybersecurity-focused, but the frameworks presented have direct applicability to security training design:
Paulo Freire's critical pedagogy provides four applicable concepts. Problem posing starts from participant-generated scenarios analyzed collaboratively, with the expert as facilitator. Example: "What happens if someone infiltrates our group chat? What information would be most dangerous in the wrong hands?" Dialogue and co-learning establishes a horizontal conversation where experts bring technical knowledge to the learner's reality. This produces more nuanced security decisions -- for example, moving beyond "don't bring your phone to a protest" to harm-reduction approaches that account for disability, parenting, and navigation needs. Critical consciousness connects personal experience to social, political, and economic forces (as EFF did for Isabelle), leading to more accurate threat modeling and genuine engagement. Knowledge-action-reflection loops create iterative cycles of practice, evaluation, and adjustment, tied to spaced repetition.
The LeVar Burton principle (named by Isabelle after the Reading Rainbow host) encapsulates the goal: participants should leave feeling curious and empowered, not overwhelmed. Burton did not just teach book content -- he inspired a love of reading and directed viewers to their library to continue independently. Similarly, security trainers should emphasize that all knowledge is freely available and learners do not need to go through the expert as a gatekeeper.
Audience-contributed techniques included: turning training into room-wide conversation before opening PowerPoint, using real phishing examples (including "Fake Mike" persona with the real CEO laughing in the back), AI-driven post-click conversations that assess user understanding through rubric-based dialogue, peer homework discussion in multi-day classes, knowledge checks with feedback loops explaining why wrong answers seemed right, and having learners teach topics back to reinforce both confidence and retention.
Demo / Proof of Concept
▶ Watch: Paulo Freire: problem posing and critical consciousness in security (26:00)
The talk itself was a demonstration of its own principles. Isabelle used a live QR code poll at the start to gather audience perspectives on what makes a good teacher, then wove those responses into the presentation. The extended audience discussion section (approximately 20 minutes) was a live implementation of dialogue and co-learning, where practitioners shared techniques from military security training, phishing simulation design, retirement community education, and corporate engineering training contexts.
Defensive Implications
▶ Watch: Decision fatigue and the tech doula model for hands-on guidance (38:00)
For security teams responsible for awareness training, the implications are direct: the standard annual compliance training is not producing behavior change, and the community training approaches used by many security professionals volunteering their time are often replications of corporate patterns that do not work outside that context.
Organizations should consider restructuring security training to include multiple shorter sessions with spaced repetition rather than single annual marathons. Training designers should reduce cognitive load, use humor and emotional connection, and create hands-on practice opportunities. The "tech doula" model -- intensive one-on-one or small-group guided setup of security tools -- is particularly effective for at-risk populations but requires significant time investment.
For security leaders, the gatekeeping problem is worth noting: if security teams position themselves as the sole keepers of knowledge, they create a bottleneck and a dependency. Emphasizing that security knowledge is freely accessible and learnable empowers people to continue learning independently.
Key Takeaways
- Standard security training (annual compliance, death by PowerPoint, tool evangelism) does not produce behavior change; six touches with spaced repetition is the public health benchmark
- Paulo Freire's critical pedagogy -- problem posing, dialogue and co-learning, critical consciousness, knowledge-action-reflection loops -- provides a proven framework for transformative security education
- Decision fatigue is a major barrier: people who understand the "why" of security tools become paralyzed by the "which one" and simply do not act; the "tech doula" model of guided hands-on setup addresses this
- How participants feel when they leave (curious, capable, empowered vs. overwhelmed, anxious) is the most important outcome metric for community security training
- Security professionals should not gatekeep: emphasize that all knowledge is freely available and learners can continue independently
- 90 minutes is the maximum attention span; slides should be simple (few words, color, graphics understandable in four seconds); humor drives engagement and subsequent action
About the Speaker(s)
Isabelle (they/she) is a security and privacy consultant who came to cybersecurity from 15 years of nonprofit public health education (HIV prevention, intimate partner violence). They are a volunteer organizer with Techies for Reproductive Justice, where they serve as a "tech doula" providing hands-on security guidance to community members. Their entry point to cybersecurity was a 2020 EFF and Hacking Hustling workshop that connected technical education to political context. They maintain a Signal group for continuing peer education among security trainers.
Reviews
Dr. Zero (Offensive Security Researcher) — HARD PASS
A community education and pedagogy talk with zero technical security content. Isabelle presents Paulo Freire's critical pedagogy and neuroscience-backed teaching tactics applied to security awareness training for non-technical audiences. While potentially valuable for community educators, this contains no vulnerabilities, no tools, no exploits, no technical research of any kind.
Heather Calloway (CISO) — STRONG
A valuable talk for anyone responsible for security awareness training, especially in community or high-risk population contexts. The Paulo Freire frameworks, neuroscience-backed teaching tactics, and the tech doula model address the persistent failure of standard security training to produce behavior change. The audience-contributed techniques (AI post-click conversations, Fake Mike phishing simulations) add practical depth. Limited in governance applicability but strong for defender education programs.