As ethical hackers we must present our findings to other I.T. professionals; by exposing security flaws we are essentially critiquing their work and that can sometimes elicit a defensive reaction. The response can be anywhere from downplaying the threat or likelihood of exploitation to going on the offensive and questioning the value in our work, and it can be very tempting sometimes to respond in kind. Certainly our delivery can help push others towards or away from the defensive, and at times it's almost an art.
So what kinds of reactions have you gotten from presenting your findings? How did you react...what worked and what didn't?
Is this skill important, and would teaching effective delivery and diffusing a situation be a valuable subtopic in ethical hacker training?