My first year dedicated to Cyber Security

Share
My first year dedicated to Cyber Security
Image by Irina from Pixabay

Soon I will be celebrating my first full year as a purely Information Security Analyst, so here are some of my own personal thoughts on the state of cyber security

Firstly, experience trumps certifications.
I took the CISSP thinking I would just waltz into a job, and it never worked out that way. I did get a few interviews but I also got rejected a lot, falling short with not enough experience specifically in Security.

Yes, CISSP is a very difficult certification and I took it because it's seen as the gold standard certification to get. There people with decades of experience who do not pass the exam, which I took 4-5 weeks solid, 6-7 hours a day to prepare for. So I am proud of myself for that. Although in the end, I think a good mix of knowledge and certifications is where you should be and, you should always be wanting to expand your knowledge further as the area grows.

Secondly, Cyber Security is vast. You cannot do every single area of IT security and do it well. I am starting to see that maybe I cannot learn it all regarding IT Security. I personally keep wanting to learn penetration testing skills but I am unsure if it fits my brain, I'm a problem solver and I think if I can get my head round the technical parts, I can do it, but I go to do a CTF (Capture The Flag) and I get easily turned off by it.

There are so many areas I know that I will not expand my knowledge past the basic knowledge, such as Cryptography. I probably know more than an IT engineer, but I couldn't get myself locked into the nitty gritty parts of Cryptography.

While there are all the technical parts of IT Security, there is also GRC (Governance, Risk & Compliance) - and I think this is maybe where my head feels the most comfortable. Either auditing people or being a part of a team who is audited to meet certain governance criteria. I think it's the black and white and rule setting that really allows me to know what to aim for.

Next, Cyber Security is hard and is only going to get harder. You have to be confident in what you're talking about, you have to be able to guide people in the right direction while thinking of what the company needs from a managerial perspective and now AI is being thrown in with Security.

Don't get me wrong, I love what AI is doing, it has allowed me to create things I just didn't have the skills or time for and it does it well enough. Could I get away being a website developer for a business, no. Can I use it to build handy applications for me to use day to day, yes.

Finally, you'll never win everyone over. Unfortunately Cyber Security are usually the ones who are demonized when changes come in place to protect your companies/customers. Some people will just accept it, some people will not be bothered and then some will kick up a fuss, unfortunately that seems to be unavoidable in IT Security. Don't take it to heart.

Keep chugging on!