Live data from Hacker News

Thinking of a Cybersecurity Career?

krebsonsecurity.com

121–129 of 129 posts

Re: Thinking of a Cybersecurity Career?

#121
post #110

Earlier quoted context omitted.

Naively, I would expect that an insurer is less likely to pay out if a basic pen-test suggests negligence on the part of the company.

Sort of. Pentests are a joke - a compliance activity and nothing more. As the client I get to pick the vendor, determine scope and influence the criticality of findings in the final report. Insurers don’t care about anything until you have a breach and a claim. They look to see whether you have the controls mandated in the policy and... Whether your attacker used a nation-state toolkit if so then they don’t have to p…

> Whether your attacker used a nation-state toolkit if so then they don’t have to pay.

Definitely seen that one.

I'm curious as to why an insurer wouldn't look at a bottom-tier pen-test for signs of gross negligence. They'll readily turn up things like failing to have authentication on key file shares, no access controls on the network, or no MFA in use. The sort of stuff that's easily exploited and shows utter neglect on the part of the insured.

Basically, it's been my experience that a tick-box pen-test exercise does a reasonable amount to check if the supposed controls are actually there.

Re: Thinking of a Cybersecurity Career?

#122

CyberSecurity, the domain that doesn't recruit yet has a shortage. What cybersecurity is to most people is automated security scans. This can be done by interns with a week of training to run the tools. (Interpreting and remediating the findings is another matter). Besides that, security is mainly about authentication. That's done by setting up LDAP, active directory, openid connect and co, and integrating in applica…

I mean the domain is so large you literally left out all of incident response and blue team, centralized threat analysts and red team, and all the engineers in those areas.

Re: Thinking of a Cybersecurity Career?

#123
post #48

Cybersecurity, as a field, is in desperate need of identifying different roles within it. These roles are notionally understood within the field, but what they are called and what exactly they do hasn't really crystallized quite yet. You still see job postings for "Cyber-security SME" or whatever and the organization has almost no idea what exactly they want out or the person they hire. So they end up with bored, hig…

Identifying roles? SANS has done this 10 times over.

Re: Thinking of a Cybersecurity Career?

#124
The amount of people completely forgetting and not even mentioning:

- Cybersecurity Incident Response, - The behemoth that is SIEM (nowadays called security analytics platforms) and everything else Blue Team - The role of centralized Vulnerability team and Threat Intelligence team. - And Red Team for in-house vulnerability detection to support the previous bullet.

Is alarming.

Re: Thinking of a Cybersecurity Career?

#125
post #13

Earlier quoted context omitted.

I used to do interviews for pentesters at an old job, and I was suprised as well. I think it's because CyberSecurity is relatively new, so companies have no idea how to hire for it, and end up hiring whoever can talk the best. I interviewed a lot of people with titles like "Senior Cybersecurity Engineer" who had no security knowledge beyond how to run an automated scan against an IP range, and put the findings it pri…

And yet here I am with half a decade actual experience in 'Cyber Security', can write passable Golang, C, C++, Python, hands on, real world knowledge and experience of threat actors and APT TTPs, for Blue team threat hunting, IDS/IPS signature creation, incident response... etc. And I can't even get a callback from any other company, because I don't check the "Bachelor degree required" box. Fucking, awesome.

Was curious to learn more about you, your website is nice, but the blog (blog.penguincoder.com) redirects to the main site (penguincoder.com), FYI.

Re: Thinking of a Cybersecurity Career?

#126
post #71

Earlier quoted context omitted.

> I don't care if you can explain SQLi to me Huh interesting. I work in infosec (but not a hiring person). I would normally rank this as an important skill. Not because i actually care about getting an explanation but because half the job is getting non security devs to care about security issues/fix them/not make them in the future. In my experience it is really difficult to do that if you can't explain the vulnerab…

I think you misunderstood. Almost anyone can tell you what sqli is, few can demonstrate an exploit. You need to be much closer to the latter than the former.

That's fair. Proof of concepts definitely get the point across better than a natural language explanation.

Re: Thinking of a Cybersecurity Career?

#127
post #14
post #9

Krebs does not work in Cybersecurity, does not come from a position of knowledge or experience in Cybersecurity and his only skill relating to Cybersecurity is doxxing people. I could understand if this was "Thinking of a Cybersecurity journalism career" but there are better people to learn from.

Perhaps instead of going after the author you could go after his ideas? It seems like quite a well written essay imo

Shall I do that for everyone who does not work in the industry they are advising people on?

Re: Thinking of a Cybersecurity Career?

#128
post #121

Earlier quoted context omitted.

Sort of. Pentests are a joke - a compliance activity and nothing more. As the client I get to pick the vendor, determine scope and influence the criticality of findings in the final report. Insurers don’t care about anything until you have a breach and a claim. They look to see whether you have the controls mandated in the policy and... Whether your attacker used a nation-state toolkit if so then they don’t have to p…

> Whether your attacker used a nation-state toolkit if so then they don’t have to pay. Definitely seen that one. I'm curious as to why an insurer wouldn't look at a bottom-tier pen-test for signs of gross negligence. They'll readily turn up things like failing to have authentication on key file shares, no access controls on the network, or no MFA in use. The sort of stuff that's easily exploited and shows utter negle…

Definitely agree. I just haven’t seen them (insurers) kick off an audit pro-actively without there being a breach.

I’m sure insurers understand that if they are proactive in auditing then a company will stay vigilant and probably patch all those old systems.

Re: Thinking of a Cybersecurity Career?

#129
post #125

Earlier quoted context omitted.

And yet here I am with half a decade actual experience in 'Cyber Security', can write passable Golang, C, C++, Python, hands on, real world knowledge and experience of threat actors and APT TTPs, for Blue team threat hunting, IDS/IPS signature creation, incident response... etc. And I can't even get a callback from any other company, because I don't check the "Bachelor degree required" box. Fucking, awesome.

Was curious to learn more about you, your website is nice, but the blog (blog.penguincoder.com) redirects to the main site (penguincoder.com), FYI.

Hey, thanks for the reply. My blog isn't ready for primetime yet, so I do have it redirecting to the main page for now.
Post reply on HN