Live data from Hacker News

I quit infosec and I couldn't be happier

paulsec.github.io

121–130 of 175 posts

Re: I quit infosec and I couldn't be happier

#121
post #89

Earlier quoted context omitted.

Average tenure for a CISO is lowest of any C suite. You will likely take the hit in the event of a security incident and be fired. Tedious work. What to do is often obvious. Getting everyone to do it is the hard part and usually devolves into politics. Thankless job, you can only be wrong once. Just not appealing and CISO is becoming legally sketchy, requiring a lot of diligence out of a CISO to not end up in legal t…

> Average tenure for a CISO is lowest of any C suite. Do you have any stats to support this statement? I work as a Information Security Officer, other firms have BISOs or other names for this kind of position. Additionally, a lot of what you are describing is either cliché ("you can only be wrong once"), only true for certain types of businesses or regions. There have been examples where CISOs have experienced legal…

There's a reason the role is often referred to as the Chief Sacrificial Officer...

Re: I quit infosec and I couldn't be happier

#122
post #112
post #89

Earlier quoted context omitted.

> Average tenure for a CISO is lowest of any C suite. Do you have any stats to support this statement? I work as a Information Security Officer, other firms have BISOs or other names for this kind of position. Additionally, a lot of what you are describing is either cliché ("you can only be wrong once"), only true for certain types of businesses or regions. There have been examples where CISOs have experienced legal…

BISO and CISO are generally not the same. A BISO function tends to be an interface between information security and business units.

That is certainly true. I was trying to point out that I am indeed not working as a CISO, but as an ISO or a BISO. :)

Re: I quit infosec and I couldn't be happier

#124

Earlier quoted context omitted.

Average tenure for a CISO is lowest of any C suite. You will likely take the hit in the event of a security incident and be fired. Tedious work. What to do is often obvious. Getting everyone to do it is the hard part and usually devolves into politics. Thankless job, you can only be wrong once. Just not appealing and CISO is becoming legally sketchy, requiring a lot of diligence out of a CISO to not end up in legal t…

> Average tenure for a CISO is lowest of any C suite. You will likely take the hit in the event of a security incident and be fired. As far as I can tell, this is the actual purpose of a CISO: being the sacrificial goat when an entity experiences a security event that ends up in the news. I say this without any sarcasm.

> As your company's CISO, the most unkind yet accurate adjective people will ever apply to me is "ablative."

For Corey Quinn's fantastic "security awareness training" thread: https://infosec.exchange/@Quinnypig@awscommunity.social/1097...

Re: I quit infosec and I couldn't be happier

#125

Earlier quoted context omitted.

Millenials still had cause to buy into the Regan-era story of hard work and hyper capitalism leading to a glorious future for the common person. Zoomers have never been able to buy into that lie because they were born into a world where it is so obviously untrue.

Zoomers aren't even old enough to determine that yet. They're in their early 20's at most and no one that age has the experience to definitively say anything regarding this. The alternative to hard work is doing nothing and that certainly will get you no where at all. The idea that a younger generation might have had it slightly better (which I think is pretty subjective anyway, previous generations have all had thei…

> The alternative to hard work is doing nothing and that certainly will get you no where at all.

This is a false dichotomy. I put in a solid 40-50 hours at work. If I have to put in double that just to stand a shot -- not get, but have a shot at -- the lifestyle that my parent's had while only putting in 40 hours a week, then the system has failed me.

And that was 40 hours a week with one person working and the other staying at home.

No one is suggesting you get to have stuff for free, but it is painfully clear that even with dual incomes the average American is failing to maintain their parents' standard of living.

It's a broken system, and the Zoomers can easily see that -- they've had smartphones since they were like 8.

Re: I quit infosec and I couldn't be happier

#126

"Quitted", srsly? Yeah, blow my karma idk

Even if English is the lingua franca of the world, people master it to varying degrees. Also, it seems like 'quitted' was the more common form up until the ~late 1930s [1], so it's not entirely unreasonable to assume that, if this person learned with some vintage material or they read classics, they've seen 'quitted' more often.

[1] https://books.google.com/ngrams/graph?content=had+quitted%2C...

Re: I quit infosec and I couldn't be happier

#127

I had watched a few courses on information security and noticed that those working in the more management / corporate related infosec roles seemed to be massively overweight, almost all of them (I am too, btw). Not saying that to shame anyone, just: Does the job make you miserable or stressed out? I have been forced to do the infosec role as a "side thing" in a couple of jobs now, mainly because nobody else was aroun…

I'm very interested in security vulnerabilities and clever hacks. Because of that I thought I'd be good in a security role. Then I discovered that defending against security problems is awful.

The biggest security weaknesses are people. Employee get socially engineered or phished. Management doesn't take security seriously so they put only a tiny budget toward security. Lazy sysadmins don't keep their systems patched. Software developers can't be bothered to learn how to write secure software, and this is mostly because their bosses don't incentivize them to. Security vendors often hype up their snake oil products. Good security protocols and technologies aren't adopted because people don't want to change.

Dealing with these human problems is awful, demoralizing, and generally unsolvable.

Re: I quit infosec and I couldn't be happier

#128

> The main warning I might just give to people is to keep proper distances between work and personal life I've been thinking about this a lot lately. As a millennial, I've tied so much my self-worth into my career and recently, started questioning this belief and I think the next generation (i.e. Gen Z) might be on to something around quiet quitting, their generation placing extra emphasis on pursuing things that mak…

The leading edge of Gen Z has taken to concepts like quiet quitting, but they still seem to have tied their personal lives to their jobs, often having few physical world friends outside of the workplace and still falling for the "we're a family" line, even if now they want to play to part of kid who doesn't take out the trash if their allowance isn't high enough (which it might not be). Doubt that's healthy and seems a lot like the recreation of a dysfunctional family.

Re: I quit infosec and I couldn't be happier

#129

I had watched a few courses on information security and noticed that those working in the more management / corporate related infosec roles seemed to be massively overweight, almost all of them (I am too, btw). Not saying that to shame anyone, just: Does the job make you miserable or stressed out? I have been forced to do the infosec role as a "side thing" in a couple of jobs now, mainly because nobody else was aroun…

I manage a monitoring and ir team and am obese. I tend to stress eat and there is a lot of stress playing defense all the time.

If you prevent all the security threats, nobody notices, and the bosses wonder why they even pay you. If a security issue gets through, the bosses wonder why they even pay you.

Re: I quit infosec and I couldn't be happier

#130

> The main warning I might just give to people is to keep proper distances between work and personal life I've been thinking about this a lot lately. As a millennial, I've tied so much my self-worth into my career and recently, started questioning this belief and I think the next generation (i.e. Gen Z) might be on to something around quiet quitting, their generation placing extra emphasis on pursuing things that mak…

The success of this approach hinges on the assumption that no one else is doing it. However, even those who quietly quit still rely on others to provide the goods and services they desire. There is a concern that this could lead to a snowball effect and result in food scarcity and famine, but the timeline for such an outcome is uncertain.

In terms of adding extra items to improve their happiness, it appears that this strategy is generally ineffective. Despite their efforts, the quiet quitters I met do not appear to be any happier

Post reply on HN