Live data from Hacker News

Cybersecurity Ventures predicts 3.5M cybersecurity job openings by 2021

cybersecurityventures.com

51–60 of 66 posts

Re: Cybersecurity Ventures predicts 3.5M cybersecurity job openings by 2021

#51
post #33

Earlier quoted context omitted.

Buying insurance might be the most cost effective strategy. If insurance of $2MM would cover your liability, why incur 3MM expenditures and still only be reasonably secure?

Cyber security insurance has liability caps, relatively low for the premiums. Standard boilerplate demands to hold such insurance in the US is around $1M liability coverage for small shops, usually gets quoted around $50K annual premiums. If you can even get underwritten at all. I have been able to negotiate those clauses away so far. Everyone is already trying to pass the buck (quite literally) on information securi…

>>> One possibility that might develop out of the standoff is customers pushing the liability onto Cloud vendors and washing their hands of the concern.

That would be good, the cloud is a lot more secure than everything self hosted or self developed.

Re: Cybersecurity Ventures predicts 3.5M cybersecurity job openings by 2021

#52
post #47

Earlier quoted context omitted.

> You can assign 100 students to develop a trojan for a week. At the end of the week, more than 90% of the software are detected as generic trojan by the antivirus. Probably because 90 of these 100 students have no idea how AV heuristics work and what the trivial tricks are to completely stomp them.

Some of them quickly realize that the AV is flagging all their binaries and they try to evade it. They will soon discover that it is far from trivial. Don't underestimate the students and don't underestimate the AV. The world is full of surprises.

I don't have to underestimate AV's because I know how they work, and tested myself how easy it is to bypass them. You either don't or you're employed by one and shilling here.

Re: Cybersecurity Ventures predicts 3.5M cybersecurity job openings by 2021

#55

Earlier quoted context omitted.

Cyber security insurance has liability caps, relatively low for the premiums. Standard boilerplate demands to hold such insurance in the US is around $1M liability coverage for small shops, usually gets quoted around $50K annual premiums. If you can even get underwritten at all. I have been able to negotiate those clauses away so far. Everyone is already trying to pass the buck (quite literally) on information securi…

>>> One possibility that might develop out of the standoff is customers pushing the liability onto Cloud vendors and washing their hands of the concern. That would be good, the cloud is a lot more secure than everything self hosted or self developed.

Is that always true?

If you're doing heavy R&D and you keep things on isolated networks, might not your R&D be at least similarly secure on-premises, if you follow secure practices?

How much visibility do you have into your cloud provider's security? For email, sure go with a known cloud provider. Some SaaS services on the back-end can be less than ideally secure.

Re: Cybersecurity Ventures predicts 3.5M cybersecurity job openings by 2021

#56
post #31

Earlier quoted context omitted.

> I won a free certification course as an EC-Council Certified Security Analyst, and it's the biggest joke I've ever seen. It's such a massive fucking joke that I decided to not even renew my certification for free because it would just have been a waste of time. I've been in the field for a couple of years. I work for a global corporation with 10k+ employees and most of our team members in the security department ar…

>Care to explain why you think intrusion detection is bullshit? If they're signature based they're not better than antivirus. I have zero faith in signature based systems. For the stuff that uses machine learning, I have to admit, I have no idea how that stuff performs. But in general I wouldn't trust a machine learning model to not be fooled. Edit: Add to that HTTPS, I don't buy any claim that they can spot malware…

> For the stuff that uses machine learning, I have to admit, I have no idea how that stuff performs

That's ok.

You're in good company with the vendors who sell ML cybersecurity appliances.

Re: Cybersecurity Ventures predicts 3.5M cybersecurity job openings by 2021

#57
post #42

Earlier quoted context omitted.

I have NEVER heard a useful description by a cybersecurity analyst (i.e. detecting intrusions and exfiltration) on how they do their work, despite being in a position where they should have been able to do so. Usually I just get shrugged shoulders.

I have no trouble conjuring a job description for a "cybersecurity analyst"; I assume their job consists of: 1. Staffing an event management system (probably something with a pretty console that is 1/5th as powerful as an ELK deployment but that costs 10x as much because Security) and investigating alerts. 2. Kicking off routine scanning processes and reviewing the results generated by them. 3. Responding to requests…

[deleted]

Re: Cybersecurity Ventures predicts 3.5M cybersecurity job openings by 2021

#59
post #52

Earlier quoted context omitted.

Some of them quickly realize that the AV is flagging all their binaries and they try to evade it. They will soon discover that it is far from trivial. Don't underestimate the students and don't underestimate the AV. The world is full of surprises.

I don't have to underestimate AV's because I know how they work, and tested myself how easy it is to bypass them. You either don't or you're employed by one and shilling here.

This crosses into personal attack, which is not allowed here. Please read https://news.ycombinator.com/newsguidelines.html and follow the rules when commenting here.

Re: Cybersecurity Ventures predicts 3.5M cybersecurity job openings by 2021

#60

Earlier quoted context omitted.

Cyber security insurance has liability caps, relatively low for the premiums. Standard boilerplate demands to hold such insurance in the US is around $1M liability coverage for small shops, usually gets quoted around $50K annual premiums. If you can even get underwritten at all. I have been able to negotiate those clauses away so far. Everyone is already trying to pass the buck (quite literally) on information securi…

>>> One possibility that might develop out of the standoff is customers pushing the liability onto Cloud vendors and washing their hands of the concern. That would be good, the cloud is a lot more secure than everything self hosted or self developed.

It’s team- and manager-dependent. I’ve seen good and bad security in cloud and on-prem. The key is management recognizes and budgets for the fat tail risk, just like the fat tail risk of financial fraud is treated by the finance teams. Much of the response is proforma, and only intended to secure from drive-by opportunistic raids, and insider attacks are still difficult to defend against, for example, so no silver bullets in this story.
Post reply on HN