Getting Started in (Cyber) Security
Key Takeaways:
Cyber security might seem like a newish field in IT, but it’s actually been around for 40+ years.
Most people in the cyber field have prior experience doing something else, mainly in the broader IT industry, such as a developer or systems engineer.
If you’re new to the field, focus on acquiring in-depth knowledge and understanding key security concepts and how to apply them to real-world scenarios.
With certifications, the more difficult/advanced certs are the most valuable.
Technical skills are only half the battle. Soft skills make up the other half.
Introduction
The cyber security industry may not seem that old, to me, it certainly doesn’t, but cyber security has been a thing since the 1970s when an ARPANET[1] developer named Bob Thomas created the first computer worm program known as “Creeper”[2] that switched from one computer to another by itself across all the PCs connected to the network.
Finding and removing a malicious program was the first task for the newly born cyber security field. It’s actually a really interesting timeline, and I would encourage anyone interested in cyber (or even technology more broadly) to go and read up on the history of cyber security and all the significant events that have taken place along the way right up to where we are now in 2023. Stuxnet[3] (2010), NotPetya[4] (2017), and the Shadow Brokers[5] (TSB) leaking NSA hacking tools (2017) are a few honourable mentions.
What I want to cover in this article is some tips for starting out in the cyber security field and provide some insights from my own experience, how I got into cyber security and some of the essential things I’ve learned along the way being on both sides of the fence, as a candidate and as hiring manager. Let’s get into it!
2011 - Where it all started (for me)
I got my first taste of IT security back in 2001 when I was in year 8 of high school. A group of friends and I figured out we could access the teachers' classroom guides and test sheets stored on the school's network over the server message block (SMB) protocol. All we needed to do was reboot the classroom computer into safe mode, which automatically logged in as the local system administrator, and we were good to go.
It was an exciting time to be playing with computers back then, and everything was clunky and pixelated compared to what we have at our fingertips today. But I would happily return to those days of WinAMP, IRC and MSN messenger, even if it was just for 15 minutes.
Years later, working in IT, I started out in technical support and systems administration (think of password resets, Windows Server 2003, Active Directory, and DHCP problems…etc.). I moved across to networking in 2011, where I configured and deployed firewalls and started controlling how network traffic (data) moves from point A to point B.
From a career perspective, this was the beginning of where security and, well, cyber security, as it’s widely referred to today, started becoming a part of my job function. I am fortunate to have had the opportunity to naturally progress throughout my career and gain the experience that has led me to where I am today. Still, I will say with absolute certainty that it didn’t happen without A LOT of self-study, late nights, and practice to get here.
But I Need Experience. Where Do I Start?
I’ve thought about this quite a lot recently because I have had a few people message me about this. Every other week I come across something on LinkedIn where someone is writing about how hard it seems to be to break into the cyber industry.
When I take a step back and try to look at what makes the most significant impact on being successful in cyber security, I think it comes down to three key things;
Knowledge
Ability
Soft Skills
Let me explain this in some more detail.
Knowledge
There’s a quote I love from Friedrich Nietzsche that goes like this; “He who would learn to fly one day must first learn to walk and run and climb and dance; one cannot fly into flying.”
This quote sums things up nicely regarding anything you want to do or who you want to become. To get anywhere, you need to start somewhere, and the best way to do that is by learning the basics and becoming familiar with topics like; Identity and Access Management (IAM), Security Operations, Network and Infrastructure Security, and Cloud concepts. Today, there are more than enough resources to help with this, thanks to the rise in online learning platforms like Udemy, Cybrary.it and many others.
Now, the basics, while serving as a mandatory first step, are just the start.
When focusing on knowledge with zero hands-on experience, I would advise you to take the theoretical learning as far as you possibly can—progressing onto more intermediate and advanced level certifications and courses. Challenge yourself to apply those foundation-level concepts and understand how these complex topics come together in different types of real-world scenarios.
The point I want to make here is to start small but progress far into the more intermediate/technical areas of cyber security. Focus on acquiring knowledge and understanding the key areas.
I’m a big advocate for vendor-neutral certifications as they target learning more towards the practical application of security to systems and data and not solely on a single implementation, which is where the vendors come in. That being said, it is a good idea to also look at the well-established and successful security vendors and consider getting certified in their products, as many organisations use their solutions. Having in-demand knowledge is a major advantage and extremely valuable.
Here are some security certifications that I highly recommend:
Vendor-neutral (ordered from beginner to advanced):
ISC2 Certified in Cybersecurity (CC)
CompTIA Security+
Certificate of Cloud Security Knowledge (CCSK)
Certified Information Systems Security Professional (CISSP)
Certified Cloud Security Professional (CCSP)
Vendor certifications to consider (no particular order):
Microsoft Azure Security Engineer Associate (AZ-500)
AWS Solution Architect Associate (SAA)
AWS Certified Security Speciality
GCP Professional Cloud Security Engineer (PCSE)
Palo Alto Network Certified Network Security Engineer (PCNSE)
Fortinet Certified Network Security Export - Level 4 (NSE4)
In addition to what I mentioned above, most organisations will be using two or more (sometimes a lot more!) security vendors for their in-house solutions so it is beneficial to have a solid understanding of various vendor products and how they work.
Ability
This is where the rubber meets the road. You’ve learned how to walk and run, and now we’re trying to climb and maybe dance a little (continuing with the Nietzsche theme). Ability is about putting your knowledge into action and demonstrating your understanding with some added proficiency.
It doesn’t always have to be about physically showing your skills, as in most cases with job interviews; you might be asked to elaborate on certain things, further prompting your level of understanding in a specific area. Ideally, you want to try and practice your understanding of security concepts in a simulated lab environment to complement and solidify your knowledge as you learn.
The big three cloud providers, Micrsoft[6], AWS[7] and GCP[8], all offer free trials (see the references section for the links to these) where you can sign-up and practice your skills with some allocated free credit (usually something between $200 to $300), or for 30-days before expiring.
As with everything, to master a skill, you need to practice it, and theory is a big part of the process. Still, to give yourself the best shot at landing a position in cyber security, you want to be comfortable and competent when applying security in a real-world scenario. Virtual lab environments are the best place to do this.
Soft Skills
If you have spent a great deal of time and effort and feel confident with the above two points, knowledge and ability, then I would say you can start submitting your resume to any company looking for a security administrator/engineer/analyst. Most of these positions will ask for 1-3 years of experience, but you can definitely get your foot in the door with the certifications I mentioned earlier and a practical understanding of key security concepts and solutions.
But this is where we conveniently arrive at soft skills. If knowledge and ability get your foot in the door, then proficiency in soft skills will get you the rest of the way through it.
I probably could have stopped short of making a point on soft skills, but I have seen promising candidates fall short too many times in this area to not mention it.
When I say soft skills, you might be asking, “which ones?” and this is a good question because there are a lot of different soft skills. It would be easy just to say “all of them,” but that’s a bit extreme if we’re focusing on landing a job in cyber security. So here are a select few soft skills that I feel would benefit your future cyber professional self.
Communication (no surprise here)
Critical-thinking
Problem-solving
Teamwork
Self-awareness
Time management
As you gain experience and start getting exposure to different areas in cyber security, having a good level of skill in each of these areas will serve you greatly as you progress in your career, and this applies to any job really, not just cyber! I won’t go into each of these individually, but I would encourage you to brush up on them if you feel you’re lacking in any of them.
Conclusion
In this blog, we have covered a (very) brief history of cyber security, dating back as far as the 1970s up until now. I have also covered some key focus areas that make a significant impact when trying to break into the competitive cyber security industry, especially when hands-on experience is hard to come by.
With the major technological developments and the increased sophistication and intensity of cyberattacks in recent years, the demand for skilled cyber security professionals has also significantly increased. This massive demand from the market isn’t currently being met, so there’s plenty of opportunity to invest in your career and future by leveraging the information I have provided to help get a solid start to becoming a cyber security professional.
References
[1] ARPANET. (2023, January 30). In Wikipedia. https://en.wikipedia.org/wiki/ARPANET
[2] Creeper and Reaper. (2023, February 22). In Wikipedia. https://en.wikipedia.org/wiki/Creeper_and_Reaper
[3] Stuxnet. (2023, March 24). In Wikipedia. https://en.wikipedia.org/wiki/Stuxnet
[4] Petya. (2023, March 24). In Wikipedia. https://en.wikipedia.org/wiki/Petya_and_NotPetya
[5] The Shadow Brokers. (2023, February 24). In Wikipedia. https://en.wikipedia.org/wiki/The_Shadow_Brokers
[6] Microsoft Azure Free-trial. https://azure.microsoft.com/en-us/free/
[7] Amazon AWS Free Tier. https://aws.amazon.com/free
[8] Google GCP Free-trial. https://cloud.google.com/free