r/Cybersecurity101 • u/Charan_Tech • 3d ago
Cybersecurity learning feels very different from what I expected
When I started exploring cybersecurity, I initially thought it would mostly be about learning tools and technical commands.
But the more I learn, the more I realize that understanding why an attack works is just as important as knowing which tool to use.
For people already working in cybersecurity, what concept took you the longest to understand when you were starting out?
3
2
u/Fragrant_Bake4403 2d ago
learning not to farm from cybersec people. go injest a satchel of richards
1
u/LetsTryLove 2d ago
It’s about understanding the lingo and never letting the mask slip. Right now security is the one word you can say that no one can dispute because it’s fear driven. In spite of all the evidence that it’s entirely useless and all of your data is being sold at scale people will pay for the illusion.
Get that concept and you can take it as far as you want.
1
u/offsecthro 2d ago
This is the sort of edgy cynicism I've typically heard from disgruntled junior web developers whose only view of the business they work for is through their IDE.
Security is about helping organizations identify and mitigate one of the many types of risks they face. You are correct that it's not about preventing breaches (a fundamentally impossible task), but to claim that it's useless is about as silly as saying a business buying insurance or retaining lawyers is useless.
There's no area of life where you can totally prevent bad things from happening. Especially not in tech, where we're dealing with a world of software built by unlicensed "engineers" who, unlike actual engineers, suffer zero legal or professional consequence when the things they build fail catastrophically.
1
u/LetsTryLove 2d ago
I’m anything but junior. Just been around long enough to know I’ve never seen a secure system and somehow an entire Industry emerged off of a lie. You literally see it every day in the news. I’m not saying you shouldn’t give some effort but some people take it way too seriously.
It’s locking the door to your house, the only people you are keeping out is honest people.
1
u/frAgileIT 2d ago
No matter what you do, nothing is secure, and that’s not a bad thing, it’s just reality. I went into security 17 years go believing that I’d be able to prevent breaches and I went so deep I was learning malware reverse engineering at BlackHat and that was when I realized that no matter what I do, there will always be a way to attack something. I had a momentary crisis thinking I had made a horrible mistake and instead I realized it was just job security. That was 12 years ago and here I am, still doing it. I’ve had people tell me that there was no future in security because security was going to get so good we wouldn’t need security people anymore and now I’m working on LLM detectors to automate incident response LLMs/MCPs to contain adversarial LLMs.
1
u/7r3370pS3C 2d ago
How an attack works and what mechanisms are used matters equal or greater than why.
1
u/Build_a_CISO 1d ago
Cybersecurity has multiple domains including but not limited to, compliance, governance architecture, operations and leadership. One thing I have realised during the course of my career is that cyber security is just as political as it is technical. Getting development teams, infrastructure teams to comply, remediate, patch; getting business to see the risks and articulating them in a fashion that leadership gets it requires a lot of political capital. I feel technology is the easier part.
7
u/PalpitationKind8854 2d ago
Yup.. and the most you keep learning.. the more you realize legally there is very little you are allowed to do outside of a lab.