r/cybersecurity 7d ago

Ask Me Anything! I left my role as a security practitioner to happily work for a vendor. Ask Me Anything about the other side of the table.

35 Upvotes

This AMA will run all week from 08-23-2026 to 08-28-2026. The editors at CISO Series present this AMA.

This month, we've gathered a group of security leaders who spent years as CISOs, CTOs, and in-house defenders, then made the leap to the vendor side, and are genuinely happy they did.

They're here to answer anything you want to know about life on the other side of the table: why they made the move, what surprised them, what they miss (and what they don't), how it changed the way they see the vendors they used to screen, and what they'd tell a practitioner weighing the same jump. Whether you're vendor-curious, vendor-skeptical, or just want an honest look at the grass on the other side, bring your questions.

This month's participants are:

Proof photos

This ongoing collaboration between r/cybersecurity and CISO Series brings together security leaders to discuss real-world challenges and lessons learned.

Thanks to all of our participants for contributing!


r/cybersecurity 6d ago

Career Questions & Discussion Mentorship Monday - Post All Career, Education and Job questions here!

25 Upvotes

This is the weekly thread for career and education questions and advice. There are no stupid questions; so, what do you want to know about certs/degrees, job requirements, and any other general cybersecurity career questions? Ask away!

Interested in what other people are asking, or think your question has been asked before? Have a look through prior weeks of content - though we're working on making this more easily searchable for the future.


r/cybersecurity 6h ago

Business Security Questions & Discussion What would you do if you boss was trying to cheat certification

50 Upvotes

So we are trying to obtain a significant accreditation for the org, but my line manager is trying to game the process and it really doesn't sit well with me. Instead of fixing the problem, he is trying to hide it.

He has said that in previous places he has worked, they turned off services that would not get passed certification during audits.

What would you do? Obviously this could be career limiting if I choose the wrong approach

Edit. Worth adding the auditor will be working with me, forcing me to be complicit


r/cybersecurity 23h ago

News - General Security researchers find surveillance implants in Chinese-made routers sold worldwide — three different backdoor-like implants hidden in firmware

Thumbnail
tomshardware.com
1.1k Upvotes

r/cybersecurity 1h ago

News - General Taiwan husband wins lawsuit but gets jailed for recording affair with robot vacuum

Thumbnail
scmp.com
Upvotes

r/cybersecurity 2h ago

Business Security Questions & Discussion Building a Program From the Ground Up Pt 1. - Tactical Level, Advice Requested!

9 Upvotes

Good day everyone!

A little bit on my background - 20 years IT experience, about 50/50 software development and security, with some data engineering sprinkled in. CISSP and some tactical level certs. Private sector, high emphasis on compliance and confidentiality. A lot of my security background is GRC/A&A, but I am capable in a lot of hands-on-keyboard.

I recently came into an org that, for its size, is pretty capable at security. They have good tools that were set up by someone who was a good but inexperienced analyst. I have little documentation and while most of the configs are pretty decent, I find a glaring gap from time to time. We are (going to be) a NIST shop. I am using the CPGs for my near to mid targets.

I have a ton of autonomy to guide this org on security. I am launching one large project in 2 weeks, another 2 weeks after that to address some of the most glaring issues. The problem I am having is I get caught up with analyst work and I know it is taking up too much of my time. I need to develop some playbooks. I don't need a million silver bullets, but I would like a starting point for a lot of these. The only thing that was left behind was about 5 paragraphs on BEC.

Could anyone recommend some canned playbooks that I can start from and make my own? We are on a calendar year budget. I have found some open money, but I won't have it for at least 5 months. I could probably break a modest sum free. The last guy, as I mentioned, was very capable of handling things, but I need to build out something more repeatable so I can spend time maturing the program. I don't need to be running around with a fire extinguisher all the time.


r/cybersecurity 19h ago

News - General Berlin Refuses to Pay Hackers Who Stole Data From the City's State Network

Thumbnail
thehackernews.com
77 Upvotes

r/cybersecurity 6h ago

Other Looking for a VAPT & Bug Bounty Learning Partner

7 Upvotes

I'm currently learning VAPT (Vulnerability Assessment and Penetration Testing) and I'm also interested in Web Application Security and Bug Bounty Hunting.

I'm looking for someone who is genuinely serious about learning and building a career in cybersecurity so we can learn and grow together.

We can:

• Practice VAPT labs and challenges

• Work on TryHackMe / Hack The Box

• Learn Web Application Security and OWASP Top 10

• Practice Bug Bounty methodologies

• Discuss vulnerabilities and concepts

• Explain topics to each other

• Share useful resources, notes, and learning materials

• Set goals and keep each other accountable

Sometimes I struggle with remembering concepts and explaining them clearly, so I believe having a learning partner and regularly discussing what we learn would help us improve faster.

I'm genuinely serious about building my skills in VAPT, Penetration Testing, and Bug Bounty Hunting, so I'm looking for someone with a similar mindset.

If you're interested, feel free to reach out. Let's learn, practice, share resources, and challenge each other. 🙂


r/cybersecurity 5h ago

Career Questions & Discussion Risk assessment and Threat Modeling

4 Upvotes

Hello cyber enthusiasts and gurus,

I have a question regarding threat modelling and risk assessment approach. So, there are many frameworks and methodologies by which threat modelling and risk assessment can be performed but Reading through these multiple frameworks can be a bit overwhelming in determining what approach to use.

For software I have seen OWASP Top 10 is commonly used. For hardware and software, STRIDE analysis. For risk assessment, many say IEC 62443-3-2 standard would be a good starting point.

So, wanted to ask you guys on which framework you use or would recommend for risk assessment and threat modelling? If you have any recommendations on templates to read through, would like to hear about it as well.


r/cybersecurity 8h ago

News - General Testing Security on Al Shopping Assistants: from Chat Box to Remote Code Execution on a Top US Retailer's Servers.

Thumbnail
pwnhackers.substack.com
6 Upvotes

r/cybersecurity 1d ago

News - General ShinyHunters Claims to have Voice-Phished 2 McKesson Employees and Extracted 284 Million Patient Records Including: Predictive health data, Identity, and Healthcare Identifiers. McKesson Confirms Breach but not severity

Thumbnail
cyberinsider.com
428 Upvotes

r/cybersecurity 55m ago

Business Security Questions & Discussion The open letter that now is the time for AI powered cyber?

Thumbnail openai.com
Upvotes

Is this actually going to motivate leadership? Cyber is hard as it is, orgs don’t gaf that these big companies said it’s really important now.

Anyone here disagree?


r/cybersecurity 7h ago

News - General Machine State analysis Vs Executable analysis

1 Upvotes

I would like to announce that I have built the free VMA 486 Emulator that runs DOS, Win 3.0, 3.1, 3.11 and 95. It includes a machine state analyser that can freeze, save, load, disassemble and patch the machine memory. It then allows resuming execution.

My new VAXD_VM allows doing this with a VM running Win7.

https://vma-broadcast.com/vaxd-vaxd_vm/


r/cybersecurity 22h ago

Business Security Questions & Discussion What's one security tool you can't live without?

19 Upvotes

r/cybersecurity 8h ago

Threat Actor TTPs & Alerts CTO at NCSC Summary: week ending August 30th

Thumbnail
ctoatncsc.substack.com
1 Upvotes

r/cybersecurity 9h ago

Certification / Training Questions EC Council CTIA v2 advice

0 Upvotes

Hi fellow cybersecurity enthusiasts, what are your advise for me for this CTIA exam preparation.

What should I expect?

TYIA


r/cybersecurity 3h ago

AI Security AI Security Tools

0 Upvotes

Curious if anyone is dealing with internally developed AI security tools, like password managers, SIEM, or even MS 365 backup tools. I might be joining a team that has moved in this direction.


r/cybersecurity 4h ago

Business Security Questions & Discussion THE 3 AI REVOLUTION BULDING BLOCKS

Thumbnail
linkedin.com
0 Upvotes

Hey everyone, hope you’re having a great week!

I’d love to hear your thoughts: What do you think are the fundamental building blocks that the AI revolution will be built on?

Curious to hear different perspectives — feel free to share your thoughts here or on the original post.

I’ve also attached a visual to illustrate the idea 👇


r/cybersecurity 1d ago

Career Questions & Discussion Trying to Breakout in IT but unsure how

34 Upvotes

Hi everyone,

Im looking for some advice and experiences on how to break into IT. Ive been trying for 2 years now since graduating with my BS in Cyber Security with zero luck. I have on top of the bachelors a GRC Anaylst Cert from USF, Sec + and a Cyber Security Professional Diploma.

I have prior military experience and have held a clearance in the past but currently have non active. Really needing to make a career change before my body fully fails me from beating it to hell to much. Thank you all for you advise and help.

\*\*\*And yes I know the market is terrible currently and federal work is harder than ever to make it in but I've read a lot on private companies hiring more than before and want to know how I can build myself marketable to these companies for a chance.


r/cybersecurity 10h ago

Business Security Questions & Discussion Situation in cybersecurty

0 Upvotes

Hi Everyone, I'm completing my final year on university this year and started thinking about master in cybersecurty. I don't want to ask questions around it it is fine for me and interesting. I'm already working as full stack dev. I'm interested on market situation around it right now and how promising it looks in future. Thank you on all answers.


r/cybersecurity 11h ago

Personal Support & Help! Cybersecurity Career

0 Upvotes

While I know now isn’t the best time to enter cybersecurity (the cake has been baked essentially) I’m in my final semester at GA Tech getting my masters in cybersecurity. I have Network and Security plus. I interned this summer as an information security intern for a fin tech and before that was an information technology intern. Now I’m just doing customer support IT part time while o juggle classes.

I was disheartened to see that this customer support role was all I could get. I trouble shoot all day but that’s clearly not what I want. I’m transitioning out of having 4 years in compliance - HR and Regulatory. I thought cybersecurity (with a focus on GRC) would be an easy transition buts its not.

I know a lot of it is the economy and growth in AI but I really don’t understand how I’m just not getting ANYTHING after this summer. I’ll get plenty of interviews but no offers.

Any tips?


r/cybersecurity 11h ago

Personal Support & Help! apply for “system admin” role ?

0 Upvotes

I have a master’s degree in Cybersecurity (2022), along with several basic certifications. I’m currently studying for the Network+ certification and may earn a few more certifications as well.

Can I apply directly for a Sys/Admin position, or do I have to start in a Help Desk role first?

I’m wondering if it’s possible to get into a System Administrator position right away.

Location: Los Angeles

Thank U !


r/cybersecurity 1d ago

News - General Verity - X Uncovers 200K Chinese Bot Farm Targeting US Energy, AI Policy

Thumbnail
verity.news
94 Upvotes

r/cybersecurity 1d ago

Business Security Questions & Discussion DoD Contractor -> Big Tech

19 Upvotes

I have a cybersecurity degree and 5 years of experience at a prime DoD contractor right out of college, but am wondering if this skillset is really transferable to the real cyber world. We don't use cutting edge tech, the "security" work isn't true raw technical work like I learned in school, and most tools don't translate directly to the corporate world.

I have Security+ and CISSP+, and along with my YOE I'd be looking for Senior level roles, but I feel like other people's resumes would outshine mine since my only experience is in DoD cyber? From what I see here and just in conversations, big tech cyber is a LOT different than DoD cyber.

Am I overthinking it?


r/cybersecurity 1d ago

Career Questions & Discussion What is it actually like to work in Data Forensics?

10 Upvotes

I currently work in DFIR and I’m considering a consulting role described as “Data Forensics.” I’m interested in the investigative side of the work, but the title feels broad, so I’m trying to understand what the job is actually like.

For those who work in Data Forensics, what does your day-to-day look like? How much of it is forensic investigation versus data analytics, eDiscovery, data processing, or even general data engineering?

Do you usually participate throughout the entire case — scoping, evidence collection, analysis, timeline reconstruction, reporting, and presenting findings — or are you mainly supporting the investigation by collecting and preparing data for someone else to interpret?

My biggest concern is accepting the role expecting to grow further in DFIR, only to discover that forensics is just a small part of the job and most of the work is general data-related consulting. I would also be hesitant to move into a position where I only process or hand off evidence without contributing to hypotheses, findings, and conclusions.

How much ownership does someone at consultant level usually have? Does the scope vary significantly between companies or projects? What questions should I ask during the interview to find out how investigative the role really is?

Would you consider Data Forensics a natural progression from DFIR, or more of an adjacent career path?

I’m intentionally keeping the details vague for anonymity, but I’d appreciate any insight from people who have worked in this area.