<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Widespread Incompetence in the Cybersecurity Field? in Endpoint Security</title>
    <link>https://community.cisco.com/t5/endpoint-security/widespread-incompetence-in-the-cybersecurity-field/m-p/3917237#M1077</link>
    <description>&lt;P&gt;First, this post is not intended as that run-of-the-mill elitist "why isn't everyone as smart as me?" kinda post, but I do want a gut check.&lt;/P&gt;&lt;P&gt;I keep meeting "security professionals" who'd struggle to match the technical expertise of a help desk admin.&lt;/P&gt;&lt;P&gt;Cases:&lt;/P&gt;&lt;P&gt;1:&amp;nbsp;My company just brought on someone with a Master's in Cybersecurity from an online school, and had 10 years of experience working risk compliance for a prestigious government contractor. I got to talking with him and he didn't know what a VM was. No, I am not joking. There is plenty more to say about this person, but let's move on.&lt;/P&gt;&lt;P&gt;2:&amp;nbsp;I keep hearing security professionals bring up absurd concerns during meetings with management meant to determine how our budget is spent. Concerns like "if we allow speakers, they can be turned into microphones and steal keystrokes from our air-gapped devices." Yes, we've all read that article talking about that theoretical attack, but when actual pressing issues like {insert pretty serious vulns here} exist. They can't prioritize hypothetically NAC or MFA over expensive countermeasures for the latest scary Wired article.&lt;/P&gt;&lt;P&gt;3:&amp;nbsp;I meet otherwise highly credentialed people who struggle with basic IT concepts. What I will list here is more forgivable than the previous two, but still worth mentioning. Issues like not knowing theoretically how a DMZ is set up, not knowing the difference between a subnet and a VLAN, failing to understand the difference between giving someone limited admin rights vs giving every sysadmin domain admin, etc etc.&lt;/P&gt;&lt;P&gt;Let me make this clear: I am NOT talking about folks with less than 5 years experience. We should embrace our up and coming security professionals. But I feel like I am surrounded by people who have no business being in security who are there simply because organizations can't fill those roles with anyone else.&lt;/P&gt;&lt;P&gt;Thanks for reading my thing.&lt;/P&gt;</description>
    <pubDate>Fri, 21 Feb 2020 05:10:40 GMT</pubDate>
    <dc:creator>ryan45</dc:creator>
    <dc:date>2020-02-21T05:10:40Z</dc:date>
    <item>
      <title>Widespread Incompetence in the Cybersecurity Field?</title>
      <link>https://community.cisco.com/t5/endpoint-security/widespread-incompetence-in-the-cybersecurity-field/m-p/3917237#M1077</link>
      <description>&lt;P&gt;First, this post is not intended as that run-of-the-mill elitist "why isn't everyone as smart as me?" kinda post, but I do want a gut check.&lt;/P&gt;&lt;P&gt;I keep meeting "security professionals" who'd struggle to match the technical expertise of a help desk admin.&lt;/P&gt;&lt;P&gt;Cases:&lt;/P&gt;&lt;P&gt;1:&amp;nbsp;My company just brought on someone with a Master's in Cybersecurity from an online school, and had 10 years of experience working risk compliance for a prestigious government contractor. I got to talking with him and he didn't know what a VM was. No, I am not joking. There is plenty more to say about this person, but let's move on.&lt;/P&gt;&lt;P&gt;2:&amp;nbsp;I keep hearing security professionals bring up absurd concerns during meetings with management meant to determine how our budget is spent. Concerns like "if we allow speakers, they can be turned into microphones and steal keystrokes from our air-gapped devices." Yes, we've all read that article talking about that theoretical attack, but when actual pressing issues like {insert pretty serious vulns here} exist. They can't prioritize hypothetically NAC or MFA over expensive countermeasures for the latest scary Wired article.&lt;/P&gt;&lt;P&gt;3:&amp;nbsp;I meet otherwise highly credentialed people who struggle with basic IT concepts. What I will list here is more forgivable than the previous two, but still worth mentioning. Issues like not knowing theoretically how a DMZ is set up, not knowing the difference between a subnet and a VLAN, failing to understand the difference between giving someone limited admin rights vs giving every sysadmin domain admin, etc etc.&lt;/P&gt;&lt;P&gt;Let me make this clear: I am NOT talking about folks with less than 5 years experience. We should embrace our up and coming security professionals. But I feel like I am surrounded by people who have no business being in security who are there simply because organizations can't fill those roles with anyone else.&lt;/P&gt;&lt;P&gt;Thanks for reading my thing.&lt;/P&gt;</description>
      <pubDate>Fri, 21 Feb 2020 05:10:40 GMT</pubDate>
      <guid>https://community.cisco.com/t5/endpoint-security/widespread-incompetence-in-the-cybersecurity-field/m-p/3917237#M1077</guid>
      <dc:creator>ryan45</dc:creator>
      <dc:date>2020-02-21T05:10:40Z</dc:date>
    </item>
    <item>
      <title>Re: Widespread Incompetence in the Cybersecurity Field?</title>
      <link>https://community.cisco.com/t5/endpoint-security/widespread-incompetence-in-the-cybersecurity-field/m-p/3917272#M1150</link>
      <description>&lt;P&gt;I've been in IT for almost 40 years, most of that time having security as a primary or at least secondary role. I have worked in both public and private sectors - both on the end user and reseller side. In my experience there isn't any one specialty that suffers from a disproportionate share of less than fully-qualified individuals.&lt;/P&gt;
&lt;P&gt;There are a very high number (disproportionately so) of cybersecurity vacancies; so many organizations may be struggling with staffing those properly. It sounds you've had the unfortunate experience of interacting with low-performing or lesser qualified cybersecurity professionals. I can say from first hand experience that most of the ones I have dealt with have been doing their jobs to the best of their ability and often with great benefit to the organizations they serve.&lt;/P&gt;
&lt;P&gt;Whenever I come across someone who's making unwise choices or recommendations - be it in security or elsewhere - I do my best to inform the discussion with better-reasoned explanations and recommendations so that we collectively advance the status quo to a better place.&lt;/P&gt;</description>
      <pubDate>Sun, 01 Sep 2019 06:04:18 GMT</pubDate>
      <guid>https://community.cisco.com/t5/endpoint-security/widespread-incompetence-in-the-cybersecurity-field/m-p/3917272#M1150</guid>
      <dc:creator>Marvin Rhoads</dc:creator>
      <dc:date>2019-09-01T06:04:18Z</dc:date>
    </item>
    <item>
      <title>Re: Widespread Incompetence in the Cybersecurity Field?</title>
      <link>https://community.cisco.com/t5/endpoint-security/widespread-incompetence-in-the-cybersecurity-field/m-p/4123089#M5563</link>
      <description>&lt;P&gt;&lt;a href="https://community.cisco.com/t5/user/viewprofilepage/user-id/1077619"&gt;@dhanushxdhanushx29596&lt;/a&gt; why did you repeat the first paragraph of my earlier reply as your post?&lt;/P&gt;</description>
      <pubDate>Wed, 22 Jul 2020 02:03:39 GMT</pubDate>
      <guid>https://community.cisco.com/t5/endpoint-security/widespread-incompetence-in-the-cybersecurity-field/m-p/4123089#M5563</guid>
      <dc:creator>Marvin Rhoads</dc:creator>
      <dc:date>2020-07-22T02:03:39Z</dc:date>
    </item>
    <item>
      <title>Re: Widespread Incompetence in the Cybersecurity Field?</title>
      <link>https://community.cisco.com/t5/endpoint-security/widespread-incompetence-in-the-cybersecurity-field/m-p/4125993#M5568</link>
      <description>&lt;P&gt;Presumably so they could spam their link to MXPlayer, whatever that may be&lt;/P&gt;</description>
      <pubDate>Mon, 27 Jul 2020 10:46:24 GMT</pubDate>
      <guid>https://community.cisco.com/t5/endpoint-security/widespread-incompetence-in-the-cybersecurity-field/m-p/4125993#M5568</guid>
      <dc:creator>neil.woodhouse</dc:creator>
      <dc:date>2020-07-27T10:46:24Z</dc:date>
    </item>
    <item>
      <title>Re: Widespread Incompetence in the Cybersecurity Field?</title>
      <link>https://community.cisco.com/t5/endpoint-security/widespread-incompetence-in-the-cybersecurity-field/m-p/4126020#M5569</link>
      <description>&lt;P&gt;&lt;a href="https://community.cisco.com/t5/user/viewprofilepage/user-id/47417"&gt;@neil.woodhouse&lt;/a&gt; thanks - I didn't see that spam link earlier.&lt;/P&gt;
&lt;P&gt;Anyhow, it's not posted anymore - I sent the post to moderation limbo. &lt;span class="lia-unicode-emoji" title=":slightly_smiling_face:"&gt;🙂&lt;/span&gt;&lt;/P&gt;</description>
      <pubDate>Mon, 27 Jul 2020 11:35:07 GMT</pubDate>
      <guid>https://community.cisco.com/t5/endpoint-security/widespread-incompetence-in-the-cybersecurity-field/m-p/4126020#M5569</guid>
      <dc:creator>Marvin Rhoads</dc:creator>
      <dc:date>2020-07-27T11:35:07Z</dc:date>
    </item>
    <item>
      <title>Re: Widespread Incompetence in the Cybersecurity Field?</title>
      <link>https://community.cisco.com/t5/endpoint-security/widespread-incompetence-in-the-cybersecurity-field/m-p/4558760#M6696</link>
      <description>&lt;P&gt;The term "security professional" is too overloaded and broad. Do you want a software engineer who knows how to create secure applications? Do you want a risk/standards/compliance lead? Do you want an IT professional that knows how to keep infrastructure secure? Do you want someone in a SOC? Do you want someone to run a bug bounty program? Do you want a pen-tester that can hack the **bleep** out of your IoT product? do you want a pen-tester than can hack the **bleep** out of your infrastructure? All of these require different skillsets and different people. But they are all "cybersecurity professionals"&amp;nbsp;&lt;FONT size="1 2 3 4 5 6 7" color="#FFFFFF"&gt;&lt;A href="https://get-vidmate.com/" target="_blank"&gt;&lt;FONT color="#FFFFFF"&gt;vidmate&lt;/FONT&gt;&lt;/A&gt;&lt;/FONT&gt; &lt;FONT size="1 2 3 4 5 6 7"&gt;&lt;A href="https://instasave.onl/" target="_blank"&gt;&lt;FONT color="#FFFFFF"&gt;instagram&lt;/FONT&gt; &lt;FONT color="#FFFFFF"&gt;video download&lt;/FONT&gt;&lt;/A&gt;&lt;/FONT&gt;&lt;/P&gt;</description>
      <pubDate>Sat, 26 Feb 2022 06:14:43 GMT</pubDate>
      <guid>https://community.cisco.com/t5/endpoint-security/widespread-incompetence-in-the-cybersecurity-field/m-p/4558760#M6696</guid>
      <dc:creator>grahamvid</dc:creator>
      <dc:date>2022-02-26T06:14:43Z</dc:date>
    </item>
  </channel>
</rss>

