shellsharks

joined 2 years ago
MODERATOR OF
3
Off-Topic Friday (self.cybersecurity)
submitted 6 months ago by shellsharks to c/cybersecurity
 

Wanna chat about something non-infosec amongst those of us who frequent /c/cybersecurity? Here’s your chance! (Keep things civil & respectful please)

 

Weekly thread to discuss whatever you’re working on, big or small, at work or in your free time.

 

Weekly thread for any and all career, learning and general guidance questions. Thinking of taking a training or going for a cert? Wondering how to level up your career? Wondering what NOT to do? Got other questions? This is the time and place to ask!

8
Off-Topic Friday (self.cybersecurity)
submitted 6 months ago by shellsharks to c/cybersecurity
 

Wanna chat about something non-infosec amongst those of us who frequent /c/cybersecurity? Here’s your chance! (Keep things civil & respectful please)

 

Weekly thread to discuss whatever you’re working on, big or small, at work or in your free time.

4
Off-Topic Friday (self.cybersecurity)
submitted 7 months ago by shellsharks to c/cybersecurity
 

Wanna chat about something non-infosec amongst those of us who frequent /c/cybersecurity? Here’s your chance! (Keep things civil & respectful please)

 

Weekly thread for any and all career, learning and general guidance questions. Thinking of taking a training or going for a cert? Wondering how to level up your career? Wondering what NOT to do? Got other questions? This is the time and place to ask!

5
Off-Topic Friday (self.cybersecurity)
submitted 7 months ago by shellsharks to c/cybersecurity
 

Wanna chat about something non-infosec amongst those of us who frequent /c/cybersecurity? Here’s your chance! (Keep things civil & respectful please)

 

Weekly thread for any and all career, learning and general guidance questions. Thinking of taking a training or going for a cert? Wondering how to level up your career? Wondering what NOT to do? Got other questions? This is the time and place to ask!

6
Off-Topic Friday (self.cybersecurity)
submitted 7 months ago by shellsharks to c/cybersecurity
 

Wanna chat about something non-infosec amongst those of us who frequent /c/cybersecurity? Here’s your chance! (Keep things civil & respectful please)

 

Weekly thread to discuss whatever you’re working on, big or small, at work or in your free time.

 

Weekly thread for any and all career, learning and general guidance questions. Thinking of taking a training or going for a cert? Wondering how to level up your career? Wondering what NOT to do? Got other questions? This is the time and place to ask!

[–] shellsharks 4 points 1 year ago
[–] shellsharks 1 points 1 year ago

Good luck getting those new resources/headcount!

[–] shellsharks 2 points 1 year ago

My favorite classic Nintendo games - https://shellsharks.com/notes/2011/07/07/favorite-nintendo-games

Not listed there are gameboy games. I mostly just played the various Pokémon games and Final Fantasy Legends.

[–] shellsharks 1 points 1 year ago

CIS Critical Security Controls and/or NIST CSF as frameworks to help put you in the right mindset. But so much of what you should do first depends on some variables imo.

  • What is your budget?
  • What already exists security-wise at your company?
  • What level of executive support do you have? Can you enact real change?
  • What is most important to the company? i.e. "Crown Jewels"
  • What does the network/infrastructure/endpoint environment look like?

Once you answer these questions then you can get a better idea of where to spend the limited time/money you have. The CSC will likely tell you to tap into an inventory and do some form of Vulnerability Management. This is a decent idea as you need to know what you are trying to protect and also catch low-hanging fruit via vuln scanning. Instrumenting endpoints (EDR) or gaining visibility into your infra is also important but which do you pick first? Crowdstrike is awesome but expensive. No one solution is a silver bullet.

Have a plan, create a reasonable roadmap, figure out your companies risk threshold, ask for more resources depending on what level of risk they're willing to accept and how quickly they want things implemented.

[–] shellsharks 2 points 1 year ago (1 children)

Oh cool. I've been thinking of getting one too. But I already have too many projects and too much work and not enough time 😩 (not that that's ever stopped me from buying stuff before...). Where do you write?

[–] shellsharks 4 points 1 year ago

Another part of my Lemmy <--> Mastodon experimentation. The Fediverse is cool but it is also a little confusing 😅

[–] shellsharks 2 points 1 year ago (1 children)

What field is it?

[–] shellsharks 1 points 1 year ago (1 children)

What are you normally up to?

[–] shellsharks 2 points 1 year ago

I haven't been looking so I can't speak with first-hand xp. From others accounts on socials it seems like it's kinda rough but everyone has different experiences. Good to hear some potentially optimistic news for a change though so I'll take it.

[–] shellsharks 12 points 1 year ago

Be young. Young folk never sore

[–] shellsharks 4 points 1 year ago (1 children)

Complaints are more than welcome. and omg yes I've seen this happen before. Typically a result from ONE bad interaction with ONE engineer/analyst who messed something up and now everyone has to be babied 🙄.

[–] shellsharks 2 points 1 year ago (2 children)

On one hand, the market is such that it might be too much work / too depressing to passively hunt for a plan B. On the other, it's probably good to have an idea of what a plan B could be...

view more: ‹ prev next ›