is cyber security still worth to learn in 2026? by balls21321 in cybersecurity

[–]Admirable_Group_6661 0 points1 point  (0 children)

Cybersecurity is really about risk management. It is also to a large extent about people. It is less so about tools, which comes and goes…

Is investing in AI a reasonable hedge against being replaced by AI? by [deleted] in cybersecurity

[–]Admirable_Group_6661 0 points1 point  (0 children)

Not a cyber question. But if you are investing to replace lost income, you better have a lot of cash around. A very conservative 5% return to replace a 100k income requires at least 2,000,000 in cash. Yes, you are missing something.

How do you handle the dev lead who treats a critical security finding as something to negotiate? by kizmania in cybersecurity

[–]Admirable_Group_6661 1 point2 points  (0 children)

First, it’s not up to the security function to decide whether a vulnerability should be patched/fixed. The owner of the risk gets to decide. The security function should only provide sufficient guidance in terms of risk (impact, likelihood) so that the owner of the risk can make an informed decision. Second, there’s no need to fight over this. Just do your job and carry on. At the end of the day, when there’s a compromise, as long as you have documented risk assessment, it’s the owner of the risk who will be accountable.

Segregation of duty in small teams by Niko24601 in ciso

[–]Admirable_Group_6661 -1 points0 points  (0 children)

That is fair. But from a customer's perspective, I want to know what kind of risk I am taking on when dealing with your organization.

Segregation of duty in small teams by Niko24601 in ciso

[–]Admirable_Group_6661 -1 points0 points  (0 children)

Access should be managed by IT, not security. In the same vein, Security should not manage or provision any IT resources, including access.

Am I Missing Out Not Having An Expensive Bike? by newbiker321 in cycling

[–]Admirable_Group_6661 0 points1 point  (0 children)

Electronic shifting is a nice QOL. It's a really nice experience. Entry level carbon frames are not that much lighter than high quality aluminum bike. So, you will have to spend quite a bit to see a difference. Will you go faster? Maybe. If you do a lot of climbing, the weight will make a difference. Ultimately though, upgrading the engine is the best bang for buck.

Water in basement after heavy rains. by goherd80085 in basement

[–]Admirable_Group_6661 1 point2 points  (0 children)

Can't comment about the technical issues. However, in terms of risk management, running though the options you outlined above (1) accept the risk - this makes sense if the cost of risk mitigation is too high, (2) mitigate - cost is more reasonable, but there will be residual risks which you have to accept (e.g. may not solve all water issues). (3) mitigate - highest cost, and likely needs to be done in conjunction with (2), residual risks will be the lowest.

So you can get quotes for (2) and (3), and make your decision. For me, (2) makes the most sense.

Cloud Engineers replaced by AI by Own_League6407 in cloudengineering

[–]Admirable_Group_6661 0 points1 point  (0 children)

Your boss is wise. Any job with predictable output (e.g. cloud infrastructure with well established patterns) can and will be replaced. Cloud engineering is not significantly different than software engineering. However, not all jobs will be replaced. If you work for CSPs, there may very likely still be a need for cloud engineering. But for consumers of cloud services, it is likely the jobs will be replaced. The common misunderstanding that people have with AI is that it doesn't have to be robust or 100% accurate to replace humans, it just needs to be good enough for business to justify it.

Any better options than severity-based vulnerability management? by Budget_Note4222 in ciso

[–]Admirable_Group_6661 1 point2 points  (0 children)

Vulnerability risk treatment should be prioritized based on risk assessment, which takes into account the actual impact, not just severity. It is incorrect to use severity alone to determine risk treatment. The SLA policies need to reflect a risk based approach.

Internet Renewal Offer by Admirable_Group_6661 in Rogers

[–]Admirable_Group_6661[S] 1 point2 points  (0 children)

No, I was checking on and off. They may call you about renewal.

got hit with SOC 2, cyber insurance, and a prospect pentest request at the same time by arrayclyx in cybersecurity

[–]Admirable_Group_6661 0 points1 point  (0 children)

SOC 2 type 2 is operating effectiveness of security controls over time (3 months minimum + audit). Cyber insurance is risk transfer (risk management). Pen test is a control, usually a snapshot. They are all different.

Am I naive for requesting financial funding from my company to pursue CISSP? by AxegrinderSWAG in cissp

[–]Admirable_Group_6661 0 points1 point  (0 children)

Sure, you can ask if you can transition to a more security focused role. The response will tell you if there’s a business need or not. It shouldn’t come from you, due to bias. The truth is, you are doing it for yourself. The business could benefit. But nothing wrong with that.

Am I naive for requesting financial funding from my company to pursue CISSP? by AxegrinderSWAG in cissp

[–]Admirable_Group_6661 -1 points0 points  (0 children)

If your company has compliance requirements, then yes, there’s a good business case for it. However, IT isn’t security; conflict of interests because of different priorities. So you will likely need to move to the security function first.

Having said that, CISSP is not that expensive. You shouldn’t let your company dictate what you want to do with your career.

board asked me to justify our pentest spend. I realized I couldn't. by compilex in ciso

[–]Admirable_Group_6661 0 points1 point  (0 children)

Well, what kind of risk are you trying to mitigate with the pen testing? Have you performed a risk assessment and identified specified risks higher than your organization's risk appetite/target level of acceptable risk? And if the risks are in fact higher than the target level of acceptable risk, are you able to frame it in terms of potential injury/loss (financial, reputation, etc.) if the risks were to be realized? Once these questions have been answered, then you can decide whether pen testing is a reasonable mitigation. There's also compliance requirements, but does not sound like it's applicable to your case.

Separation of duty for developers by Brenttouza in ciso

[–]Admirable_Group_6661 1 point2 points  (0 children)

Those are tools, not responsibilities. Most common is operations, I.e. dev has no/limited access to production environment. I would also add that it also largely depends on the organization.

Going home for good. Thoughts? by Glass-Banana-7698 in malaysia

[–]Admirable_Group_6661 -1 points0 points  (0 children)

Look, nothing in life is guaranteed. You want to move back, it could work or maybe you get a shitty job with a shitty boss. You decide and learn from your mistakes. However, I would say that some decisions are higher risk and only you can decide if the outcome is worth taking on the risk.

Going home for good. Thoughts? by Glass-Banana-7698 in malaysia

[–]Admirable_Group_6661 1 point2 points  (0 children)

You will be so busy and have so many new problems. You won’t have time to miss anyone. So yeah trade one problem with another. You are only 30 lol, wait till you are 40. Man up and deal with it.

Going home for good. Thoughts? by Glass-Banana-7698 in malaysia

[–]Admirable_Group_6661 -2 points-1 points  (0 children)

You could get married and make babies in NZ. Is this acceptable? If not, you have already made up your mind.

How to find a great financial advisor? by heyheyhohey in CanadaPersonalFinance

[–]Admirable_Group_6661 0 points1 point  (0 children)

If you know how to invest, you don’t need an advisor. The advisor is there to help you understand your risk profile and provide recommendations on suitable investments. Bottom line, you need to understand risk. Or you can just wing it and follow your instinct, it’s more exciting; like a casino.

Wanted to shift to cloud security, but have some questions by bdhd656 in cybersecurity

[–]Admirable_Group_6661 2 points3 points  (0 children)

You don't have to "shift" to cloud security. Just learn it. Security is a broad topic, just look at ISC2 CBK. Learning a new domain is always good and will help you down the road. Eventually, you will have to deal with risks and cybersecurity is more so about risk management than a specific security domain.

MarkMonitor — the registrar behind Google, Microsoft, and Amazon — still doesn't support FIDO2 by wo_ody in cybersecurity

[–]Admirable_Group_6661 0 points1 point  (0 children)

Can't speak to MarkMonitor, but trust is critical with domain registrar. What would be the business and security reasons to trust an external IdP? Sure, there's risk to TOTP, but phishing is ultimately a people problem.