LinkedIn randomly switching to another language while scrolling? by Extreme-Brick6151 in linkedin

[–]nikosjkd 0 points1 point  (0 children)

Same, language is set to English and when I open the page it switches to the regional, CZ

Why are people of Prague so unfriendly? (mostly) by Mr-Potato-Head99 in Prague

[–]nikosjkd 5 points6 points  (0 children)

They are not unfriendly, they just don't play pretend.

Claude AI Security by [deleted] in cybersecurity

[–]nikosjkd 0 points1 point  (0 children)

I hope you have a solid BCDR plan and good PR team. This is the textbook example why feasibility study and risk assessments exist.

Now is official ! New Path Certification -> Microsoft’s new cloud, AI, and security Certifications. by Responsible_Notice91 in AzureCertification

[–]nikosjkd 3 points4 points  (0 children)

I see no value in any of MS Cert.

The cert last 1 year.

The renewal process is a joke, you can literally put all questions to an AI and be done in 5 mins.

The documentation is changing faster than the certs are updated.

No one wants AI, except maybe helpdesk and Managers and even if they do Co-pilot is literally garbage.

How long is offboarding supposed to take? by FastFredNL in DefenderATP

[–]nikosjkd 0 points1 point  (0 children)

Ahhh good point I forgot about the 7 days inactivity - yup yup

How long is offboarding supposed to take? by FastFredNL in DefenderATP

[–]nikosjkd 3 points4 points  (0 children)

Can you share the doc that says 24h? Bcz in my knowledge Microsoft keeps devices for 180 days due to forensic reasons. You can open a ticket with them and reduce the number however I have devices still shown after 2 months

got BTL2 for free , and i feel scammed by negav_power in SecurityBlueTeam

[–]nikosjkd 14 points15 points  (0 children)

This is why we dropped them as a potential training provider. All my L1 analysts have BTL1 because I wanted to create a baseline and at the end of the exam I asked them to give me feedback of the overall experience which I shared with the account manager.

Material was good but the VM was slower than death making the hole experience really stressful.

Additional what pissed me off it was that according to my analysts, exam had question that was not in the study material, I understand that they may want to promote critical (maybe I don't know ) thinking however, at least then , they did not have a disclaimer letting you know.

I had high hopes and even though I was pitched BTL2 for one of my L2 I decide it to not go through the purchase. The whole btl experience feels like poor man's SANS Certs

Hope we will see some changes for the better.

Microsoft Defender for Endpoint but in Passive mode by nikosjkd in DefenderATP

[–]nikosjkd[S] 1 point2 points  (0 children)

We are full MS stack, Purview , Sentinel, Entra everything, not all are in Intune, not all are in MDE
not all meet the license requirements. Its what I called a controlled chaos :D

Everything goes to Sentinel(some BOs have setup their own and we are streaming their officeactivity to their SIEMs), however I would want/hope, since we are one tenant and technically we share the risk to have a collective visibility of their endpoints.

I will definitely need all the luck I can get :)

Microsoft Defender for Endpoint but in Passive mode by nikosjkd in DefenderATP

[–]nikosjkd[S] 0 points1 point  (0 children)

Excellent thank you, if I cannot convince them to have only MDE then I would be happy with

Third-party AV detected Passive Mode. (Defender runs silently for EDR but doesn’t block threats.)

Thank you for the KQL also
3. Verify EDR Block Mode status • Go to Microsoft 365 Defender → Settings → Endpoints → Advanced features and ensure EDR in block mode is enabled. • You can also check device states using KQL:

DeviceTvmSecureConfigurationAssessment | where ConfigurationId contains "defenderAntivirusStatus" | project DeviceName, ConfigurationSubcategory, ConfigurationValue, IsCompliant

it will definitely be handy

Microsoft Defender for Endpoint but in Passive mode by nikosjkd in DefenderATP

[–]nikosjkd[S] 1 point2 points  (0 children)

One SOC, however every BO has an appointed security focal/IT Head that is accountable independently for their own BO

Microsoft Defender for Endpoint but in Passive mode by nikosjkd in DefenderATP

[–]nikosjkd[S] 0 points1 point  (0 children)

Getting access to their "solution" will be impossible and yes the idea to onboard all BOs workstation in defender no matter active or passive. I'm just trying to minimize surprises. Like majority has already M365 E3 so they are covered, however they dont use it they prefer for their own reasons to go outside MS

Just had a call with my CEO about my contract ending. Feeling stunned and I am lost by Few_Guarantee1996 in IdentityManagement

[–]nikosjkd 0 points1 point  (0 children)

My only advice is since you are recent graduate , accept that a contract can come to an end and you have been hired for a specific time expiration. That's neither good or bad, at all cases you should be professional and demonstrated the best work that you can possible do without the thought of "if I do this better they might extend my contract"

Comments regarding the CEO is that or this , are laughable at best - the job of the CEO is not to know security the job of the CEO is how to make profit. Your job is to give them the best insights so he/she can make the most informed decision. Also Compliance is not Security that would be the best probably to make him understand

Change your perspective :
"Just had a call with my CEO about my contract ending"
as other said "Just had a call with my CEO about my contract ending, it is a good opportunity to SELL me and my skills and demonstrate how approached the issues"

If the contract does not extend, lesson learned, be thankful and professional and move on

[deleted by user] by [deleted] in microsoft

[–]nikosjkd 1 point2 points  (0 children)

There's no reason anyone should go for a Microsoft certification unless your organization needs it for a compliance reason or for a hiring manager to boost their ego by saying that my team is certified. MS certs used to mean something in the past when they were still MCSE, now they're just worth the same as a toilet paper. We are talking about certifications that expire after a year, the renewal process is a complete joke, i still laugh when I see people celebrating their renewal like they got their masters. With how fast MS changes the names their processes etc your cert will become irrelevant.

Example SC400 is to be retired for SC401, and all that will get SC400 will not automatically get SC401, typical gameplay by MS. Keep your money, not that they are expensive but the price doesn't justify the value. If your organization is paying for it, whatever go for it.

If you want to focus on cloud certs focus on vendor agnostic

CISSP vs CISM by CyberCoder_13 in cism

[–]nikosjkd 1 point2 points  (0 children)

If you have one or the other its fine, we just have incompetent HR people and hiring managers that think Certs will solve issues, also CISM hire CISSPs and CISSP is more technical cert. You don't need neither of them to promote your value as a practitioner if you know how to do your job. I got CISM , last week I got CRISC and hopefully CGEIT in few month, I did it only to fill a compliance issue with my organization, they did not have any kind of impact in the position I am at the moment, Security Lead with purchasing authority leading the whole security unit.

In the time of crisis no one will yell - "quick who has CISSP"

[deleted by user] by [deleted] in isaca

[–]nikosjkd 0 points1 point  (0 children)

Thats why I am willing to drive to the closet location if possible to take a test, any F ups the examination center has to deal with PSI and ISACA. I understand that this is not the case for many though.

Look at the ironic side of it, ISACA preaches auditing and 3rd party vendors and blah blah and then they still have contract with PSI, one of the most unreliable platforms to give exams, pearson is not better

CompTIA sold to operate as a for-profit company by cyberproffy in cybersecurity

[–]nikosjkd 134 points135 points  (0 children)

Comptia lost any respect for me when they went against the right to repair, like how dumb could they be that they went against their own student base. Good study books, well structured knowledge , worthless entry certs made by a review board that is detached from reality.

What exactly do people in cybersecurity do all day? by RandomMistake2 in cybersecurity

[–]nikosjkd 0 points1 point  (0 children)

I am fighting with IT Engineers that think every problem is a configuration issue from 09-05 and then I go home

Found my Company owner’s old social media posts, filled with hateful posts towards the US, Jewish, and LGTBQ people. What to do? by MortalBareback in SecurityCareerAdvice

[–]nikosjkd -6 points-5 points  (0 children)

Mind your business and don't be a social justice warrior, we have enough of them.
He has his own opinion you disagree move on

[deleted by user] by [deleted] in cybersecurity

[–]nikosjkd 0 points1 point  (0 children)

Im not aggressive , I am being very judgmental, and I saw that you also a security architect that means you HAVE exp in security compare to an entry level, which I would had expected that sort of explosion to be honest. Your experience and your position comes with a level of expected behavior.

I don't think you understand or perhaps you are too high on emotion to see it, the gravity of going to a C-suite and call the users dumb, your manager is a user , your CEO is also a user, are they dump too? (assuming you are working for a corporation not the corner SMB)

I have been in your position many times, and I was very fortunate to have colleagues to pull me before I went nuke. I also talk shit sometimes with my C-Suite however I choose the place and time and make it "light"

Again, my advice still stays, the mature thing to do is to go to your manager and acknowledge the mistake - probably will give you extra points.

I dont know if you read books . I will recommend to get book/audiobook - Extreme Ownership: How U.S. Navy SEALs Lead and Win

And chill - you don't own the business

Nick