Seccuri Sessions

Seccuri Session: How do you know cybersecurity is for you?

  • juanitaJuanita Duque in Jul 21, 2022CEO at Seccuri
Seccuri Session: How do you know cybersecurity is for you?

As a quick recap, Seccuri Sessions are sessions of all topics related to the entire cybersecurity talent ecosystem. We speak to experts in the industry about their experiences, perspectives, and recommendations in various cybersecurity topic.  

This Seccuri Session is related to a question we have heard multiple times: How do I know cybersecurity is right for me?

Who is Filipi?

This Seccuri Session was held with Filipi Pires, a cybersecurity expert with many years of experience in the industry. He is member of various communities that discuss topics regarding cybersecurity, security, development, and other topics related to technology. He is the founder of Black & White Technology, a consulting company in Portugal and he is a Security Researcher in Saporo, a company in Switzerland helping  organizations improve their cyber resistance  your cyber resistance by prioritizing and reducing user and system access.

Filipi is an advocate of Hacking is not a Crime, an non-profit organization that seeks to teach the world the concept that hacking is not a crime but a a lifestyle. This organization seeks to explain that a hacker is simply an inquisitive critical thinker who solves complex problems with unorthodox means. Threat actors/cyber criminals are hackers that exploit vulnerabilities in unethical/illegal ways to do harm or steal information.

How did Filipi know cybersecurity was for him?

Starting this Session, we asked Filipi how he knew that cybersecurity was for him.

Although he feels he was born a hacker, he did not choose cybersecurity. Cybersecurity chose him. He started as a salesperson, and then moved to a technical company (Trend Micro) to the infrastructure team. Once he joined this company, he got the opportunity to learn from specialists and within the company.

He fell in love with cybersecurity. He finds it fascinating to see how threats grow exponentially and how new attacks and misconfigurations are found as new technologies arise.

What are the basic technical skills someone should learn if they want to join cybersecurity?

The simple answer is: learn the basics.  

Filipi’s advice is for talent interested in cybersecurity to learn the basics of system operations, network, cybersecurity, and program language. Learn how a tool or information works and how it is interconnected in the company.

  • Network: learn how the protocols work and how they are used in traffic
  • System operation: Not only learn what system is used, but learn about the function of the DLL or libraries and understand dependencies within system operations
  • Program language: Learn about the core languages such as C, C#, and how program assembly works.
  • Other examples he provided:
  • Learn what a handshake of TLS protocol is
  • Learn about a DNS process/flow
  •  For offensive security: not only learn how to use tools (such as SQL mapping tools used for Kali Linux or other platforms for penetration testing) but understand how the tools work and how an attack can be produced

Unsure where to learn about the basics?

  • There are many great companies that provide cybersecurity training
  • Follow experts
  • Read blogs and articles

What is an advanced skill difficult to find but crucial to know?

After asking the basics, we thought it was important to know what are the advanced skills that Filipi believes are more difficult to find in the market.

Depending on the area in cybersecurity there are different recommended advanced skills.

General: Filipi has seen that companies find have a difficulty in finding people that know program languages.

If you are an expert in cybersecurity, his advice is to learn a program language. He has seen that people usually choose Python as it is the easiest to learn, yet he recommends learning .Net, C, or C#.

Defensive Security: Understand the environment and the perimeter and how the company’s digital ecosystem works interconnectedly to be able to work with different vendors.

Offensive security: Achieve deep knowledge in penetration testing. Lear about the flow of a web application (front, backend, how the app works) and how it is connected, such as through an API.

Source: Seccuri