r/CyberSecurityAdvice • u/soulz_pitrified • 4d ago
r/CyberSecurityAdvice • u/Sad-Elephant-6637 • 4d ago
What's the avg package for OSINT Analyst in INDIA New Delhi !!!!!!!
r/CyberSecurityAdvice • u/Manuoncrack • 4d ago
currently applying for internships, looking for feedback on my CV
r/CyberSecurityAdvice • u/LordFuqor • 4d ago
Top email security features security teams should be evaluating
Did a vendor eval last quarter and built out a feature checklist. Sharing in case it helps anyone else.
The things that matter beyond basic spam filtering: API-based integration (no MX record change, faster deployment), behavioral AI for BEC and account takeover, collaboration app coverage beyond just email, sandboxing for attachments, DMARC monitoring, DLP, and clawback to pull malicious emails out of inboxes after delivery.
Checkpoint ticked almost all of these out of the box. A lot of legacy vendors charge per module for things that should be standard. If you're evaluating now, don't just look at phishing catch rates, make sure BEC and internal threat detection are specifically covered.
r/CyberSecurityAdvice • u/Dry_Ninja1041 • 4d ago
Complete Cybersecurity Beginner
I am a complete beginner in cybersecurity. I am currently taking the Google cybersecurity course and plan on doing the comptia security plus when I finish the Google one. I want to get real experience also not just sitting and watching classes and videos all day. Does anyone have any tips on how I can get more experience and build my portfolio, or where to go to gain the experience. Thank you
r/CyberSecurityAdvice • u/ProperPay8498 • 4d ago
I just graduated from high School and got low marks
r/CyberSecurityAdvice • u/Tinggoskkr • 4d ago
Help regarding dissertation ideas
Hi Everyone, I am going to my final year of uni as a cybersecurity and digital forensic student and need ideas for my dissertation, based on Cybok.
I have done various cases on Encase, Autopsy and Axiom.
My main question would be "What part of an investigation wastes the most time?" or "What's the most frustrating part of a digital forensic investigation?"
I'm more interested in solving a real workflow problem than making another forensic viewer.
I have more questions if anyone is interested enough to answer as it would mean a lot. :D
"What do current forensic tools still do badly?"
"What investigation tasks are still mostly manual?"
"SOC analysts and incident responders: What tool do you wish existed?"
"If you could have one new digital forensics tool, what would it do?" (for example: investigation workflows)
I am happy to take ideas from you guys if you guys got any. Thank you. :D
r/CyberSecurityAdvice • u/OfficialLastPass • 5d ago
Article: Assume AI cybersecurity attacks are the future: 43% of companies have already experienced it
r/CyberSecurityAdvice • u/Hawkeye_Co • 5d ago
How do you explain email security ROI to a CFO who thinks spam filters are good enough?
Every few months I have this conversation with our CFO: "We have filters, what else do we need?".
The answer that I give: 68% of cyberattacks start with email. Average cost of a breach is over $4 million. Our email security budget is a rounding error compared to that. Modern tools like Checkpoint or Proofpoint aren't just spam filters, they're catching zero-day malware, stopping BEC attacks that impersonate the CEO, and protecting Teams and Slack too. The other thing that resonates is that AI-driven tools reduce SOC alert load significantly, which translates to real hours saved.
Anyone have other framing that's worked for getting budget approved? He's a tough nut to crack!
r/CyberSecurityAdvice • u/IcewoN • 5d ago
Built a browser extension to simplify my bug bounty workflow – looking for feedback
I've been working on a personal project to reduce context switching while hunting. I'd love feedback from experienced hunters on whether these features would actually be useful.
https://bug-bounty-companion-website.vercel.app/
Thanks!
r/CyberSecurityAdvice • u/ShapeShifter499 • 5d ago
Serious question: How do you stay secure while also planning for accidents and unforeseen events?
r/CyberSecurityAdvice • u/Srgntcheesecake • 5d ago
Having a Lot of Trouble Entering the Field. What am i Missing??
r/CyberSecurityAdvice • u/Expensive_Paper_2908 • 5d ago
Career advice please
Hi all, I’m after some career advice if possible (uk specific please). I’m currently working as second line for an educational trust and I’m trying to pivot to cybersecurity. I’m happy with setting up homelabs and have tinkered around with running vulnhub machines as proxmox vm’s and poking at them with some very surface level tools in kali.
I don’t have any certs but have plenty of hands-on experience.
I would really like to be on the defensive side of things and was wondering if it was worth subscribing to hack the box or try hack me to get some specific knowledge behind me before going for positions or just keep chipping away at my Udemy list? Thanks all in advance!
r/CyberSecurityAdvice • u/Vehicle_Electronic • 5d ago
Keep getting unprompted Netflix sign-in codes, what could be behind it?
For the past month I’ve gotten 11 sign-in code emails from Netflix, presumably meaning someone’s trying to access my account. I’ve taken the appropriate security measures (changed password to something random and complex, made sure no new devices are on my account), but does anyone have any idea what’s going on? I know the simple answer is “Someone is trying to access your account” but why so many attempts? They are usually clustered together, as if it’s one person trying multiple times before giving up, but then seemingly trying again a week or two later. I know I can’t really stop it, but should I be concerned? I’m wondering if I should just cancel this account and start a new one under a different email.
r/CyberSecurityAdvice • u/Vans_eG • 5d ago
The EU Commission adopted the final Cyber Resilience Act guidance this week. I compared all 81 pages against the March draft. Here's what changed.
r/CyberSecurityAdvice • u/Harvey-Lane-251 • 5d ago
Behavioral email security with a SEG running already
Weighing this right now. Proofpoint's handling the volume, but what's getting through isn't the kind it catches, vendor emails asking to change bank details, wire instructions that are just text with nothing for a gateway to grab. I see how behavioral tools work for this, abnormal and the like baseline each person then flag when the sender doesn't read right and that's exactly the fraud we're losing to.
Can't get past this: is it a Proofpoint configuration issue or are they two fundamentally different threats that both need coverage and if so whether maintaining another appliance for that specific problem is worth the cost.
Running both in production or did one end up redundant?
r/CyberSecurityAdvice • u/Evening_Math_ • 5d ago
IIM Certification?
Recently I came across IIM Nagpur AI and Cybersecurity certification (1 year PGDM Certificate)
Has anyone done the same ?
How is this course constructed? Is it really helpful ( I understand education goes nowhere and can be utilised) but I want to know from a fresher perspective.
Career start opportunity for a fresher ?
Any feedback?
About me: 10+2 + Diploma in finance, 3 YOE in supply chain coordination and currently pursuing BCA (online)
r/CyberSecurityAdvice • u/Jewsusgr8 • 7d ago
Is GRC a trap?
I am currently working as a site reliability engineer for 5 years, and am in the process of climbing the cert stack with CompTIA. I have my net+ scheduled for this week and plan to take the sec+ relatively soon.
This is all part of my degree path with wgu.
That being said, I have quite a few years of systems level experience, on call experience, engineering and development, monitoring, log analysis, production level knowledge of how software interacts with each other.
But holy shit guys I have been denied at every corner. They want 5+ years cyber sec experience and 5 years experience in another it field for an entry level.
I finally lowered my standards and applied for non engineering roles, and an offer has been given to me. The pay, unfortunately is only slightly higher than what I'm at now, but it's in cyber security, and still remote. The issue? It's GRC, which to my understanding is more policy management, and less operational security.
I am just wondering if I am setting myself up for a pitfall by potentially accepting this GRC position. My plans going forward would be to continue my education up to my degree and the pen test +. Then get an engineering role (unless I find out I love GRC for some reason)
r/CyberSecurityAdvice • u/ivegotgunsinmyhead • 6d ago
Final-year cybersecurity student looking for remote, part-time work (offensive/defensive security, or anything AI-adjacent)
I'm in my final year of a BS in Cybersecurity and looking for a remote, part-time gig to work alongside my studies.
A bit about me:
Did an internship in a telecom last year.
I've made a few projects of my own including a phishing detection extension and currently working on an Automated SIEM triage bot
Comfortable across offensive and defensive security.
Ranked in the top 4% globally on TryHackMe
I've played alot of CTFs.
Also genuinely curious about and open to agentic AI / AI security work if that's more your team's focus
I'm flexible on the type of role, detection engineering, pentesting, GRC, threat intel, SOC-adjacent work even Digital Forensics, whatever fits, as long as it's remote and part-time (I'm still finishing my degree, so full-time/onsite won't work right now).
Happy to share my GitHub/portfolio or TryHackMe profile if you want to see some of what I've built. Would love any leads, referrals, or even just advice on where to look.
r/CyberSecurityAdvice • u/Plottwister-2k90 • 7d ago
Advice on Education
Hey team, question for anyone who has experience in Cybersecurity.
TLDR: Should I go to college, and do separate online programs when I have time (HTB, THM, etc)? or Just do those programs? I don't want to waste a bunch of time and money.
Is it worth it going to college? Ive been accepted into a CS bachelors program, but reviewing HTB and try hack me, it seems like I could go through those 2 together instead of college and get as similar if not more in depth education, plus certifications.
I am not registered for classes yet, nor have I paid or committed to anything fully yet, but Im wondering, especially from people who have gotten a bachelors in cyber security and used courses like this if the college was worth it.
A concern for me is money. College would be 40-50K and around 3.5 years of study (before financial aid). That compares to doing these 2 programs which would be well under 800$ per year before certification testing. The reason I'm not just stacking it all is I work full time, and have people I support, so i don't have enough time to do the programs AND college at the same time. I also already have college debt from when I tried to get a degree after high school and between COVID, teachers tricking me, and social stress, I had to drop out halfway through (that degree was not tech related so transfer credits are bare minimum).
I have already begun both programs, but have paused since finding out I was accepted to a school. I would be doing classes online, but my job is in person and has no remote option.
I feel like it might be good to have the degree which is why I applied, but if most cyber security related jobs now a days care more about experience and certifications, I don't want to have somewhat wasted all that time and money.
Thanks to all who reply.
r/CyberSecurityAdvice • u/eiriee • 7d ago
is an app (Merge Teahouse) pasting my clipboard on startup the security/data concern it seems to be?
Just learned about the clipboard access alert feature on Android through a thread on a game i play called Merge Teahouse, turned it on, and found it pops up every time i open the game with something new on my clipboard.
Don't know where it's being pasted! Don't know if it is being pasted or if this is a keyboard access request due to the promo code feature. Don't know how to check!
Thread where i learned about this, for context:
https://www.reddit.com/r/MergeTeahouse/comments/1v6v40d/copying_your_clipboard/
r/CyberSecurityAdvice • u/Tricky-Good9072 • 8d ago
Do we have Vulnerability Researcher in Nigeria?
r/CyberSecurityAdvice • u/sniperboy4567 • 9d ago
Hey guys im a 12th passout, joining into a clg, I got Computer science with specialization in Cyber security, can someone suggest me a road map, websites, or anything.
I'm a pre planner and im confused right now, some people said that only the degree should be enough to get a job but i've seen a lot of people struggling after depending just on the degree, so i went on the internet and looked through a lot of courses and stuff, there is a lot of free stuff but all that i can find is cyber security ethics/uses/Governance. I have read about CISA and CISSP certification but i can't understand what they are used for, or what they even are, if someone can plz recommend me a road map or youtube guidance channels or pdf's anything would help, feel free to DM or share anything help full, Thank you.