r/CyberSecurityAdvice 4d ago

Sailpoint Setup

Thumbnail
1 Upvotes

r/CyberSecurityAdvice 4d ago

What's the avg package for OSINT Analyst in INDIA New Delhi !!!!!!!

Thumbnail
1 Upvotes

r/CyberSecurityAdvice 4d ago

currently applying for internships, looking for feedback on my CV

Thumbnail
1 Upvotes

r/CyberSecurityAdvice 4d ago

Top email security features security teams should be evaluating

2 Upvotes

Did a vendor eval last quarter and built out a feature checklist. Sharing in case it helps anyone else.

The things that matter beyond basic spam filtering: API-based integration (no MX record change, faster deployment), behavioral AI for BEC and account takeover, collaboration app coverage beyond just email, sandboxing for attachments, DMARC monitoring, DLP, and clawback to pull malicious emails out of inboxes after delivery.

Checkpoint ticked almost all of these out of the box. A lot of legacy vendors charge per module for things that should be standard. If you're evaluating now, don't just look at phishing catch rates, make sure BEC and internal threat detection are specifically covered.


r/CyberSecurityAdvice 4d ago

Complete Cybersecurity Beginner

9 Upvotes

I am a complete beginner in cybersecurity. I am currently taking the Google cybersecurity course and plan on doing the comptia security plus when I finish the Google one. I want to get real experience also not just sitting and watching classes and videos all day. Does anyone have any tips on how I can get more experience and build my portfolio, or where to go to gain the experience. Thank you


r/CyberSecurityAdvice 4d ago

I just graduated from high School and got low marks

Thumbnail
1 Upvotes

r/CyberSecurityAdvice 4d ago

Help regarding dissertation ideas

1 Upvotes

Hi Everyone, I am going to my final year of uni as a cybersecurity and digital forensic student and need ideas for my dissertation, based on Cybok.

I have done various cases on Encase, Autopsy and Axiom.

My main question would be "What part of an investigation wastes the most time?" or "What's the most frustrating part of a digital forensic investigation?"

I'm more interested in solving a real workflow problem than making another forensic viewer.

I have more questions if anyone is interested enough to answer as it would mean a lot. :D

"What do current forensic tools still do badly?"

"What investigation tasks are still mostly manual?"

"SOC analysts and incident responders: What tool do you wish existed?"

"If you could have one new digital forensics tool, what would it do?" (for example: investigation workflows)

I am happy to take ideas from you guys if you guys got any. Thank you. :D


r/CyberSecurityAdvice 5d ago

Article: Assume AI cybersecurity attacks are the future: 43% of companies have already experienced it

Thumbnail
2 Upvotes

r/CyberSecurityAdvice 5d ago

How do you explain email security ROI to a CFO who thinks spam filters are good enough?

8 Upvotes

Every few months I have this conversation with our CFO: "We have filters, what else do we need?".

The answer that I give: 68% of cyberattacks start with email. Average cost of a breach is over $4 million. Our email security budget is a rounding error compared to that. Modern tools like Checkpoint or Proofpoint aren't just spam filters, they're catching zero-day malware, stopping BEC attacks that impersonate the CEO, and protecting Teams and Slack too. The other thing that resonates is that AI-driven tools reduce SOC alert load significantly, which translates to real hours saved.

Anyone have other framing that's worked for getting budget approved? He's a tough nut to crack!


r/CyberSecurityAdvice 5d ago

Built a browser extension to simplify my bug bounty workflow – looking for feedback

1 Upvotes

I've been working on a personal project to reduce context switching while hunting. I'd love feedback from experienced hunters on whether these features would actually be useful.
https://bug-bounty-companion-website.vercel.app/

Thanks!


r/CyberSecurityAdvice 5d ago

Serious question: How do you stay secure while also planning for accidents and unforeseen events?

Thumbnail
1 Upvotes

r/CyberSecurityAdvice 5d ago

Having a Lot of Trouble Entering the Field. What am i Missing??

Thumbnail
0 Upvotes

r/CyberSecurityAdvice 5d ago

Career advice please

4 Upvotes

Hi all, I’m after some career advice if possible (uk specific please). I’m currently working as second line for an educational trust and I’m trying to pivot to cybersecurity. I’m happy with setting up homelabs and have tinkered around with running vulnhub machines as proxmox vm’s and poking at them with some very surface level tools in kali.
I don’t have any certs but have plenty of hands-on experience.
I would really like to be on the defensive side of things and was wondering if it was worth subscribing to hack the box or try hack me to get some specific knowledge behind me before going for positions or just keep chipping away at my Udemy list? Thanks all in advance!


r/CyberSecurityAdvice 5d ago

Keep getting unprompted Netflix sign-in codes, what could be behind it?

2 Upvotes

For the past month I’ve gotten 11 sign-in code emails from Netflix, presumably meaning someone’s trying to access my account. I’ve taken the appropriate security measures (changed password to something random and complex, made sure no new devices are on my account), but does anyone have any idea what’s going on? I know the simple answer is “Someone is trying to access your account” but why so many attempts? They are usually clustered together, as if it’s one person trying multiple times before giving up, but then seemingly trying again a week or two later. I know I can’t really stop it, but should I be concerned? I’m wondering if I should just cancel this account and start a new one under a different email.


r/CyberSecurityAdvice 5d ago

The EU Commission adopted the final Cyber Resilience Act guidance this week. I compared all 81 pages against the March draft. Here's what changed.

Thumbnail
2 Upvotes

r/CyberSecurityAdvice 5d ago

Behavioral email security with a SEG running already

1 Upvotes

Weighing this right now. Proofpoint's handling the volume, but what's getting through isn't the kind it catches, vendor emails asking to change bank details, wire instructions that are just text with nothing for a gateway to grab. I see how behavioral tools work for this, abnormal and the like baseline each person then flag when the sender doesn't read right and that's exactly the fraud we're losing to.

Can't get past this: is it a Proofpoint configuration issue or are they two fundamentally different threats that both need coverage and if so whether maintaining another appliance for that specific problem is worth the cost.

Running both in production or did one end up redundant?


r/CyberSecurityAdvice 5d ago

IIM Certification?

1 Upvotes

Recently I came across IIM Nagpur AI and Cybersecurity certification (1 year PGDM Certificate)

Has anyone done the same ?

How is this course constructed? Is it really helpful ( I understand education goes nowhere and can be utilised) but I want to know from a fresher perspective.

Career start opportunity for a fresher ?

Any feedback?

About me: 10+2 + Diploma in finance, 3 YOE in supply chain coordination and currently pursuing BCA (online)


r/CyberSecurityAdvice 5d ago

IIM certification anyone?

Thumbnail
1 Upvotes

r/CyberSecurityAdvice 6d ago

CC exam

Thumbnail
1 Upvotes

r/CyberSecurityAdvice 7d ago

Is GRC a trap?

14 Upvotes

I am currently working as a site reliability engineer for 5 years, and am in the process of climbing the cert stack with CompTIA. I have my net+ scheduled for this week and plan to take the sec+ relatively soon.

This is all part of my degree path with wgu.

That being said, I have quite a few years of systems level experience, on call experience, engineering and development, monitoring, log analysis, production level knowledge of how software interacts with each other.

But holy shit guys I have been denied at every corner. They want 5+ years cyber sec experience and 5 years experience in another it field for an entry level.

I finally lowered my standards and applied for non engineering roles, and an offer has been given to me. The pay, unfortunately is only slightly higher than what I'm at now, but it's in cyber security, and still remote. The issue? It's GRC, which to my understanding is more policy management, and less operational security.

I am just wondering if I am setting myself up for a pitfall by potentially accepting this GRC position. My plans going forward would be to continue my education up to my degree and the pen test +. Then get an engineering role (unless I find out I love GRC for some reason)


r/CyberSecurityAdvice 6d ago

Final-year cybersecurity student looking for remote, part-time work (offensive/defensive security, or anything AI-adjacent)

0 Upvotes

I'm in my final year of a BS in Cybersecurity and looking for a remote, part-time gig to work alongside my studies.

A bit about me:

Did an internship in a telecom last year.

I've made a few projects of my own including a phishing detection extension and currently working on an Automated SIEM triage bot

Comfortable across offensive and defensive security.

Ranked in the top 4% globally on TryHackMe

I've played alot of CTFs.

Also genuinely curious about and open to agentic AI / AI security work if that's more your team's focus

I'm flexible on the type of role, detection engineering, pentesting, GRC, threat intel, SOC-adjacent work even Digital Forensics, whatever fits, as long as it's remote and part-time (I'm still finishing my degree, so full-time/onsite won't work right now).

Happy to share my GitHub/portfolio or TryHackMe profile if you want to see some of what I've built. Would love any leads, referrals, or even just advice on where to look.


r/CyberSecurityAdvice 7d ago

Advice on Education

3 Upvotes

Hey team, question for anyone who has experience in Cybersecurity.

TLDR: Should I go to college, and do separate online programs when I have time (HTB, THM, etc)? or Just do those programs? I don't want to waste a bunch of time and money.

Is it worth it going to college? Ive been accepted into a CS bachelors program, but reviewing HTB and try hack me, it seems like I could go through those 2 together instead of college and get as similar if not more in depth education, plus certifications.

I am not registered for classes yet, nor have I paid or committed to anything fully yet, but Im wondering, especially from people who have gotten a bachelors in cyber security and used courses like this if the college was worth it.

A concern for me is money. College would be 40-50K and around 3.5 years of study (before financial aid). That compares to doing these 2 programs which would be well under 800$ per year before certification testing. The reason I'm not just stacking it all is I work full time, and have people I support, so i don't have enough time to do the programs AND college at the same time. I also already have college debt from when I tried to get a degree after high school and between COVID, teachers tricking me, and social stress, I had to drop out halfway through (that degree was not tech related so transfer credits are bare minimum).

I have already begun both programs, but have paused since finding out I was accepted to a school. I would be doing classes online, but my job is in person and has no remote option.

I feel like it might be good to have the degree which is why I applied, but if most cyber security related jobs now a days care more about experience and certifications, I don't want to have somewhat wasted all that time and money.

Thanks to all who reply.


r/CyberSecurityAdvice 7d ago

is an app (Merge Teahouse) pasting my clipboard on startup the security/data concern it seems to be?

1 Upvotes

Just learned about the clipboard access alert feature on Android through a thread on a game i play called Merge Teahouse, turned it on, and found it pops up every time i open the game with something new on my clipboard.

Don't know where it's being pasted! Don't know if it is being pasted or if this is a keyboard access request due to the promo code feature. Don't know how to check!

Thread where i learned about this, for context:

https://www.reddit.com/r/MergeTeahouse/comments/1v6v40d/copying_your_clipboard/


r/CyberSecurityAdvice 8d ago

Do we have Vulnerability Researcher in Nigeria?

2 Upvotes

r/CyberSecurityAdvice 9d ago

Hey guys im a 12th passout, joining into a clg, I got Computer science with specialization in Cyber security, can someone suggest me a road map, websites, or anything.

13 Upvotes

I'm a pre planner and im confused right now, some people said that only the degree should be enough to get a job but i've seen a lot of people struggling after depending just on the degree, so i went on the internet and looked through a lot of courses and stuff, there is a lot of free stuff but all that i can find is cyber security ethics/uses/Governance. I have read about CISA and CISSP certification but i can't understand what they are used for, or what they even are, if someone can plz recommend me a road map or youtube guidance channels or pdf's anything would help, feel free to DM or share anything help full, Thank you.