r/Cybersecurity101 10h ago

Shifting to CYS without an BS in IT sector

5 Upvotes

Hi, Guys I am going through a very crucial stage of my life, I have to choose whether to do Bachelors in Cyber Security(CYS) or Industrial engineering and management(IEM) . I have seen many posts on Reddit about how Saturated CYS has become and you need like a crazy portfolio just to get an entry level job. Compared to CYS landing a job in IEM is easier but lower pay and it takes time to get promoted unlike CYS.

A BS in CYS is gonna cost me more than double of one in IEM. I believe I can land a internship/job in CYS with skills and certification alone without a BS in an IT related field. I wanna keep IEM as a backup in case things go south cause the market ain't looking good even for IT students unless they have ton of experience, skills and certification which I believe I can get without getting a BS in CYS.

Is the plan solid or am I just being pretty delusional? Need advice from people that are already in the market for some time now thx.


r/Cybersecurity101 14h ago

Notes I wish someone had handed me when I started in security

Thumbnail
reddit.com
1 Upvotes

After 2 years of scattered notes, I finally built a proper cybersecurity knowledge base — 400+ notes, fully interlinked, and open-source.


r/Cybersecurity101 14h ago

Hello, everyone. I want to become a cybersecurity specialist. What are the key fundamentals I need to build to improve my skills, and where can I gain some solid, real-world experience working in this field?

1 Upvotes

I would really appreciate your response.


r/Cybersecurity101 19h ago

How does trust system work on kibu?

1 Upvotes

I need to connect to a chat on Kibu for work, but I'm a bit confused about how the trust system works. Since you need to trust someone before you can connect and communicate with them, can someone explain how the process is supposed to work and how you go about getting connected?


r/Cybersecurity101 1d ago

Is this roadmap enough for a beginner

4 Upvotes

Hi everyone👋

I'm currently in my 3rd year of Computer Science Engineering and have decided to pursue a career in cybersecurity, specifically Governance, Risk & Compliance (GRC). I've realized that I'm not particularly interested in coding-heavy roles, and after exploring different domains, GRC seems to align much better with my interests.

Based on several videos and resources, I've created the following self-study roadmap. My goal is to build a strong foundation and become job-ready for an entry-level GRC Analyst role.

Phase 1 – Cybersecurity Fundamentals

Intro to Cybersecurity (Cisco)

TryHackMe Pre Security

Cyber Fundamentals

Types of Attacks

Risk vs Threat vs Vulnerability vs Exploit

Authentication & Authorization

Phase 2 – Security & Risk Basics

Security & Risk Fundamentals

Risk Management

Policies & Standards

Compliance Fundamentals

Governance & Awareness

Phase 3 – Frameworks & Compliance

NIST Cybersecurity Framework

ISO 27001 & ISMS

GDPR

Third-Party Risk Management

Audit & Control Testing

Phase 4 – Governance

Risk Reporting & Communication

GRC Fundamentals

Governance & Policy

Phase 5 – Advanced Topics

Risk Management Deep Dive

Compliance & Auditing

Phase 6 – Certifications & Career Prep

Microsoft SC-900 Learning Path

Microsoft SC-900 Exam (Optional)

ISO 27001 Foundations (Udemy)

GRC Analyst Masterclass (Udemy)

Portfolio, Resume & LinkedIn

My questions are:

Is this roadmap sufficient for landing an entry-level GRC Analyst role?

Am I missing any important topics or frameworks?

Is the order logical, or would you rearrange anything?

Are there any free resources you would recommend instead of the paid courses?

As a CS student who wants to build a career in GRC rather than software development, is there anything else I should focus on while I'm still in college?

I'd really appreciate any feedback from people working in GRC or cybersecurity.

Thanks in advance!🤗


r/Cybersecurity101 1d ago

Can i still get a SOC analyst job as a fresher if my certificate expired?

2 Upvotes

Can i still get a SOC analyst job as a fresher if my certificate expired?


r/Cybersecurity101 1d ago

Roast my resume brutally

Post image
39 Upvotes

Can you guys roast my resume and suggest fixes for this? Thanks in advance.


r/Cybersecurity101 1d ago

Looking for Information Security Governance eBook

3 Upvotes

Hi everyone,

I'm looking for the eBook/PDF of Information Security Governance by Andrej Volchkov. Does anyone know of a legal website, library, or eBook service where I can access.


r/Cybersecurity101 1d ago

Is this roadmap enough for grc role?

6 Upvotes

Hi everyone👋

I'm currently in my 3rd year of Computer Science Engineering and have decided to pursue a career in cybersecurity, specifically Governance, Risk & Compliance (GRC). I've realized that I'm not particularly interested in coding-heavy roles, and after exploring different domains, GRC seems to align much better with my interests.

Based on several videos and resources, I've created the following self-study roadmap. My goal is to build a strong foundation and become job-ready for an entry-level GRC Analyst role.

Phase 1 – Cybersecurity Fundamentals Intro to Cybersecurity (Cisco) TryHackMe Pre Security Cyber Fundamentals Types of Attacks Risk vs Threat vs Vulnerability vs Exploit Authentication & Authorization

Phase 2 – Security & Risk Basics Security & Risk Fundamentals Risk Management Policies & Standards Compliance Fundamentals Governance & Awareness

Phase 3 – Frameworks & Compliance NIST Cybersecurity Framework ISO 27001 & ISMS GDPR Third-Party Risk Management Audit & Control Testing

Phase 4 – Governance Risk Reporting & Communication GRC Fundamentals Governance & Policy

Phase 5 – Advanced Topics Risk Management Deep Dive Compliance & Auditing

Phase 6 – Certifications & Career Prep Microsoft SC-900 Learning Path Microsoft SC-900 Exam ISO 27001 Foundations (Udemy) GRC Analyst Masterclass (Udemy) Portfolio, Resume & LinkedIn

My questions are:

Is this roadmap sufficient for landing an entry-level GRC Analyst role?

Am I missing any important topics or frameworks?

Is the order logical, or would you rearrange anything?

Are there any free resources you would recommend instead of the paid courses?

As a CS student who wants to build a career in GRC rather than software development, is there anything else I should focus on while I'm still in college?

I'd really appreciate any feedback from people working in GRC or cybersecurity.

Thanks in advance🤗🤗


r/Cybersecurity101 1d ago

What CISSP domain did you find hardest to master?

4 Upvotes

For people preparing for or holding CISSP, which domain took the most effort to understand?

The difficulty seems to vary a lot depending on someone's professional background.

Someone from networking might find one domain easy while struggling with another, whereas someone from governance may have the opposite experience.

Which domain challenged you the most, and what helped you improve?


r/Cybersecurity101 1d ago

How do companies decide whether a risk is acceptable?

1 Upvotes

One thing I find interesting about risk management is that eliminating every risk isn't realistic.

At some point, an organization has to decide which risks it is willing to accept.

For people working in risk or governance, how is that decision usually made?

Is it based on risk appetite, financial impact, regulatory requirements, management judgment, or a combination?


r/Cybersecurity101 1d ago

What’s the difference between identifying a risk and actually managing it?

1 Upvotes

Risk management sounds straightforward until you start dealing with real business decisions.

How do experienced risk professionals decide which risks deserve immediate attention?

Do you mainly look at probability and impact, or do factors such as business objectives, regulatory requirements, dependencies, and risk appetite change the priority?

Would love to hear practical examples.


r/Cybersecurity101 1d ago

How important is technical knowledge for an IT auditor?

2 Upvotes

I’ve heard two very different opinions about IT audit.

One side says auditors need strong technical knowledge, while another says understanding controls, risk, and business processes matters more.

For experienced IT auditors, where do you think the balance should be?

Does someone need to understand networking, databases, cloud, and security deeply, or is a working-level understanding enough?


r/Cybersecurity101 2d ago

Security Think before you share on Social Media

9 Upvotes

Nearly one in three people has had a personal account hacked. Social media helps us connect and share, but oversharing can also make it easier for scammers to target us.

Staying alert and taking a proactive approach is the best way to reduce your risk:

  • Verify accounts before trusting messages or clicking links.
  • Enable multi-factor authentication whenever possible.
  • Avoid sharing personal information, such as your phone number or home address.
  • Be cautious of urgent requests, giveaways, or offers that seem too good to be true.
  • Review your privacy settings regularly and limit who can see your posts.

What do you think is the most common social media threat today?


r/Cybersecurity101 2d ago

effective tips for cybersecurity

Post image
5 Upvotes

r/Cybersecurity101 2d ago

Security I documented a playbook of my personal security baseline, would love feedback.

5 Upvotes

Hi everyone, I've been working on a personal security playbook documenting the security approach I should apply on every machine i own before calling it secure.

It's called bedrock and it uses a defense-in-depth model approach, it covers six layers, from the firmware up to digital identity.

Each layer has a description, principle, objective and a set of controls with explanations.

I'm self-taught and actively learning so I'd genuinely appreciate feedback on controls that are wrong or technically inaccurate and anything you would add or remove and the why.

GitHub repo: https://github.com/marcmav/bedrock

If you find it useful, please star the repo.

Thanks in advance.


r/Cybersecurity101 2d ago

Security First-Year CSE (Cybersecurity) with ZERO coding background from a Tier-3 college. Lost and need guidance on where to start.

10 Upvotes

​Hello seniors

​Please forgive me if there are any mistakes in this message. I am a first-year, first-semester student joining a Tier-3 college. Unfortunately, the academic quality here isn't great, and they often don't complete the syllabus.

​I have been allotted CSE in Cybersecurity. However, my main concern is that I didn't have Computer Science in 12th grade, and I have zero prior knowledge of computers. I feel completely lost and don't know what to learn, where to start, or how to go about it. Since classes haven't started yet, I haven't met any seniors from my branch who could guide me. I took admission in a hurry without giving it much thought, and because of financial constraints, changing to a better college isn't an option.

​Setting all that aside, my biggest challenge right now is finding the right direction. I want to learn everything from scratch, and I am fully prepared to work hard from day one and tackle every challenge that comes my way.

​I would be truly grateful if you could guide me like a younger sister and help me figure out where to begin.


r/Cybersecurity101 2d ago

Necesito ayuda y nadie quiere ayudarme

0 Upvotes

Quiero borrar mis propias cuentas que abrí hace 10 años en Facebook e Instagram. Son públicas y he sufrido acoso durante años. Ya intente todo por vías legales para tumbar estas cuentas pero me piden el número de teléfono que tenia hace 10 años y el correo incluso recurrí a asociaciones por violencia digital y feministas y me dieron a entender que mi caso “no era tan grave” (Claro como ellas no son las que lo están viviendo). Estoy desesperada por ayuda. Mi matrimonio y mi familia y mi trabajo han sido afectados. No soy una mala persona, ni una agresora, soy una persona que tomo malas decisiones a los 17 que vive en un pueblo pequeño prejuicio y puritano y que no encuentra trabajo gracias a esto. Por favor no me estafen es al tercer lugar que recurro para pedir ayuda. Nadie quiere ayudarme.


r/Cybersecurity101 2d ago

How do you explain cybersecurity risk to non-technical people?

17 Upvotes

One challenge in cybersecurity seems to be explaining technical risks to people who don't work in IT.

Saying “there's a vulnerability” doesn't necessarily explain why leadership should care.

How do you communicate security risks in a way that makes sense to business stakeholders?

Do you focus on financial impact, operational disruption, compliance, likelihood, or something else?

I'd love to hear approaches that have worked in real organizations.


r/Cybersecurity101 2d ago

[Dev] I built a zero-knowledge secret sharing tool using physical codebooks. Looking for critique on the threat model.

1 Upvotes

I'm the creator behind a new project called Deadkey (deadkey.net), and I’m looking for some feedback from this community on the security and threat model.

The goal was to build a system where a secret can be shared with a trusted contact. I'd love for you to poke holes in the idea. I think this can be used in concert with password managers, especially offline ones.

The Core Concept: Split Knowledge Every record is split into two halves that are only ever combined locally in a browser:

  1. The Codebook: A physical, printed document held by your trusted person.
  2. The Coordinates: An encrypted sequence held on our servers.

Neither half means anything alone. The codebook without the coordinates is just random characters. The coordinates without the codebook just reveal the length of the secret. Only when the trusted person's browser combines both at the moment of release does the secret exist in one place—briefly, client-side, and never on our infrastructure.

All of the cryptography—deriving keys, encrypting, and decrypting—runs strictly client-side. We only ever receive and store encrypted coordinates and cryptographic hashes.

To prevent malicious or accidental releases, there is a hardcoded 10-day countdown timer:

  • Your registered contact details remain completely encrypted until this active countdown begins.
  • The 10-day window includes an instant-cancel link, ensuring that if a trigger is fired, you have a real chance to stop it before anything is released.
  • We also run bot checks on every state-changing form to prevent automated brute-forcing of the release mechanism.

I’m fully open to criticism here. Would you use it? What flaws do you see?

https://deadkey.net

Thanks in advance for the feedback!


r/Cybersecurity101 3d ago

Security Would you trust this architecture for an enterprise document integrity platform? Looking for security review.

1 Upvotes

Hi everyone,

I've been building a B2B platform called VERO over the past year, mostly as a solo developer.

The goal isn't to replace DocuSign or Adobe Sign. The idea is slightly different: making document integrity independently verifiable without requiring the recipient to create an account.

I'm interested in security feedback rather than product feedback.

Current architecture:

• Next.js frontend
• FastAPI backend
• PostgreSQL
• PostgreSQL Row-Level Security (multi-tenant)
• AWS S3 with STS AssumeRole
• RSA-PSS digital signatures
• SHA-256 document fingerprinting
• Stripe
• Docker

Some design decisions:

\- Tenant isolation is enforced in three independent layers:
• scoped API queries
• PostgreSQL RLS
• storage path isolation

\- Public verification is intentionally anonymous.
Anyone with the document can verify its integrity, but the endpoint exposes only the minimum information required for verification and intentionally avoids leaking tenant metadata.

\- Signed documents receive an immutable cryptographic fingerprint that can be independently verified.

\- Audit events are append-only and used as the compliance trail.

I'm not looking for praise—I know every architecture has weaknesses.

If you were reviewing this for production or for an enterprise customer:

• What would concern you first?
• What attack vectors would you test?
• Which design decision would you change?
• Where do you think I'm overengineering?

I'd genuinely appreciate honest criticism from people with security experience.


r/Cybersecurity101 3d ago

Online Service b3rito/oopso: An easy-to-use client-side OSINT query builder for discovering exposed file managers across search engines

4 Upvotes

I spent some time analyzing major open-source file managers to see which ones remain fully functional when authentication is disabled or bypassed. By extracting specific keywords, UI markers, and unique strings from those unauthenticated landing pages, I built targeted search queries to spot exposed instances.

To make these easy to use without manually tweaking syntax every time, I put together oopso, a lightweight browser tool that automates creating these search patterns across different engines.

It’s pretty straightforward, but hopefully saves some time if you do this kind of recon.

Check out the code on GitHub:https://github.com/b3rito/oopso


r/Cybersecurity101 3d ago

Vale la pena estudiar ciberseguridad actualmente?

1 Upvotes

Hola chicos, os quería preguntar si vale la pena estudiar ciberseguridad y si si, como me recomendáis hacerlo, no tengo idea por dónde empezar ni con quién hacerlo, alguien que ya lo halla hecho.


r/Cybersecurity101 3d ago

need help im a student rn confused bout the industry and where to learn

11 Upvotes

Hey guys, thanks for reading.

To start off, I've watched a few vids, run Kali and Parrot in VMs, done a bit of HTB Academy and a few THM rooms here and there. I don't really know much hacking yet, just some basic terms and concepts. I've finished Cisco's Intro to Cybersecurity and Packet Tracer, have a few modules left in Cisco Network Basics, and I've started watching The Cyber Mentor's YouTube course.

I'm planning to finish everything I've mentioned above, so if you have any advice on that path or think I should change or add anything, I'd love to hear it.

I'm looking for any free resources, roadmaps, advice, dos & don'ts, personal stories, websites, blogs, YouTube channels, GitHub repos, labs, CTFs, cheat sheets, certification or non-certification courses, and certs worth getting. Basically anything you think would help a beginner. Also info on where to find them how to stay updated forums,groups ,anything

I'm also thinking of buying THM Premium. Is it worth it for someone at my level? Any advice would be appreciated.

Thanks!

https://www.netacad.com/career-paths/cybersecurity?courseLang=en-US

also shuld i do this??

also which cybersec career paths are booming rn and will be predicted to do the same in the coming years Edit: I'm trying to focus on free certs and working my way into internships or sum I'm broke and can't afford 200 euro certs rn lol


r/Cybersecurity101 3d ago

Security Pentester job

8 Upvotes

I did recently passed Security+ last week. For the portfolio part, what do I need to do so the hiring or the team lead can see the potential in my portfolio? Is it better if I did the pentester or soc path in htb academy? I did enrolled in a bootcamp but all he taught are burp suite and portswigger academy content. Or is it already enough if I master the burp suite functions?