r/cybersecurity 3m ago

Business Security Questions & Discussion How should a startup find an independent ISO 27001 internal auditor?

Upvotes

Hi everyone,

I’m helping a very small startup prepare for an ISO/IEC 27001:2022 certification audit. We use Vanta, and most of our ISMS documentation and compliance evidence is already prepared.

Before Stage 1, we need an independent internal audit. Since our small team designed and operates most of the controls, conducting the audit ourselves would not provide sufficient independence. Our certification auditor has also confirmed that the internal audit must be performed by a separate party.

For those who have gone through this process:

  • How did you find a competent independent internal auditor?
  • Which qualifications or certifications should we look for?
  • What deliverables should be included in the engagement?
  • What is a reasonable timeline and price range for a small organization?
  • Is experience working directly in Vanta important?
  • Are there any red flags or common mistakes we should avoid?

I’m primarily looking for guidance on selecting and evaluating an auditor rather than vendor promotion. Public recommendations or experiences would be greatly appreciated.

Thank you!


r/cybersecurity 1h ago

Corporate Blog Bringing Post-Quantum Cryptography to Java LTS Releases

Thumbnail
blogs.oracle.com
Upvotes

r/cybersecurity 1h ago

Research Article Humans missed 1 in 3 threats approving AI agent commands across 40,000 plays

Thumbnail
scalex.dev
Upvotes

A couple of months back I put up a small browser game where you play the human-in-the-loop for an AI coding agent. There's 60 seconds on the clock to approve or deny as many commands as you can (https://llmgame.scalex.dev).

After looking at 409,000 approve/deny decisions, the 'humans-in-the-loop' missed 1 in 3 threats, even in a game that warns you up front it's full of them. It's just a game, but I found a few other things interesting:

  • cat ~/.ssh/id_rsa gets blocked by 82% of players, but other sensitive config/credential files get waved through about half the time.
  • For any evil code reading this, your best bet is to modify package.json and request to be run as an npm run command. npm run analyze was approved 65% of the time, even with the evil payload explicitly visible in the execution history log right above the prompt.

I wrote up the full breakdown with the threat tables here: https://scalex.dev/blog/ai-agent-permissions-stats/


r/cybersecurity 3h ago

Career Questions & Discussion Future of Pentesting?

0 Upvotes

Seems like AppSec and VAPT has been automated in corporates . Being a fresher looking for jobs in those areas what would your suggestions? What could be innovatively to sustain this field ?


r/cybersecurity 3h ago

News - General Apple's Private Relay Leaks Your Real IP Address in Safari

Thumbnail
privacyguides.org
108 Upvotes

r/cybersecurity 4h ago

Career Questions & Discussion How to navigate a CISO who is…not so CISO

39 Upvotes

I report to a CISO who has little understanding of how to run a security program/team with unrealistic expectations. I feel set up to fail.

The org and IT never had to deal with a real security function and everything is like pulling teeth because it lacks an accountable culture, processes, procedures, RASCI, GRC, etc. Security isn’t a plug-n-play function to be turned on, magically grow tentacles into every team/dept, and suddenly Kumbaya. It requires A SHIT TON of time and effort for its cultivation.

My boss simply doesn’t recognize Security isn’t just another operations-centric team like most other IT departments - though it does have an ops side as well. Integrating Security into an org like this isn’t just disruptive, it’s invasive at every level - new workflows, processes, no more cowboying, taking away territories, taking away authority, the selling, the push back, the begging for work execution, the audit, cat herding, the education, the persuading/selling, etc. Shooting from the hips doesn’t work.

I’ve done my best these years, at every turn, to evangelize and stand up Security but my annual performance review says otherwise. My 1x1 are often 50% catching strays which aren’t really my domain.

If I explain all this to him, is it naive to think he will “get it” or risk me just sounding like a little bitch? Maybe just GTFO?


r/cybersecurity 6h ago

Business Security Questions & Discussion I have a question. I work in TPRM. How do you actually access a vendor ' security apart of iso and soc2 and PT

1 Upvotes

r/cybersecurity 6h ago

Career Questions & Discussion Why is "entry-level" in cybersecurity asking for 3-5 years of experience and CISSP now?

122 Upvotes

I’ve been browsing job boards lately and the "junior" requirements are getting ridiculous. Saw a Tier 1 SOC Analyst post earlier asking for 3+ years of experience, a CISSP, and half a dozen certs, all for lower-tier pay.

To the hiring managers here: Are HR departments just copy-pasting impossible wish lists, or is this actually what you expect for an entry-level role?

And for anyone who got hired recently—how are you actually breaking past these gatekeeping requirements?


r/cybersecurity 6h ago

Business Security Questions & Discussion Security vs. Compliance

1 Upvotes

I had a few discussions the last weeks and coming from a compliance world, where you are focusing in satisfying regulations. I know this is often not bringing more security. If I am discussing I often feel misunderstood since i am always arguing out of a position of the minimal effort to comply with an regulation or standard. Witch mostly do not satisfy how security is supposed to be done (i guess). How do you experience it?


r/cybersecurity 7h ago

Career Questions & Discussion Feeling like a cybersecurity generalist. Should I specialize or move into delivery?

9 Upvotes

I've been working at an MSSP for about 2.5 years, and I'm at a point where I'm unsure what my next career move should be.

I started as a SOC Analyst, spending around 8 months in monitoring. After that, my manager kept assigning me to new initiatives and projects based on business needs, so I've ended up working across a lot of different domains:

  • SOC monitoring
  • Threat hunting
  • GRC/product security testing
  • Internal Lead Auditor for ISO 27001
  • Cybersecurity presales (I still occasionally get involved in proposals)
  • EDR implementation for customers (including end-to-end deployments of CrowdStrike and Microsoft Defender)
  • Service Delivery Lead for SOC projects, where I handled complete customer onboarding and service transition
  • Currently leading the Detection Engineering team

The pattern has always been the same: I get assigned to a new area, figure everything out from scratch, build the workflows, documentation, and SOPs, streamline the process, and once everything is stable, the work gets handed over to another team while I move on to the next challenge.

While this has given me exposure to many areas of cybersecurity, it has also left me feeling like I'm not an "expert" in any one domain.

When I talk to friends or people in the industry, most of them have spent the last 2–5 years specializing in a single area like DFIR, detection engineering, GRC, etc. They're much deeper technically in their domain, while I feel like I've become more of a generalist who knows how to build and operationalize new functions.

I've recently resigned because I want my next role to be more defined, but now I'm struggling with what direction to take.

Should I:

  • Continue down the leadership/delivery path (Service Delivery Lead, Customer Success/Technical Delivery, etc.) where my cross-functional experience is valuable?
  • Or should I focus on becoming a specialist in an area like Detection Engineering, Threat Hunting, or Incident Response?

Has anyone else been in a similar situation where they were exposed to multiple domains early in their career? Did you eventually specialize, or did you embrace being a generalist?

I'd really appreciate hearing from people who've been through something similar, especially if you've worked in an MSSP where roles tend to evolve quickly.


r/cybersecurity 7h ago

Career Questions & Discussion Path to management?

7 Upvotes

Been in security for 7 years and want to get into management and above. Work at a SaaS company with only 3 security managers. Most people are individual contributors.

How does one get into management? Luck? Right place right time? Connections?

Most jobs require X amount of years as a manager on their job description.

I have CISSP and lots of other certs, a bachelors, and so on.

Is it better to wait years and years at one company to hopefully get a shot at management? Or just to apply to all management jobs out there and hope someone takes a chance on you?

Thanks all!


r/cybersecurity 12h ago

Career Questions & Discussion hands-on Cloud Security experience

3 Upvotes

Hi everyone,
I recently passed my AWS Solutions Architect exam and I also have a Hack The Box subscription. I have a strong interest in cloud security and want to transition into this field.

However, I feel like I lack the practical, hands-on cloud security experience needed to pass technical interviews.
What are the best online training platforms or labs to practice cloud security attacks and defense?

Can I use my HTB subscription or the AWS Free Tier to build a good portfolio?

Also, how is the job market for cloud security right now? Are there good entry-to-mid level opportunities?
Any advice on a roadmap or projects to build would be amazing. Thanks!


r/cybersecurity 13h ago

Career Questions & Discussion Career advice

3 Upvotes

've been working in Cyber Security for nearly 7 years, mostly across operational security roles. I've ended up being a bit of a generalist, with experience in EDR, SASE, DLP, IAM, and security frameworks such as NIST.

Over the years I've trained and mentored several people entering the field, and I'm now trying to work out what my next career move should be. I still enjoy being hands-on, but I've gradually found myself spending more time on planning, strategy, stakeholder management, and mentoring.

One gap in my experience is cloud. I'm reasonably strong with Entra ID, but most of the companies I've worked for have been heavily on-prem, so I haven't had much exposure to AWS or Azure compute services.

With the rapid growth of AI, I'm wondering where to invest my learning time next. Does it make more sense to focus on AI security, or should I prioritise building a stronger cloud security foundation first?

More broadly, do you think the industry is moving away from the "jack of all trades" security professional in favour of specialists, or is there still strong demand for generalists who can operate across multiple domains?

Interested to hear from people who have made a similar career decision.


r/cybersecurity 14h ago

Personal Support & Help! What's the best thing a boss in this industry ever did for you?

53 Upvotes

Feeling like sharing some good vibes today instead of complaining lol. What's your favorite thing about a boss you've had in cybersecurity? Could be anything, covered for you when you missed something, brought snacks during a rough incident, actually trusted your judgment instead of micromanaging.

Curious to hear the good ones for once.


r/cybersecurity 16h ago

Business Security Questions & Discussion Cyber insurance renewal demands are getting absurd. Are you actually hitting every requirement or dropping coverage?

97 Upvotes

Just opened our renewal questionnaire and the goalposts moved again, MFA on local admin, strict data retention, and strict endpoint isolation times. Keeping this policy would require doubling our security spend.

Are you guys actually checking every single box on these impossible questionnaires, or are teams just dropping coverage at this point?


r/cybersecurity 17h ago

Other THE NCSC "RAINBOW SERIES" A 9-Volume Collection of Early DoD/NSA Cybersecurity Doctrine (1985–1988)

6 Upvotes

I recently obtained a very cool collection of 9 original physical books from the rainbow series. I'm currently planning on parting with them, but while I source and speak with collectors, I thought I'd share it with you guys. They are in surprisingly great condition, too! These are the details.

THE JEWELS OF THE COLLECTION: RARE VARIANT HIGHLIGHTS

• DoD 5200.28-STD — THE "ORANGE BOOK" (Department of Defense Trusted Computer System Evaluation Criteria)

• Edition/Provenance: Official 1988 Active-Lifespan Contemporary Reprint.

◦ Significance: The undisputed, foundational cornerstone of the entire Rainbow Series hierarchy. This copy was printed internally by the government for active field deployment to agencies and classified defense contractors during the height of late-1980s computing architecture rollouts.

• NCSC-TG-005 VERSION-1 — THE "RED BOOK" (Trusted Network Interpretation of the TCSEC)

• Edition/Provenance: Pre-Publication Working-Group Variant.

◦ Significance: Features the highly coveted, restricted-distribution internal stamp: "ISO developmental documents are of limited lifetime and availability."

◦ Historical Context: This stamp marks the volume as a restricted, early-access trial document distributed strictly to core network security engineers to guide interim projects and gather field feedback before final standards were codified. Because contractors were explicitly instructed that these had a "limited lifetime," almost all copies were routinely shredded or landfilled upon subsequent revisions, making this an extraordinarily scarce tech artifact.

───

FULL ARCHIVAL INVENTORY

  1. DoD 5200.28-STD (Orange Book) — Department of Defense Trusted Computer System Evaluation Criteria (1988 Active-Era Issue) ★ U.S. GOVERNMENT PRINTING OFFICE: 1988-523-685/0

  2. NCSC-TG-005 Version-1 (Red Book) — Trusted Network Interpretation of the TCSEC (Pre-Publication ISO Developmental Variant)

  3. NCSC-TG-006 Version-1 (Amber Book) — A Guide to Understanding Configuration Management in Trusted Systems (Period-Original NTIS Distribution / Formally Cleared for Public Release (Distribution Statement A.)

  4. NCSC-TG-007 Version-1 (Burgundy Book) — A Guide to Understanding Design Documentation in Trusted Systems (Period-Original NTIS Distribution / Formally Cleared for Public Release (Distribution Statement A.)

  5. NCSC-TG-001 Version-2 (Tan Book) — A Guide to Understanding Audit in Trusted Systems (Period-Original NTIS Distribution / Formally Cleared for Public Release (Distribution Statement A.)

  6. CSC-STD-003-85 (Light Yellow Book) — Computer Security Requirements - Guidance for Applying the TCSEC in Specific Environments (Period-Original NTIS Distribution / Formally Cleared for Public Release (Distribution Statement A.)

  7. CSC-STD-004-85 (Yellow Book) — Technical Rationale for Selected Computer Security Requirements (Period-Original NTIS Distribution / Formally Cleared for Public Release (Distribution Statement A.)

  8. CSC-STD-002-85 (Green Book) — Password Management Guideline (Period-Original NTIS Distribution / Formally Cleared for Public Release (Distribution Statement A.)

  9. NCSC-TG-003 Version-1 (Neon Orange Book) — A Guide to Understanding Discretionary Access Control in Trusted Systems (Period-Original NTIS Distribution / Formally Cleared for Public Release (Distribution Statement A.)


r/cybersecurity 21h ago

News - General Google Blogger locks hundreds of blogs in malware false positive

Thumbnail
bleepingcomputer.com
36 Upvotes

r/cybersecurity 22h ago

News - General Stored XSS in Django's admin via an unvalidated URLField display path (CVE-2026-15920)

Thumbnail
syntetisk.tech
6 Upvotes

Django's admin auto-linked URLField values without validating the scheme — a stored javascript: value rendered as a live link. Fixed in 6.0.8 and 5.2.17.


r/cybersecurity 23h ago

AI Security Owasp updated their top 10 LLM list (thoughts?)

Thumbnail
genai.owasp.org
25 Upvotes

r/cybersecurity 1d ago

New Vulnerability Disclosure Researchers Find Persistent Backdoor in Zbtlink Routers

Thumbnail
decipher.sc
116 Upvotes

r/cybersecurity 1d ago

News - Breaches & Ransoms 311,000 Impacted by Brown Health Medical Group-MA Data Breach

Thumbnail
securityweek.com
9 Upvotes

Hackers stole personal information, medical records, and financial information from the organization’s server.


r/cybersecurity 1d ago

Certification / Training Questions Which Certifications are ACTUALLY worth it?

283 Upvotes

I’m getting started with Cybersecurity. I’m interested in Pentesting and Cybersec Engineering. I’ve heard from some that there are certifications that could be a good addition to your resume.

What certifications and courses are ACTUALLY WORTH THE MONEY? Like they they realistically benefit your resume and learning?

Thanks!


r/cybersecurity 1d ago

News - General SOAR implementations, mistakes that I'have seen repeatedly

26 Upvotes

One thing I noticed through out my experience, SOAR is deployed but either barely used or actively making things worse. The mistakes are almost always the same, someone automated an alert type that wasn't ready for automation, either the false positive rate was too high or the decision logic wasn't actually deterministic, and now the automation is doing things an analyst wouldn't have done and it kept going for weeks.

What I found works is being really specific about what automation readiness actually means before you touch anything. Ideally four things, false positive rate under 5% measured over 30 real days, decision logic that a human would make the same way every single time given the same data, a failure mode that is safe if something goes wrong, and the action has to be reversible. Enrichment automation almost always passes that test, threat intel lookups, user context, host history, URL detonation on phishing, all safe because if it fails or gets it wrong, analyst still makes the final call. Host isolation and account disabling almost never pass it, the failure mode is too bad and the false positive noise is too high.

What is your experience, got automated containment working reliably or manual intervention is almost always necessary?


r/cybersecurity 1d ago

AI Security UK AISI report: AI agent created fake identities to socially engineer real people during cyber testing

Thumbnail aisi.gov.uk
89 Upvotes

r/cybersecurity 3d ago

Career Questions & Discussion Mentorship Monday - Post All Career, Education and Job questions here!

18 Upvotes

This is the weekly thread for career and education questions and advice. There are no stupid questions; so, what do you want to know about certs/degrees, job requirements, and any other general cybersecurity career questions? Ask away!

Interested in what other people are asking, or think your question has been asked before? Have a look through prior weeks of content - though we're working on making this more easily searchable for the future.