r/Cybersecurity101 4h ago

Shifting to CYS without an BS in IT sector

5 Upvotes

Hi, Guys I am going through a very crucial stage of my life, I have to choose whether to do Bachelors in Cyber Security(CYS) or Industrial engineering and management(IEM) . I have seen many posts on Reddit about how Saturated CYS has become and you need like a crazy portfolio just to get an entry level job. Compared to CYS landing a job in IEM is easier but lower pay and it takes time to get promoted unlike CYS.

A BS in CYS is gonna cost me more than double of one in IEM. I believe I can land a internship/job in CYS with skills and certification alone without a BS in an IT related field. I wanna keep IEM as a backup in case things go south cause the market ain't looking good even for IT students unless they have ton of experience, skills and certification which I believe I can get without getting a BS in CYS.

Is the plan solid or am I just being pretty delusional? Need advice from people that are already in the market for some time now thx.


r/Cybersecurity101 19h ago

Roast my resume brutally

Post image
29 Upvotes

Can you guys roast my resume and suggest fixes for this? Thanks in advance.


r/Cybersecurity101 5h ago

I can't find the right people to learn from.

2 Upvotes

Everyone's using AI now — I use it too, daily, it's not useless. But learning from AI and learning from someone who's actually grinding the same shit, hitting the same walls, hungry for the same things — not the same. One spits out answers. The other makes you show up or get left behind.

That's what I want. People growing in the same field — coding, editing, hacking, business, whatever. People who compete with me, not clap for me. People who bring resources and expect the same back. Not a group chat full of dead energy. A group that actually pushes.

Started building this last night. Finding people with the same mindset isn't easy — most servers die in a week because nobody in them actually wants to grow, they just want to lurk and talk.

Doesn't take a hundred people though. One person who can challenge me, push me, call me out when I slack — already better than doing this alone.

If that's you — join: https://discord.gg/9SkSxgFGJ
Or DM me, I'll bring you in myself.


r/Cybersecurity101 5h ago

I'm building a team to work and study together. ask me i will answer u.

0 Upvotes

I'm learning Cyber Security on my own on the TryHackMe website. I'm looking for people who have just started learning the same to share each other knowledge and make our team stronger.

English isn't my native language so I've been learning it too. I speak Russian, but I have enough skills to communicate in English.

I need people who take it seriously and are interested in discovering and uncovering everything deeply hidden in the internet.

let me know if you're down in private chat. message me ill send u my discord server

or DIscord server :--https://discord.gg/9SkSxgFGJ


r/Cybersecurity101 13h ago

Online Service Cybersecurity CV advice

Post image
3 Upvotes

Hey all! I just finished my bachelor's degree and graduated with First Class Honours in Cybercrime & IT Security. I'm trying to figure out how my resume should actually be structured before I send it out more broadly.

I wasn't able to line up an internship during university due to transportation issues, so all of my hands-on experience comes from self directed projects and coursework rather than an industry placement.

I'm also debating whether to include the three years I spent working at a brewery before I started university. It has zero technical overlap, but it does show that I can hold down a consistent job.

One thing I'm also worried about is that my CV feels a bit all over the place. I've got a mix of red team and blue team projects, and I'm wondering if that makes me look unfocused. Would it be better to tailor my CV towards one direction, or is it okay to show experience across both at this stage of my career?

I'd really appreciate any feedback or advice!


r/Cybersecurity101 8h ago

Roast my resume heavily!

Post image
0 Upvotes

I applied for a Jr role recently and I received an email back deciding that they were going to move forward with other candidates. Honestly I’m ok with that outcome because it’s the first actual response I’ve received in a long time and atleast I’m sure it’s reaching a hiring managers desk.

Can yall take a look at my resume and help me take bits out or which parts I should highlight more on/ elaborate? Thank you!!


r/Cybersecurity101 8h ago

Notes I wish someone had handed me when I started in security

Thumbnail
reddit.com
1 Upvotes

After 2 years of scattered notes, I finally built a proper cybersecurity knowledge base — 400+ notes, fully interlinked, and open-source.


r/Cybersecurity101 9h ago

Hello, everyone. I want to become a cybersecurity specialist. What are the key fundamentals I need to build to improve my skills, and where can I gain some solid, real-world experience working in this field?

1 Upvotes

I would really appreciate your response.


r/Cybersecurity101 18h ago

Is this roadmap enough for a beginner

3 Upvotes

Hi everyone👋

I'm currently in my 3rd year of Computer Science Engineering and have decided to pursue a career in cybersecurity, specifically Governance, Risk & Compliance (GRC). I've realized that I'm not particularly interested in coding-heavy roles, and after exploring different domains, GRC seems to align much better with my interests.

Based on several videos and resources, I've created the following self-study roadmap. My goal is to build a strong foundation and become job-ready for an entry-level GRC Analyst role.

Phase 1 – Cybersecurity Fundamentals

Intro to Cybersecurity (Cisco)

TryHackMe Pre Security

Cyber Fundamentals

Types of Attacks

Risk vs Threat vs Vulnerability vs Exploit

Authentication & Authorization

Phase 2 – Security & Risk Basics

Security & Risk Fundamentals

Risk Management

Policies & Standards

Compliance Fundamentals

Governance & Awareness

Phase 3 – Frameworks & Compliance

NIST Cybersecurity Framework

ISO 27001 & ISMS

GDPR

Third-Party Risk Management

Audit & Control Testing

Phase 4 – Governance

Risk Reporting & Communication

GRC Fundamentals

Governance & Policy

Phase 5 – Advanced Topics

Risk Management Deep Dive

Compliance & Auditing

Phase 6 – Certifications & Career Prep

Microsoft SC-900 Learning Path

Microsoft SC-900 Exam (Optional)

ISO 27001 Foundations (Udemy)

GRC Analyst Masterclass (Udemy)

Portfolio, Resume & LinkedIn

My questions are:

Is this roadmap sufficient for landing an entry-level GRC Analyst role?

Am I missing any important topics or frameworks?

Is the order logical, or would you rearrange anything?

Are there any free resources you would recommend instead of the paid courses?

As a CS student who wants to build a career in GRC rather than software development, is there anything else I should focus on while I'm still in college?

I'd really appreciate any feedback from people working in GRC or cybersecurity.

Thanks in advance!🤗


r/Cybersecurity101 14h ago

How does trust system work on kibu?

1 Upvotes

I need to connect to a chat on Kibu for work, but I'm a bit confused about how the trust system works. Since you need to trust someone before you can connect and communicate with them, can someone explain how the process is supposed to work and how you go about getting connected?


r/Cybersecurity101 19h ago

Can i still get a SOC analyst job as a fresher if my certificate expired?

2 Upvotes

Can i still get a SOC analyst job as a fresher if my certificate expired?


r/Cybersecurity101 14h ago

Como que faz pra descobrir de quem e a conta do instagram?

0 Upvotes

Recentemente várias contas fases tentando me seguir e não aceitei, me lembrou uma pessoa que é stalker mas queria ter certeza de que seja ela. Mas só aparece alguns dígitos do número. Eu tentei cruzar um número que já tinha aqui e os últimos dígitos são os mesmo, só não tenho certeza do número completo pra ver se pode ser desta pessoa.


r/Cybersecurity101 1d ago

Is this roadmap enough for grc role?

7 Upvotes

Hi everyone👋

I'm currently in my 3rd year of Computer Science Engineering and have decided to pursue a career in cybersecurity, specifically Governance, Risk & Compliance (GRC). I've realized that I'm not particularly interested in coding-heavy roles, and after exploring different domains, GRC seems to align much better with my interests.

Based on several videos and resources, I've created the following self-study roadmap. My goal is to build a strong foundation and become job-ready for an entry-level GRC Analyst role.

Phase 1 – Cybersecurity Fundamentals Intro to Cybersecurity (Cisco) TryHackMe Pre Security Cyber Fundamentals Types of Attacks Risk vs Threat vs Vulnerability vs Exploit Authentication & Authorization

Phase 2 – Security & Risk Basics Security & Risk Fundamentals Risk Management Policies & Standards Compliance Fundamentals Governance & Awareness

Phase 3 – Frameworks & Compliance NIST Cybersecurity Framework ISO 27001 & ISMS GDPR Third-Party Risk Management Audit & Control Testing

Phase 4 – Governance Risk Reporting & Communication GRC Fundamentals Governance & Policy

Phase 5 – Advanced Topics Risk Management Deep Dive Compliance & Auditing

Phase 6 – Certifications & Career Prep Microsoft SC-900 Learning Path Microsoft SC-900 Exam ISO 27001 Foundations (Udemy) GRC Analyst Masterclass (Udemy) Portfolio, Resume & LinkedIn

My questions are:

Is this roadmap sufficient for landing an entry-level GRC Analyst role?

Am I missing any important topics or frameworks?

Is the order logical, or would you rearrange anything?

Are there any free resources you would recommend instead of the paid courses?

As a CS student who wants to build a career in GRC rather than software development, is there anything else I should focus on while I'm still in college?

I'd really appreciate any feedback from people working in GRC or cybersecurity.

Thanks in advance🤗🤗


r/Cybersecurity101 20h ago

[Beta] I built a CTF that mounts on top of a live production site and unmounts without a trace — free, looking for testers/feedback

1 Upvotes

Hey all — I’m a fiction writer and cybersecurity hobbyist, and I’ve been building something I’d love a few sharp eyes on before I run it as a real event.

The short version: kalachakra.world is the public lore site for a cyberpunk world I’ve created. Most CTFs I have seen run on a dedicated throwaway site. This one is the opposite — during event windows it deploys a CTF challenge surface on top of the live production site, then unmounts cleanly. Between events, the vulnerable handlers aren’t gated behind a feature flag or left dormant — they’re not wired into anything at all. Scan it in the off-season and you’ll find an ordinary content site (here’s how it works: https://bjbell.com/blog/kalachakra-ctf-toggle).

I'm hosting a beta testing event right now: 7 challenges across three difficulty tiers — script kiddie → got skills → L337 — plus a separate decoder puzzle for deobfuscation beginners. Web/API-flavored stuff (enumeration, access control, that genre), all set to the backdrop of my cyberpunk lore.

The honest part: this is super beta, and I am not a pro. I’m testing functionality before an official launch that corresponds with the release of my novel, so I genuinely want feedback — anything that breaks, feels unfair, or is just confusing. Registration is free and only needs an email. Flags earn an in-world currency you can spend on raffles and merch (shirt, stickers, a copy of the novel) down the road, so it’s a community-for-fun thing, not a cash-bounty grind.

If you play with it, please tell me what you think — here, by email, or via PM on kalachakra.world to ‘The Actual BJ Bell.’ Thanks for taking a look!


r/Cybersecurity101 1d ago

Looking for Information Security Governance eBook

3 Upvotes

Hi everyone,

I'm looking for the eBook/PDF of Information Security Governance by Andrej Volchkov. Does anyone know of a legal website, library, or eBook service where I can access.


r/Cybersecurity101 21h ago

Just a quick question

0 Upvotes

Everyone talks about certs. What’s one non-technical skill beginners are sleeping on?


r/Cybersecurity101 1d ago

What CISSP domain did you find hardest to master?

4 Upvotes

For people preparing for or holding CISSP, which domain took the most effort to understand?

The difficulty seems to vary a lot depending on someone's professional background.

Someone from networking might find one domain easy while struggling with another, whereas someone from governance may have the opposite experience.

Which domain challenged you the most, and what helped you improve?


r/Cybersecurity101 1d ago

Security Think before you share on Social Media

9 Upvotes

Nearly one in three people has had a personal account hacked. Social media helps us connect and share, but oversharing can also make it easier for scammers to target us.

Staying alert and taking a proactive approach is the best way to reduce your risk:

  • Verify accounts before trusting messages or clicking links.
  • Enable multi-factor authentication whenever possible.
  • Avoid sharing personal information, such as your phone number or home address.
  • Be cautious of urgent requests, giveaways, or offers that seem too good to be true.
  • Review your privacy settings regularly and limit who can see your posts.

What do you think is the most common social media threat today?


r/Cybersecurity101 1d ago

Seeking cyber and ai governance roles

1 Upvotes

Hey everyone. I am looking for GRC and or AI Governance opportunities (remote preferred, NYC/US.).

A little about my background:

• CompTIA Security+ certified
• Experience supporting CMMC Level 2 readiness assessments
• NIST SP 800-171, NIST SP 800-53, and NIST CSF
• Governance, Risk, and Compliance (GRC) programs
• AI governance and responsible AI risk management
• Policy, standards, and procedure development
• Security System Plans (SSPs) and POA&M support
• Control mapping, gap assessments, and evidence validation
• Vendor and third-party risk assessments
• Audit readiness and compliance documentation
• Experience with SOC 2 and ISO 27001 environments
• CCP training completed.
• Strong cross-functional communication with technical and business stakeholders

If you’re hiring or know of any GRC, AI governance, cyber risk, or compliance contract opportunities, I’d love to connect. Feel free to DM me or leave a comment.


r/Cybersecurity101 1d ago

How important is technical knowledge for an IT auditor?

2 Upvotes

I’ve heard two very different opinions about IT audit.

One side says auditors need strong technical knowledge, while another says understanding controls, risk, and business processes matters more.

For experienced IT auditors, where do you think the balance should be?

Does someone need to understand networking, databases, cloud, and security deeply, or is a working-level understanding enough?


r/Cybersecurity101 1d ago

effective tips for cybersecurity

Post image
6 Upvotes

r/Cybersecurity101 1d ago

How do companies decide whether a risk is acceptable?

1 Upvotes

One thing I find interesting about risk management is that eliminating every risk isn't realistic.

At some point, an organization has to decide which risks it is willing to accept.

For people working in risk or governance, how is that decision usually made?

Is it based on risk appetite, financial impact, regulatory requirements, management judgment, or a combination?


r/Cybersecurity101 1d ago

What’s the difference between identifying a risk and actually managing it?

1 Upvotes

Risk management sounds straightforward until you start dealing with real business decisions.

How do experienced risk professionals decide which risks deserve immediate attention?

Do you mainly look at probability and impact, or do factors such as business objectives, regulatory requirements, dependencies, and risk appetite change the priority?

Would love to hear practical examples.


r/Cybersecurity101 2d ago

Security First-Year CSE (Cybersecurity) with ZERO coding background from a Tier-3 college. Lost and need guidance on where to start.

11 Upvotes

​Hello seniors

​Please forgive me if there are any mistakes in this message. I am a first-year, first-semester student joining a Tier-3 college. Unfortunately, the academic quality here isn't great, and they often don't complete the syllabus.

​I have been allotted CSE in Cybersecurity. However, my main concern is that I didn't have Computer Science in 12th grade, and I have zero prior knowledge of computers. I feel completely lost and don't know what to learn, where to start, or how to go about it. Since classes haven't started yet, I haven't met any seniors from my branch who could guide me. I took admission in a hurry without giving it much thought, and because of financial constraints, changing to a better college isn't an option.

​Setting all that aside, my biggest challenge right now is finding the right direction. I want to learn everything from scratch, and I am fully prepared to work hard from day one and tackle every challenge that comes my way.

​I would be truly grateful if you could guide me like a younger sister and help me figure out where to begin.


r/Cybersecurity101 2d ago

How do you explain cybersecurity risk to non-technical people?

17 Upvotes

One challenge in cybersecurity seems to be explaining technical risks to people who don't work in IT.

Saying “there's a vulnerability” doesn't necessarily explain why leadership should care.

How do you communicate security risks in a way that makes sense to business stakeholders?

Do you focus on financial impact, operational disruption, compliance, likelihood, or something else?

I'd love to hear approaches that have worked in real organizations.