Failing Upwards

One of the phrases my early boss in pentesting taught me and adopted was failing upwards in a career.
This leads to hard decisions between hanging up part of your subject matter expertise and focusing on managing and leading teams or do you continue down the route of honing your skills.
The cliche phrasing around a good manager vs. a good leader has never stuck with me, but the sentiment of looking at leading and helping your team excel in every way you can is something I have learned from having good bosses and managers in the past.
Being able to tell the difference and learn from both to better yourself is equally important.
I started working in offensive security as an intern focused on learning the ropes in penetration testing; I then moved to a junior penetration tester position with a short stint in-between in technology and information risk at a bank, the stark contrast between working in a bank vs. consultancy was apparent in my first few interactions within pentesting.
I began pen-testing on my first day working for SecureWorks; I was given two laptops, a Nessus license, a burp license, and the task of building me a 'go to war' laptop, which SecureWorks called their pentester laptops.
Luckily, before this job, I had spent years working at a computer shop building and breaking systems, so I had extensive experience building laptops and installing stuff, configuring things in a manner that was usable and expandable; it was the first time I had given the independence to go build my own laptop for a work setting.
Still, I would go away and learn; I'd never done one, nor had I been to Norway, so it was a fun experience and pretty representative of winging it.
I learned from my second week on the job that thinking on your feet, learning new technologies, and solving problems was where I wanted to be in that moment.
I learned many things from that particular engagement and client many years on.
The skills we learn from difficult situations shape a lot of what we end up doing day to day.
I followed a manager whom I learned a lot from and saw as a leader.
From the initial team at SWX, we built a team in Scotland; what started as just him and I quickly grew into a ten-strong team.
Outside of security, while I was learning the basics and building upon them, I was honing other crafts; martial arts are very prevalent among security professionals as an escape to exercise creativity and physical excursion.
Teaching karate to kids aged 6-11 was an interesting experience, particularly in developing effective teaching methods and learning the importance of leading by example.
A significant part of this teaching role involved helping these young learners distinguish their left from right.
Back in 2016, there was an opportunity to take over a team and build it out even further; his words to me back then were you are going to do great things, but this is not what you want right now, do not hang your tools up, go forth and hone that creativity.
As I learned a lot of different paths in pentesting with a primary focus on web apps, I moved into learning infrastructure and leveraging both skill sets, which you will see in my historical blog posts.
I built out a personal brand and learnt about the go giver, so I focused my efforts on passing on as much as possible; my learning style is to teach so you can learn better, which has helped me a ton.
You can lead a horse to water but can't force it to drink; sometimes, you just need to waterboard that horse to make it understand.


This Cyber News was published on blog.zsec.uk. Publication date: Sun, 28 Jan 2024 17:13:04 +0000


Cyber News related to Failing Upwards

Failing Upwards - One of the phrases my early boss in pentesting taught me and adopted was failing upwards in a career. This leads to hard decisions between hanging up part of your subject matter expertise and focusing on managing and leading teams or do you continue ...
5 months ago Blog.zsec.uk
CVE-2020-10265 - Universal Robots Robot Controllers Version CB2 SW Version 1.4 upwards, CB3 SW Version 3.0 and upwards, e-series SW Version 5.0 and upwards expose a service called DashBoard server at port 29999 that allows for control over core robot functions like ...
4 years ago
CVE-2020-10264 - CB3 SW Version 3.3 and upwards, e-series SW Version 5.0 and upwards allow authenticated access to the RTDE (Real-Time Data Exchange) interface on port 30004 which allows setting registers, the speed slider fraction as well as digital and analog ...
2 years ago
US DOJ applies carrot-and-stick approach to Foreign Corrupt Practices Act policy - The US Department of Justice has taken a carrot-and-stick approach to its corporate enforcement policy in regard to the Foreign Corrupt Practices Act in an effort to entice companies to self-report when in violation of the FCPA. Assistant Attorney ...
1 year ago Csoonline.com
Ransomware Attacks: Are You Self-Sabotaging? - In 2023, recovering from a ransomware attack cost on average $1.82 million-not including paying any ransom-and some organizations get hit more than once. If you're hit, you generally have to choose between paying that ransom or restoring your data ...
6 months ago Cybersecurity-insiders.com
Failing Upwards: Put on your own mask before assisting others - From poor leaders, I've learned what doesn't work: breaking the team's trust, operating without transparency, employing a destructive and unempathetic approach, micromanaging, and setting people up for failure. In contrast to the negative leadership ...
5 months ago Blog.zsec.uk
Advanced ransomware campaigns expose need for AI-powered cyber defense - In this Help Net Security interview, Carl Froggett, CIO at Deep Instinct, discusses emerging trends in ransomware attacks, emphasizing the need for businesses to use advanced AI technologies, such as deep learning, for prevention rather than just ...
7 months ago Helpnetsecurity.com
Why Demand for Tabletop Exercises Is Growing - Cybersecurity drills come in many forms, including penetration testing, phishing simulations, and live-fire exercises, with some scenarios costing hundreds of thousands of dollars and running over several days or even weeks. The least complex of ...
4 months ago Darkreading.com
Report: Organisations Have Endpoint Security Tools But Are Still Falling Short on the Basics - Most IT and security teams would agree that ensuring endpoint security and network access security applications are running in compliance with security policies on managed PCs should be a basic task. A new report from Absolute Security, based on ...
1 month ago Techrepublic.com
How to Check if Your VPN is Working and Troubleshoot if It Won't Connect - Having issues while connecting to a Virtual Private Network (VPN) can be frustrating, as it can prevent you from accessing a variety of services. There are a few things that you should know and check before addressing the issue fully. In this ...
1 year ago Zdnet.com
CVE-2024-26909 - In the Linux kernel, the following vulnerability has been resolved: soc: qcom: pmic_glink_altmode: fix drm bridge use-after-free A recent DRM series purporting to simplify support for "transparent bridges" and handling of probe deferrals ironically ...
2 months ago Tenable.com
English council spent £1.1 million recovering from ransomware attack - Gloucester City Council in the West Midlands of England was forced to spend more than £1.1 million to recover from a ransomware attack in December 2021, according to the published agenda of a council meeting that took place on Monday. The meeting ...
7 months ago Therecord.media
MixModes Approach to Combating The Growing Threat of Identity-Based Attacks on Enterprise Organizations - In today's interconnected digital landscape, enterprise organizations are increasingly vulnerable to identity-based threats. According to recent studies, over 80% of data breaches are attributed to compromised credentials, highlighting the critical ...
6 months ago Securityboulevard.com
Binance Changpeng Zhao Refused Leave US - US judge refuses to allow Binance founder Zhao to travel to UAE, despite pledge of $4.5 billion equity stake in Binance. Binance's founder and former CEO Changpeng Zhao has had to remain in the United States, after a judge ruled against his request ...
5 months ago Silicon.co.uk
White House hosts Counter Ransomware Initiative summit, with a focus on not paying hackers - The third annual White House-led counter ransomware summit convening 48 countries, the European Union and Interpol launches in Washington today, featuring several new elements including a pledge from most member states not to pay ransoms and a ...
7 months ago Therecord.media
CVE-2020-9391 - An issue was discovered in the Linux kernel 5.4 and 5.5 through 5.5.6 on the AArch64 architecture. It ignores the top byte in the address passed to the brk system call, potentially moving the memory break downwards when the application expects it to ...
2 years ago
CVE-2022-37865 - With Apache Ivy 2.4.0 an optional packaging attribute has been introduced that allows artifacts to be unpacked on the fly if they used pack200 or zip packaging. For artifacts using the "zip", "jar" or "war" packaging Ivy prior ...
1 year ago
BlackCat claims attack on Fidelity National Financial The Register - Fortune 500 insurance biz Fidelity National Financial has confirmed that it has fallen victim to a "Cybersecurity incident." The services we provide related to title insurance, escrow and other title-related services, mortgage transaction services, ...
7 months ago Theregister.com
U.S. No Fly List Breach: Government Investigating - A U.S. No Fly list with over 1.5 million records of banned flyers and upwards of 250,000 selectees has been shared publicly on a hacking forum. BleepingComputer has confirmed the list is the same TSA No Fly list that was discovered recently on an ...
1 year ago Bleepingcomputer.com
CVE-2018-0228 - A vulnerability in the ingress flow creation functionality of Cisco Adaptive Security Appliance (ASA) could allow an unauthenticated, remote attacker to cause the CPU to increase upwards of 100% utilization, causing a denial of service (DoS) ...
10 months ago
Long Beach, California turns off IT systems after cyberattack - The Californian City of Long Beach is warning that they suffered a cyberattack on Tuesday that has led them to shut down portions of their IT network to prevent the attack's spread. Long Beach is the home to approximately 460,000 people and is the ...
7 months ago Bleepingcomputer.com
Manchester cops in hot water over uncleared FOI requests The Register - Greater Manchester Police must clear the backlog of hundreds of Freedom of Information Act requests - some years old - or find itself in contempt of court. So says Britain's data watchdog, the Information Commissioner's Office, which is today issuing ...
6 months ago Go.theregister.com
Blockchain dev's wallet emptied in "job interview" using npm package - The recruiter in question asked the developer to download npm packages from a GitHub repository, and hours later the developer discovered his MetaMask wallet had been emptied. Take-home job exercise empties dev's crypto wallet. Moments later, the ...
6 months ago Bleepingcomputer.com
Ban on ransomware payments? The alternative isn't working The Register - Emsisoft has called for a complete ban on ransom payments following another record-breaking year of digital extortion. On average, these attacks cost targets about $1.5 million to rectify. This included 46 American hospital systems, 108 K-12 school ...
6 months ago Go.theregister.com
Why We Need Cybersecurity Whistleblowers - While some see the practice as noble, others may associate it with disgruntled employees seeking revenge on their employers. Despite the potential controversy, whistleblowers are an essential part of cybersecurity. When you take an objective, ...
5 months ago Feeds.dzone.com

Latest Cyber News


Cyber Trends (last 7 days)


Trending Cyber News (last 7 days)