Why I’m Solving Cyber (Hayden)
Cybersecurity isn't a collection of answers.
It's a way of thinking.
I didn't start my career believing that.
If you'd asked me twenty years ago what separated good cybersecurity professionals from everyone else, I probably would have given you a shopping list.
Certifications.
Technical knowledge.
Experience.
Maybe a few vendor products if I was feeling particularly confident.
None of those answers were wrong.
They just weren't answering the question I should have been asking.
Looking back, I've been wondering whether that's how almost everyone begins.
We assume cybersecurity is like assembling a toolkit. Walk down the vendor booth aisle at an RSA conference. Decide who has the better booth advertising that day. Purchase their tool. Come back next year and do it again.
Somewhere along the way it's easy to start believing that enough tools eventually become understanding.
For a while, that feels true.
You pass an exam.
You finally understand why DNS behaves the way it does.
You discover a command you've somehow managed to live without.
Every one of those moments feels like progress.
Then, almost without noticing, something changes.
You find yourself in an incident meeting where nobody really knows what's happening.
A vendor says one thing.
The logs suggest something else.
Everyone in the room is looking at the same evidence.
Nobody agrees on what it means.
I remember sitting in meetings like that thinking, "Well... this is awkward."
Not because somebody had made a mistake.
Because everybody had enough evidence to sound convincing.
That stayed with me.
Over the years I've gradually realised that the answers themselves aren't really the difficult part of cybersecurity.
The difficult part is knowing what to do when the answers don't line up.
And they often don't.
Every few years the profession seems to rearrange itself.
Cloud changed the conversation.
CASB roared into the RSA vendor aisles and suddenly every vendor had one.
Then ransomware became the problem every product claimed it could solve.
There was a period where I noticed something that still makes me smile.
If a vendor told me their product used machine learning, there was a reasonable chance someone had actually written some Python.
If they told me it used AI...
...there was an even better chance it had been written in PowerPoint.
Now we've reached the stage where every second product seems to have become an AI platform overnight.
IPv6 spent years sitting patiently in the wings before quietly becoming someone else's deployment project.
Today it's AI but Quantum computing is already waiting for its turn to dominate conference keynotes.
The technology keeps moving.
Maybe that's why I've become less interested in memorising answers and much more interested in how people reason through uncertainty.
That thought had been sitting quietly in the back of my mind for years.
Then Brian sent me an email.
People ask me how to get into cybersecurity reasonably often.
Usually they're looking for directions.
Which certification?
Which job?
Which path?
Brian's email felt different.
I finished reading it and realised he wasn't really asking for directions at all.
He wanted to understand how people actually become good at this profession.
That made me want to reply.
One of the first things I wrote back has stayed with both of us ever since.
I can teach you cybersecurity.
I can't understand cybersecurity for you.
I wish mentoring worked differently.
It would certainly save everyone a lot of time.
But understanding has this annoying habit of arriving on its own schedule.
Usually after you've broken something.
Or misunderstood something.
Or spent two hours convinced you were right before discovering you weren't.
It's frustrating.
I still don't particularly enjoy being wrong.
But most of the lessons I've kept seem to have started exactly there.
A few weeks later we'd exchanged another email.
Then another.
Somewhere along the way we stopped talking about certifications and started talking about investigations, governance, AI, incident response, and why people make the decisions they do.
Looking back, I think SolvingCyber quietly grew out of those conversations.
I've noticed something similar whenever I've interviewed people over the years.
Early in my career I paid a lot of attention to certifications.
I still do.
I have quite a few myself.
Some of them taught me a great deal.
But somewhere along the way I realised I was listening for different signals.
Who keeps investigating after everyone else thinks they've finished?
Who builds something simply because they wanted to understand it?
Who writes notes that another person can still follow six months later?
Who is comfortable saying,
"I don't know yet."
Those questions have gradually become much more interesting to me than asking which
certification someone plans to earn next.
I suspect that's one of the reasons SolvingCyber exists.
Yes, it's a blog.
Hopefully it becomes something a little more interesting than that.
Over time, I hope it becomes a body of work.
Something people can wander through rather than simply read.
Not because every article will be perfect.
Because taken together they'll show how our thinking changes over time.
Increasingly, the best measure of a professional isn't what's written on their resume.
It's the quality of the work they leave behind.
Brian and I are approaching the same profession from opposite directions.
He's documenting what it's like to enter cybersecurity.
I'm still trying to make sense of what it looks like after more than two decades.
Those perspectives don't compete.
If anything, they keep each other honest.
You'll probably notice that many of our articles appear in pairs.
Brian might write about building a home lab, working through a TryHackMe learning path, or
documenting his first investigation.
I'll often write about why I encouraged those activities in the first place and what I think
they're teaching beneath the surface.
I don't really see my role as validating Brian.
That would be missing the point.
What's much more interesting, at least to me, is understanding why certain habits seem to
produce capable cybersecurity professionals over time.
None of those habits are particularly mysterious.
They're available to anyone willing to practise them.
I fully expect we'll change our minds.
In fact, I'd be a little disappointed if we didn't.
Technology moves too quickly for certainty to age well.
If we revisit something we wrote a year earlier because we've learned something new, I'll take that as progress rather than embarrassment.
If there's one thing I hope readers take away from SolvingCyber, it isn't that we've figured cybersecurity out.
I'd much rather they leave thinking a little differently than when they arrived.
Cybersecurity isn't a collection of answers.
It's a way of thinking.
That's what we're here to explore.