What Mentorship in Cybersecurity Should Actually Look Like

One of the biggest changes in my own thinking surprised me.

Years ago, if someone had asked me how to get into cybersecurity, I'd probably have pointed them towards a university.

Get a cybersecurity degree.

That seemed like sensible advice.

I don't find myself saying that nearly as often anymore.

These days I'm more likely to suggest a library card, a YouTube Premium subscription, and a home lab that occasionally refuses to cooperate.

That's not because universities have stopped producing good graduates. They haven't.

It's because I've become increasingly interested in something else.

If someone wanted to take the opportunity to study cybersecurity at university, I'd still encourage them to take it.

I'd also encourage them not to mistake the degree for the whole of their education.

The degree gives you the foundation. The profession expects you to build the rest yourself.

What does someone do when they discover they don't understand something?

That question tells me far more than where they studied.

We all have gaps in our knowledge.

I certainly do.

The difference isn't having the gap.

It's what happens next.

Some people disappear into a book for a weekend.

Some vanish down a YouTube rabbit hole and emerge six hours later having learned something completely unrelated to what they intended.

Some build a home lab simply because they want to watch a technology fail with their own eyes.

I've known people who happily spend a Saturday reading RFCs that nobody asked them to read.

Sometimes because there was a community challenge in a discord server, hopefully it’s because they want to understand.

Over the years I've realised those moments are some of the strongest signals I look for when I'm interviewing, mentoring, or simply getting to know someone professionally.

Not how much they know today.

I'm much more interested in what they do tomorrow after discovering they don't.

Somewhere along the way I also found myself giving that behaviour a name.

Performative curiosity.

Every profession seems to have its own version of it.

Cybersecurity certainly does.

It looks remarkably convincing from a distance.

People enthusiastically tell you what they're planning to learn.

They've got a reading list.

They've bookmarked twenty videos.

They've bought three books.

Their browser has forty-seven tabs open.

Ask them six months later and...not much has changed.

The curiosity was genuine enough.

It just never turned into action.

I've gradually come to think of that as a curiosity gap.

The gap isn't between ignorance and knowledge.

It's between intention and action.

Real curiosity has a habit of leaving evidence behind.

A notebook full of observations.

A home lab held together with equal parts determination and bad decisions.

A Python script that almost works.

An incident report that's noticeably better than the previous one.

Questions that become more thoughtful over time.

Those things are difficult to fake.

They're also difficult to produce without doing the work.

That's why I've become increasingly suspicious of motivation as a measure of potential.

Motivation is easy to talk about.

Action is much quieter.

You usually discover it by accident.

Someone casually mentions the thing they spent Saturday afternoon trying to understand.

Or they send you a notebook full of screenshots because they wanted to show you where they got stuck.

Those moments tell me far more than enthusiasm ever could.

Closing a curiosity gap isn't glamorous.

It takes time.

It takes persistence.

It usually involves discovering that the thing you were absolutely convinced was true on Monday turns out to be completely wrong by Thursday.

I still don't enjoy those moments.

I doubt I ever will.

But when I look back over the ideas that genuinely changed how I think, most of them began exactly there.

Hayden Pritchard
Hayden Pritchard

I've spent much of my career helping organizations make difficult decisions about cybersecurity, governance, and risk.

That work has taken me through hospitals, regulated industries, boardrooms, investigations, and more standards documents than I'd care to admit. Along the way I've become increasingly interested in something that doesn't appear in most governance frameworks: how people actually think.

Here, I write essays rather than reports. I explore the ideas that stay with me long after the meeting ends: why frameworks often ask the same questions in different languages, why some human limitations may actually be strengths, and how emerging technologies quietly change the assumptions that regulation depends upon.

Professionally, my work focuses on AI governance, cyber risk, healthcare, and safety-critical systems.

Personally, I'm just trying to understand them a little better than I did yesterday.

https://www.solvingcyber.com
Previous
Previous

How 100 Tryhackme rooms made me the hottest guy in the room

Next
Next

How I skipped the line