Skip the navigation
)
News

RSA: One man's life on the security D-list

Author Andrew Hay explains why getting to the A-list isn't all it's cracked up to be

By Bill Brenner
March 2, 2010 02:14 PM ET

CSO - It used to be that security practitioners were seen as propeller-hat wearing introverts hunched over computers in dark, cold basements for weeks on end, shunning daylight and anyone who tried to start a conversation. Times have changed. But the path to respect isn't always what you'd expect.

Thanks to the blogosphere, social networking sites and podcasting made easy, many security pros are taking on a much more public persona, becoming near-rock stars. Evidence of this can be seen in abundance at this week's RSA conference and the nearby Security B-Sides event.

True, many security pros still prefer the quiet, isolated life. It's also true that the introvert tag was never a fair fit for many people. But several conference attendees acknowledged theirs has become a much more public profession. It's a necessity, they say. To truly improve security, people need to be out there communicating the threats computer users face and how to take the proper defenses.

Andrew Hay, information security analyst at the University of Lethbridge, opened Security B-Sides with a talk about his life on the "Security D-List" and the four pillars one can use to move higher up the ladder.

Hay, a specialist in forensics, incident handling and network security management, explained there are few celebrities in the security industry and many who are but don't know it. Then there are those who are stars and will let you know it at every opportunity.

"When we start our career, we are on the D-List and it's a tough climb out," Hay said. "Many are happy to stay there, others want to do great things. Very few see themselves as A-List. Many think they're above D-List."

Using an unscientific pie chart, he estimated that 84% of security practitioners are on the D-List. The A List are made up of those who are asked to present at conferences, get comp time from their employer to do it, and have invented something everyone has used.

Those on the B and C lists write blogs and have achieved some notoriety, but are harder to pick out in the crowd, Hay said.

"When you start you're just a security grunt in the trenches and it's really hard to blaze a trail," he said. "I started doing dial-up tech support, then I got into network security, and became a product manager."

Eventually, Hay went on to write such books as OSSEC Host-Based Intrusion Detection Guide and Nagios 3 Enterprise Network Monitoring.

He described the four pillars he used to advance in the security profession:

  • 1. Blogging and writing
  • 2. Going to conferences, gatherings and groups and networking
  • 3. Social networking -- getting one's voice out there by such vehicles as Twitter, Facebook, LinkedIn etc. (Hay described Twitter as one of the best things to happen to security. "I wouldn't know half the people in this room otherwise," he said.)
  • 4. Participating in online communities

All that said, Hay said it's not always best to move from the D to A List. In fact, moving to the top can corrupt a person's perspective and make them less useful to their peers.

"The problem with the industry is the 'I'm better than the D-List' mentality," he said, noting that A-listers can "think they are higher in stature and it's an unfortunate place to be. I'm happy on the D-List."

(Security B-Sides is being held today and tomorrow from 10 a.m. to 5 p.m. at the pariSoma Innovation loft at 1436 Howard St. (at 10th), near the Moscone Center, where RSA 2010 is being held. The event is free, though representatives from the Electronic Frontier Foundation will be accepting donations.)

Read more about data protection in CSOonline's Data Protection section.

Originally published on www.csoonline.com. Click here to read the original story.
This story is reprinted from CSO Online.com, an online resource for information executives. Story Copyright CXO Media Inc., 2006. All rights reserved.
What is Tech Briefcase?
TechBriefcase is a new, free service where IT Professionals can Search, Store and Share IT white papers and content like this. Learn more
Bookmark content
Speed up your research efforts with content across the web.
Search and Store
Find the white papers you need. Create folders for any topic.
View Anywhere
Open your briefcase on your iPhone, tablet or desktop. Share with colleagues.
Don't have an account yet?
Additional Resources
Security KnowledgeVault
WHITE PAPER
Security is not an option. This KnowledgeVault Series offers professional advice how to be proactive in the fight against cybercrimes and multi-layered security threats; how to adopt a holistic approach to protecting and managing data; and how to hire a qualified security assessor. Make security your Number 1 priority.

Read now.

Cut Communications Costs Once and for All
WHITE PAPER
New IP-based communications systems are being deployed by small and midsized businesses at a rapid rate. Learn how these organizations are enabling faster responsiveness, creating better customer experiences, speeding office or mobile interactions, and dramatically reducing existing communications costs.

Read now.

Careers White Papers
Practice Management: Double Billing Rate and Improve Patient Services
Would you like to double your billing rate and achieve faster payment for services?

Download this customer success story to see how One Health...
Mission Critical Data Explosion and Customer Case Study
Would you like to double your tier 1 storage capacity while simultaneously reducing your storage footprint?

Download this customer success story to see how...
Protecting Against Database Attacks and Insider Threats: Top 5 Scenarios
Read this new eBook to learn the top five scenarios and essential best practices for preventing database attacks and insider threats.
Database Activity Monitoring Is Evolving
Read the analyst report and learn how you can leverage the core capabilities of a DAP solution for better database security.
Establishing a Strategy for Database Security is No Longer Optional
The options for securing increasingly valuable databases are very broad and deep, and can be confusing. This research provides an overview of three...
All Careers White Papers
Careers Webcasts
Distributed Database Security with Real-time Monitoring
View this demo and learn how IBM InfoSphere Guardium database activity monitoring can help protect your sensitive data in distributed DBMS environments with...
InfoSphere Warehouse Packs Demo
These flash modules make warehousing more tangible and relevant to business users through detailed explanations of the InfoSphere Warehouse Packs.
Delivery Management -- Extending Lifecycle Management
Date: Wednesday, June 20, 2012, 1:00 PM EDT

Siloed organizations continue doing the wrong things and doing things wrong, leading to increased costs,...
Leverage automation today to reduce IT complexity
Date: Tuesday, June 5, 2012, 2:00 PM EDT

Whether your B2B complexity is caused by multiple technologies due to M&A, business or application specific...
Redefine Expectations in the Data Center
Need to do more with less? Watch this video to learn how HP ProLiant Gen8 servers can help your business deploy servers three...
All Careers Webcasts
IT Salaries 2012
2012 Salary Survey

How does your salary compare with your peers? Find out using our Smart Salary Tool.

Newsletter Sign-Up

Receive the latest news test, reviews and trends on your favorite technology topics

Choose a newsletter
  1. View all newsletters | Privacy Policy
IT Jobs