04/22/2025
The dark side of cybersecurity certifications for new professionals:
I spoke to a new cybersecurity analyst last week.
And I was shocked at what I heard;
He'd done a 'certification bootcamp' (5k+ investment)
Where they'd set him up with a stack of certifications:
• CompTIA Security+
• CISSP
• CEH
• CISA
and trained him to pass the exams
Now while there is nothing inherently wrong with these certifications
And in fact, they are great, I recommend 3 of them now
The problem is that they are useless without something in place
Think of it like this
You learn all the firewall configurations, encryption protocols, compliance frameworks
And then you can't apply any of them because you forgot to learn how to communicate effectively
That's EXACTLY the problem with these certifications and these programs pushing them
They are not a complete system
They are limited if you don't have strong communication skills, practical experience, and stakeholder management abilities
Don't believe me?
• Look at who's getting promoted in cybersecurity
• Look at who's effectively implementing security changes
• Look at who stakeholders actually listen to
The general rule here is to master communication first, then build your technical expertise