Keynote: My 2 Paisa on Infosec

DiverSecCon

2021/11/14

SlideDeck

Full Video

AI Generated Summary

This keynote presentation “My 2 Paisa on Infosec” shares insights from 15+ years of experience in information security, covering the distinction between hacking and infosec, industry challenges, hiring practices, remote work, and advice for attackers and defenders.

Speaker Background

Key Topics Discussed

Infosec is NOT Equal to Hacking:

Hacking:

Infosec Industry:

Offense vs. Defense:

Security is Not Just Hacking:

Skill Shortage - Different Take:

Industry Reality:

Giving Credit to Defense:

Hiring Strategies:

Certifications:

Technical Interviews vs. Actual Job:

Outside Work:

Judging by Public Work:

Hiring Summary:

COVID-19 and Remote Work:

World Changed:

Diversification - Location:

Hiring Practices - Salary:

Remote First Policies:

Employee Aspect:

Advice for Attackers:

Fancy About Cutting-Edge:

Two Cents to Attackers:

Don’t Forget the Old:

Advice for Defenders:

Collaboration:

Sponsoring Open Source:

Frameworks:

Metasploit Example:

Firefighters vs. Fire Prevention:

Take Care of Yourself:

Prevention vs. Detection/Containment:

Last Nugget for Defenders:

References:

Key Insights:

Actionable Takeaways:

  1. Understand difference between hacking (passion) and infosec (profession)
  2. Be enabler, not blocker - help business achieve goals
  3. Accept people are here for money, not just passion
  4. Hire for work you have, not for fancies
  5. Give credit to defense - they’re more important than offense
  6. Don’t bottleneck hiring with certifications - hire skilled people, then certify them
  7. Look at tier 2/3 cities for untapped talent
  8. Implement proper remote first policies
  9. Attackers: Learn emerging tech but don’t forget old tech
  10. Defenders: Collaborate, sponsor open source, focus on detection/containment
  11. Take care of yourself - never-ending war requires pauses
  12. Assume breach will happen - focus on containment