All Signs Point to a Schism in Cybersecurity
*Note: This article was originally published by the author on October 4, 2020. It is being republished here for archival purposes. Free…
All Signs Point to a Schism in Cybersecurity
Note: This article was originally published by the author on October 4, 2020. It is being republished here for archival purposes. Free read link here. Portions of the article were featured in the book, [97 Things Every Information Security Professional Should Know](https://books.google.com/books?id=H99CEAAAQBAJ&pg=PA67&lpg=PA67&dq=Ian+Barwise&source=bl&ots=8KqaBlCqwM&sig=ACfU3U3j6sHvseCFqNWnHM2ilHefrWi9pQ&hl=en&sa=X&ved=2ahUKEwjMu5zsxc_-AhUeJUQIHbAsC244MhDoAXoECAIQAw#v=onepage&q=Ian%20Barwise&f=false)*, written by Christina Morillo.

A schism has formed in cybersecurity amongst the various skillsets and myriad of nation-state cyber threat adversaries
A schism is a division or disunion, especially into mutually opposed parties.
The cybersecurity industry is at a crossroads. Each week there are new reports of data breaches and ransomware attacks that expose Personally Identifiable Information (PII), Personal Health Information (PHI), financial, proprietary, passwords, and sensitive information that is very damaging to individuals, organizations, and governments across all industries. We will continue to see the effects of these breaches for years to come.
But it’s not as if computers or networks and the technical protocols they operate on are new inventions and it’s not as though cybersecurity is some new field of study. Information and Communications Technology (ICT) has been around for decades and the entire time it has existed, there have been vulnerabilities that have been consistently exploited by criminal hackers. It’s not new, this is an old game of whack-a-mole. You patch one hole and they pop up through another.
There is a schism that has formed within the information security industry and the rest of the world including commercial industry, government, and criminal enterprises. As employers’ performance expectations continue to rise and they continue to complain about a self-perceived ‘skills gap’ there is a mountain of evidence to support the fact that employers don’t understand cybersecurity, don’t write their job requirements correctly, and aren’t willing to pay cybersecurity professionals competitive salaries or offer them quality benefits. Meanwhile, cyber threat actors could care less about any of this. They see your organizations’ lack of a coherent, well-defended network as a juicy target that is ripe for exploitation.
1. Attackers Have Always Had The Advantage
Sourcegraph surveyed 500 North American software developers in 2010 and revealed that software devs in 2020 are now managing 100 times more code today than they did (Salter, 2020). That is just insane to think about. Imagine if you had to penetration test 100 times more systems a year just to earn the same amount of salary you make now. How about if you had to manage and monitor 100 times more information systems?
It’s daunting to think about yet everyone is quick to point fingers at the devs who write the code that gets exploited. Mind you, salaries have not gone up 100x since 2010 but employers expect employees to perform much more each year. Sound fair to you? When people ask why there seems to be a neverending amount of exploitable vulnerabilities in software applications, it’s not difficult to understand why.
Humans are fallible and can’t possibly be expected to write that much code quickly and proofread it for accuracy as they go. We are not machines. “But there are tools for checking code,” you say. Yes, of course. We are aware. Like Artificial Intelligence and Machine Learning, however, these tools and capabilities are only as good as the code and biased algorithms we program them to operate with.
How well has that approach worked for us thus far in preventing vulnerabilities? Not reasonably well I contend as someone who has worked in cybersecurity for going on 26 years now. The pressure on devs to produce, produce, produce is unreal. The tempo of DevSecOps in some of the organizations I’ve worked in is unreal, even unsustainable I would venture to say. Burnout is coming for you! “Just get the code to production, we can patch the flaws later!!” I can hear the SCRUM masters now. Another team will take care of fixing your code flaws. Let’s be honest, the agile software development approach is not without security risks. Our software development practices aren’t perfect, much like our system and application security hardening practices. There is always room for improvement.

In fact, one can almost say that it’s become more lucrative to become a criminal hacker than to use that same knowledge to protect computer systems. Employers won’t pay you as much to protect information systems, even critical infrastructure, as one well-aimed ransomware attack might net hundreds of thousands in US dollars for cybercriminals. Does that mean we should just stop trying to protect them though? No, I think it means we may need to change our approach however in the wake of an apparent schism in the cybersecurity industry.
You see, attackers are always going to have the upper hand in this cat and mouse game as long as they get to pick the method of attack, the time, the date, the particular place (IP address), and the weakest vulnerability on a network or computer system. As long as we continue to give cybercriminals those advantages, they will continue to have the upper hand. If they didn’t have those advantages, there wouldn’t be so much of a market for this illegal activity and they wouldn’t be as successful as they have been. Finding and poking holes in computer and network security is much easier than engineering something that is impenetrable like a fortress. Fortresses are very expensive and take a long time to build when done correctly. Not to mention, while you’re building the fortress, someone may slip in some backdoor (remote access Trojan) that will allow them to access and exploit it later.
Even still, fortresses can be defeated with enough fiery boulders covered in oil catapulted into the walls. Walls can be scaled with ropes and grappling hooks. The software can be decompiled, analyzed, and manipulated by skilled cyber threat actors. Moats can be bridged, doors can be rammed through with battering rams. You get the picture but security has never been a permanent set once and forget about it type of thing. This is one reason why open source software is preferable to closed source software, the flaws can be discovered by the good hackers before the criminal hackers have a chance to exploit it.
It’s simply not possible to engineer a system that is completely secure for a plethora of reasons, not the least of which are the vulnerabilities in software, such as operating systems, applications, and firmware. Additionally, the ports, protocols, services used by computer systems are very dated and known to have specific weaknesses that are exploitable if they are not properly patched and blocked by firewalls or by other means. Unnecessary ports are closed, unnecessary services and programs are removed from a secure system to reduce attack surfaces. These are some of the things that we can do to harden information systems but they take time and a lot of effort not to reduce overall functionality. Time and patience that often is not shared by company managers who want to see the end product yesterday with zero chance of successful attacks. Hah, keep dreaming.
2. Employers Keep Saying There is a Skills Gap
Sure, there’s a skills gap alright. The skills gap is employers’ ability to hire and retain the right cybersecurity talent in the first place. Is it a skills gap or is your company expecting miracles out of peanut wages? There are plenty of capable cybersecurity professionals out there but they aren’t willing to work for $70K salaries and shit benefits. Employers need to reevaluate their priorities.
Ask yourselves, do you want talent that can help to prevent cyber attacks (e.g., denial of service and ransomware attacks) enough that attackers will opt to target less well-defended targets, or do you want to fall victim to a data breach or ransomware attack resulting in regulators breathing down your neck, regulatory fines, stock depreciation, loss of confidence by the board of investors, and potential class-action lawsuits from customers? The choice is obvious but go ahead and keep pretending it’s cheaper to just pay the fines.
Doing cybersecurity correctly requires enterprise-level organizations to:
- Acknowledge publicly that cybersecurity is a top priority for the organization
- Hire a Chief Information Security Officer (CISO) who answers directly to the CEO, not the CIO (i.e., a direct conflict of interest)
- Hire a team of cybersecurity professionals based on experience more so than degrees and worthless certifications that were earned 15 years ago
- Allocate an adequate slice of the budget to procure and manage the security architecture for the entire organization that is required to be upgraded periodically (e.g., every 5 years on average)
- Implement a robust risk management framework (for starters) that aligns with the National Institute of Standards and Technology (NIST) Cybersecurity Framework (CSF), the NIST Risk Management Framework (SP 800–53 revision 5), ISACA’s COBIT, CIS Top 20, ISO 27001, PCI DSS, or something other than the usual makes it up as we go “we don’t have a plan” BS that fails eventually 100% of the time
- Have your cybersecurity professionals create a Business Continuity Plan (BCP) and Disaster Recovery Plan (DRP)
Small and medium-sized businesses (SMB) will obviously not be able to afford to do all of this, but they are expected to implement whatever measures they can. Due diligence is still required whether you’re a large organization or a tiny one. Maybe your ‘cybersecurity department’ is only one person, at least you’ve got someone working towards these important goals.
So employers can continue complaining about a skills gap all they want but the fact is that until they can get their collective act together and stop requiring entry-level cybersecurity professionals with 5 years of experience, a B.S. degree in cyber, and a CISSP certification, who will earn $75K a year tops they are going to keep getting ghosted by job candidates and their cybersecurity posture will suffer as a result. There’s no skills gap, there’s a refusal by companies to pay cybersecurity professionals competitive salaries for the stressful and technically challenging work they perform. The only shortchanging happening is to your organization. Get ready to pay the piper.
3. Penetration Testing is Sexy, But There’s Much More to Cybersecurity

The Map of Cybersecurity Domains v2.0; credit: Henry Jiang (also in Spanish)
Cybersecurity is a wide field of study. Every single one of the domains shown in Henry Jiang’s ‘Cybersecurity Domains’ graphic (pictured above) could be a job specialty in and of itself but what commonly happens is that they get combined into a single role that is forced by employers to wear several hats. “Sorry buddy, we can’t afford to hire anyone else unless you’re willing to accept a pay cut?” How about management takes a pay cut instead? How about we shave a ‘hundo-thousand’ off the CEO’s salary? Not an option you say? Ok, well there you have it then. You’ve made your priorities clear as day. Don’t be surprised when your only cybersecurity talent gives notice and leaves your organization high and dry because you saddled them with 4 different jobs for the salary of one of those jobs.
Many of us who work in cybersecurity in some capacity are also “hackers” at heart. The degree of which is up for debate depending on who’s judging. Any self-proclaimed ‘hacker’ has undoubtedly been brainwashed by the Hollywood stereotypes of what hackers are supposed to look like and how they are unbelievably skilled at programming, breaking encryption, and can hack into any system or account. Most of that trash is a myth, it’s garbage and it’s perpetuating a harmful stereotype of criminal hackers in Guy Fawkes masks wearing black hoodie sweatshirts.
I’ve noticed that in recent years, there is a huge trend among newcomers to the infosec field to want to specialize in penetration testing because they want to break into systems, pop shells, and be considered L337 (elite) hackers. If they’ve never worked in Information Technology or Information Security before, however, this is a lot like skipping directly to the front of the line at the movie premiere. You can’t possibly understand all of the underlying concepts of IT and cybersecurity if you’re first and only experience in the field is penetration testing. Critical to success is having the proper attitude that in this field, we’re always learning. Having an open mind is crucial, nobody knows it all.
Only seeing one aspect of cybersecurity, the offensive security aspect of it, is ok but it takes well-rounded cybersecurity pros to understand the underlying issues as to why a particular organization is so vulnerable after you conducted that pentest and how the organization can best secure its infrastructure with the limited resources it has. There is so much more to be considered and to learn. Why is this trend an issue though? Because the more this trend continues, the fewer cyber defender talent is available to help with the overwhelming tasks of securing the millions of information systems that exist in the U.S. alone not to mention worldwide.
Believe it or not, there are plenty of other important jobs in cybersecurity besides penetration testing networks and computer systems. In fact, I would even go so far as to say that in terms of difficulty, it is much harder to design a secure system (security architect/engineer) and maintain/defend it from cyber threats and attackers than it is to attack it. So, if a challenge is what you’re after in your chosen career path, the challenges aren’t limited to breaking into systems. There are plenty of challenges in protecting them also. Both aspects are equally important but poking holes in system security is a lot easier than defending it.
The Blue Team is composed of cybersecurity professionals who focus on protecting the Confidentiality, Integrity, and Availability (CIA triad) of information systems. The Red Team focuses on long-term, adversary-simulated physical, and cyberattacks to discover security weaknesses before adversaries can identify and exploit them. Whereas penetration testers perform short-duration, pre-timed security assessments for organizations. Both the Red Team and penetration test security assessments offer valuable insight that Blue Team defenders can use to improve their overall security posture. Purple Team members combine both Blue and Red Team skills and experience to focus on internally testing networks and systems to identify potential vulnerabilities that can be remediated internally by the organization. All of these teams work together to improve cybersecurity and often physical security as well. We can’t have cybersecurity without physical security.
Security Operations Center (SOC) analysts monitor the information technology environment and network for intrusions or anomalies in the infrastructure to simplify it greatly. Cyber Threat Intelligence (CTI) analysts hunt for sophisticated cyber threat groups that may attempt to target their organizations. They follow current cyber threat intelligence news and hunt for clues inside their networks.
There are security managers that focus on information system security overall, they manage systems and may also write governance policy, and manage cybersecurity specialists in the accomplishment of organizational project tasks and their day-to-day duties. Security management, although typically a less technical cybersecurity role, requires some degree of technical understanding in your career somewhere along the way before you can make it to that level. There is a degree of technical knowledge that you must possess to understand even the documentation of information system security.
There are digital forensics investigations and incident responders often lumped together under the DFIR umbrella. These specialists respond to incidents and often are the first ones to respond to any criminal system intrusions or data breaches.
All of these important sub-disciplines of cybersecurity rely on one another to some degree or another. One is not more important than the others. They rely on each other for mutual reinforcement. Just as a penetration tester may be able to their skills and knowledge to identify critical vulnerabilities in an organization’s system, that policy that a CISO created is only worth the paper it was printed on if the organization’s top leadership doesn’t sign off on it. It truly is a one-team, one-fight scenario. There is no room for cowboy mavericks. Avoid them like the Coronavirus.
4. No Cybersecurity Apprenticeship Program
Mature industries like construction, electricians, shipbuilders, welders, plumbers, engineers have apprenticeship programs that allow entry-level workers to find mentors and progress up through the ranks with certification tests along the way. Cybersecurity doesn’t have that as it has not yet reached such a level of maturity still being a relatively new job industry. Therefore, we get a fair amount of the “fake-it-until-you-make-it” types entering the cybersecurity field which can be a problem in more ways than one. The software development field has an apprenticeship program that the cybersecurity field could adapt to its own needs but for it to be effective, it would need to be widely adopted across all industries. Employers looking for a senior security engineer would actually have widely accepted metrics and certifications on which to base hiring decisions for a change. Just imagine that.

Apprenticeship.gov has a structure to begin apprenticeship programs for any industry
It’s not about gatekeeping the non-hackers out of the industry though. We don’t need to weed anyone out that doesn’t know Linux or whatever other false metrics you use to measure the perceived skill of cybersecurity professionals. This schism has everything to do with the need for our industry to design and build a pathway for entry-level (apprentices), junior, intermediate, senior, and executive-level cybersecurity apprenticeship programs with corresponding exams and professional recommendations to progress from one level to the next.
This is vital to the success of an industry and most major industries have similar apprenticeship programs. What are we waiting for? We desperately need to implement something like this now. As we used to say in the Marines, “there’s nothing standing in the way but air and opportunity.” I think we would see tremendous improvement in the quality and effectiveness of our profession by implementing an apprenticeship program. As I’ve seen on social media and have even mentored newcomers to the field myself, there are plenty of experienced cybersecurity professionals who are willing to mentor. The NICE CyberSeek Interactive Map should be incorporated into this as well.
5. U.S. Information Systems Are Among the Juiciest of Targets
The United States is among the most, if not the most, technologically advanced nations in the world. That isn’t true of all aspects within the U.S., but it is certainly true overall and for many of the more developed cities and among our critical infrastructure information systems when compared to other nations.
Look no further than your organization’s system firewall logs to see which attacks are originating from which countries the most. See if their country flag is included in the picture at the top of the article. Sure, IP addresses can be proxied, so attribution is better left to the experts but some cyberthreat actors don’t even bother to obfuscate their true IP addresses. Chinese-based cyber threat actors are notorious for this.
How do we change the narrative with this particular schism? It’s simple but even amongst cybersecurity professionals, we cannot agree on how to do it. For instance, I think air-gapping information systems makes sense for critical infrastructure. There are lots of opinions on what defines a critical information system but check it out, if your entire business relies on it then it’s pretty critical that it remains available and that its integrity and confidentiality aren’t compromised, correct? I would say so. Otherwise, you’re dead in the water. Now, whether the government considers the services your organization provides as “critical” is a different matter. But, irrespective of that, it’s critical to the operation of your business.
credit: infragardcincinatti.org
Therefore, certain critical segments may need to be disconnected from the Internet. But there are those cybersecurity pros who will make the argument that edge cases like acoustical and electro-magnetic attack vulnerabilities, malicious insiders, or sneakernet Stuxnet-style attacks can circumvent air-gapped information systems. Well, sure they can but there are also compensating controls that can be used to defend against those types of attacks like physical security measures. So, let’s not throw the baby out with the bathwater so to speak.
So Where is the Schism?
The schism is all five of these issues combined which continue to plague the cybersecurity industry as a whole. Until we adequately address these issues like coming to terms with the fallible nature of software development and accepting that getting hacked is not necessarily your security team’s fault since there are countless ways to hack a system, we are going to continue experiencing this schism in cybersecurity. Employers need to do a better job of writing job descriptions (maybe outsourcing that requirement to someone who truly knows?) and of allocating the funding and other resources needed to stand up a robust cybersecurity program.
Encouraging cybersecurity professionals and newcomers to the industry to follow an established apprenticeship program will do great things for our community and industry and prevent a lot of the nonsense and disparity we are seeing now in terms of compensation and experience level requirements for positions. Lastly, we know that our systems in the U.S. are going to be targeted simply because our nation is wealthier than almost every other nation. The cybercriminals aren’t attacking the poorest nations as much as they’re the biggest payoff targets. For that fact alone, we have got to take the basic actions to protect our systems using cybersecurity best practices whether that means air-gapping systems or something else. In conclusion, the only way we stop the schism is by putting our egos aside and working together to find common ground. Then and only then can we hope to improve.
Reference
Salter, J. (2020, October 1). Sourcegraph: Devs are managing 100x more code now than they did in 2010. Retrieved from https://arstechnica.com/gadgets/2020/10/sourcegraph-devs-are-managing-100x-more-code-now-than-they-did-in-2010/
메타데이터
- post_id
- 0fe2fd59c9c5
- slug
- all-signs-point-to-a-schism-in-cybersecurity-0fe2fd59c9c5
- url
- https://medium.com/@z3r0trust/all-signs-point-to-a-schism-in-cybersecurity-0fe2fd59c9c5
- canonical_url
- https://medium.com/@z3r0trust/all-signs-point-to-a-schism-in-cybersecurity-0fe2fd59c9c5
- author_url
- https://medium.com/@z3r0trust
- status
- ok
- fetched_at
- 2026-07-20 21:37:36