Transcription
This video might be controversial, but my goal is to help you understand the cybersecurity industry better.
In this video, I will give you my honest, no-BS rating of cybersecurity certifications in terms of which ones are useful for you, so you can master a subject and also land a job. This is based on my own journey when I was trying to break into cybersecurity 20 years ago, as well as what I see in the market both as a hiring manager and as a cybersecurity consultant, where I help organizations run their cybersecurity divisions.
When I was trying to land my first cybersecurity role, I thought I had it all figured out. People advised me to do CompTIA A+ and CCNA to build that foundation before I could begin to learn how to do some ethical hacking activities. However, as I was going through these certificates, I noticed that I was getting extremely bored learning both the A+ and the Cisco CCNA. Not only that, but I noticed that the things I was learning were completely irrelevant. I didn't see how learning the Cisco command line would help me with ethical hacking for web application servers; it just made no sense.
Then things got worse. I started noticing that some of my friends got their first cybersecurity job without even doing any of those certificates. In fact, I've even met fresh university graduates who landed their first cybersecurity role without having any certifications or experience whatsoever. So, I started questioning the path I was on, which turned out to be a blessing in disguise. It led me to a journey of doing many cybersecurity trainings and certifications, giving me exposure to numerous cybersecurity certification programs. If this video manages to save time and money for one person, then I consider my goal accomplished.
Let's get into it. CompTIA certificates are extremely popular among people who don't work in cybersecurity and among those who are extremely junior and early in their cybersecurity journey. The main advantage of the CompTIA certificates is that they are vendor-neutral, which means instead of teaching you how to configure Palo Alto firewalls, they teach you in general what firewalls are and what they do. However, they don't teach you how to configure a specific vendor firewall, which can be useful for someone who's new to the field. So, you get to learn the generic concepts of how things are supposed to work.
Another big advantage that I personally like about CompTIA is that the CompTIA Security+ is a beginner introductory certificate that will teach you the general foundations of what cybersecurity is. This was quite revolutionary because, in the past, we didn't have many cybersecurity certifications that would introduce you to the field. So, Security+ was, and still is, a good introduction to cybersecurity.
Now, there are many problems with CompTIA certificates. The biggest disadvantage is that the exams are multiple-choice, which means when people study for these certificates, they end up memorizing and cramming a bunch of concepts to pass the exam. This is not the best way to learn a topic, in my opinion.
We will use this popular tiering system: the S tier is the super tier, followed by A, B, C, D, and F, which is the worst tier in the list. The CompTIA certificates that I will look at include Security+. I think it does a good job introducing people to the field of cybersecurity. It delivers on the promise that it will teach you the foundational concepts of cybersecurity. It's not going to make you an expert; it's not going to make you an all-knowing hacker, but it's definitely a good introduction to cybersecurity.
Then we have the CySA+ (CompTIA Cybersecurity Analyst). I actually really like this one because it's a lot harder than Security+ and introduces you to extremely useful concepts that you will use if you work as a cyber analyst. It will teach you about security operations, incident response, vulnerability management, and even reporting. Unfortunately, the same disadvantage that applies to all CompTIA certificates applies here: it's extremely theoretical, so you will end up memorizing and cramming a bunch of concepts to pass a multiple-choice exam. Nonetheless, I still think the information in there is valuable.
The next one is the CASP+ (CompTIA Advanced Security Practitioner). This is meant to be a tier above the CySA+. It's a little bit harder and touches on concepts such as architecture, operations, GRC, engineering, and cryptography. Then we have the CompTIA PenTest+. This is the penetration testing certificate. I honestly don't think this certificate serves any purpose because trying to learn ethical hacking from a theoretical, multiple-choice-based exam is like trying to learn to drive a car by reading a book. Yes, you can learn all about the traffic rules by reading a book, but you still have to actually try and drive the car to learn driving.
So, in my opinion, PenTest+ doesn't serve any purpose. To put them in our tiering list, I will put all of the CompTIA certificates as tier B because they have good theoretical information, but unfortunately, they lack the practicality that we need in cybersecurity. Except for PenTest+, I think it's rated as F because, in my opinion, it doesn't serve any purpose; it will just waste your time and money.
Now, before we move on to the next section, I didn't forget the popular CompTIA A+ and Network+ and even things like CCNA. In my opinion, these are not cybersecurity certificates; these are general IT certificates. For cybersecurity professionals, I don't think it's a great idea to pursue them. If you've already done them, that's great, but if you haven't, there are so many options that are cheaper and faster that will teach you the same concepts, and I talked about all of them in this video, so please check it out.
The next one is the GIAC certificates. The GIAC certificates have an associated SANS training. The SANS Institute is the most popular cybersecurity training institute in the cybersecurity industry. Sure, your IT manager or network admin, or even your hotshot junior cyber analyst may not have heard about the SANS Institute, but those of us who work in cybersecurity are extremely familiar with it. They are not only a training provider, but they've also set some industry standards that we use in our day-to-day cybersecurity jobs.
The way it works is you do a SANS training that lasts four to six days, depending on the course, and then you study and pass the associated GIAC exam. The SANS Institute has world-class cybersecurity training for a number of reasons. They are extremely selective about who the instructors are, so a SANS instructor is usually someone who has a lot of experience in cybersecurity. They are actively working in cybersecurity, so they are not a full-time instructor and they are not an academic. They have hands-on experience, and to become a SANS instructor is a very demanding process, so they maintain this high quality of instructors throughout their use.
Now, compare that to your PhD university professor who has never worked a day in their life and is trying to teach you how to become a cybersecurity professional. There is a huge difference. The other good advantage about SANS is that the material is of such high quality; it's always up to date. Their courses reflect problems that we face today in cybersecurity.
Another great thing about SANS training is that most of their courses have a practical component that you will do in the training. The other underrated advantage of SANS training is that they cover every topic under the sun. They've got a training course for every topic you can imagine, even obscure things like operational technology, mobile device forensics, and cloud forensics. So, whichever topic you want to learn, chances are there is a SANS training, and you know that the quality is super high.
The final advantage of SANS training is that it's well-respected within the cybersecurity industry. When people see that you've done a SANS training or a GIAC certification, they know that you know something that goes beyond memorizing and cramming to pass a multiple-choice exam.
Now, the biggest disadvantage of SANS training is the price. The cost of the training is about $8,000, and the reason behind that is that SANS training usually targets companies. They want your company to pay for the training so the employees can attend.
Now, bonus tip: if you want to do SANS training cheaper, go to the work-study program within SANS. Apply there, and you might get a chance to be an assistant in a SANS training program, or you get to do the training for much cheaper. I've done a few of those myself, and I highly recommend it.
There are so many GIAC certificates that it's nearly impossible to rate all of them, but if I were to group them all together and rate GIAC and the SANS Institute all at the same time, they would definitely be in the S tier. Anyone who works in the industry knows that, and they've maintained their quality throughout the years.
The next one is ISACA. ISACA certificates focus on the area of governance, risk, and compliance, or GRC. The main advantage of ISACA is that they are kind of the only GRC certificate providers. So, if you want to do an IT audit certificate, then ISACA is pretty much all you have at the moment.
The other thing I like about ISACA is they host a lot of free events for the community. If you go to Google and type "ISACA chapter" in your own city, chances are you'll find a really nice meetup that you can attend, and you can network with other cybersecurity professionals. I highly recommend attending those.
Now, unfortunately, there are many disadvantages with ISACA certificates. The first one is that to do ISACA certificates, you need five years of experience. I'm talking here about the popular ones like CISA, CISM, and CRISC. In my opinion, this experience requirement is not warranted. The topics in CISA and even CISM, to a certain extent, are not exactly advanced, so any junior IT auditor should be able to do and pass at least the CISA certificate.
To me, they created an unnecessary hurdle. The main biggest disadvantage that I personally don't like about ISACA is that the training itself doesn't teach you anything. Think of ISACA as something you do after you get GRC experience to validate your experience. But if you do the ISACA certificate, they're not going to teach you how to do GRC, which is a huge problem in my opinion. Because of all of that, my tiering is C. I still think they hold some value, but unfortunately, they don't teach you anything.
The next ones are ethical hacking certificates. Those are my absolute favorite certificates. I wish that the rest of the cybersecurity domains had good training materials similar to ethical hacking. The most popular ethical hacking certificate is the OSCP, and it's fully practical. It's popular for a reason: it tests that you can actually perform ethical hacking as opposed to testing you on how you're going to pass a bunch of multiple-choice exams.
Fortunately, we have other ethical hacking certificates. We have the eJPT and the pJPT, both of which are entry-level ethical hacking certificates meant to introduce you to the field of ethical hacking using fully practical training and practical exams, which I'm a huge fan of. Even if you don't want to be an ethical hacker, in my opinion, doing these certificates is extremely helpful for you as a cybersecurity professional.
So, if I were to tier the eJPT and the pJPT, they are definitely A tier. Now, we talked about OSCP, but there is ECPPT and TNTP. All are extremely valuable practical ethical hacking certificates. In my opinion, they are S tier because if you do them, you will learn so much, and doing the exam will also prove that you have the skill of ethical hacking.
I personally know many cybersecurity professionals who started studying for the OSCP but never managed to finish it because it's just hard. Finishing it also communicates to me that you are passionate about cybersecurity. As a hiring manager, I see so many candidates who tell me, "I'm very passionate about cybersecurity," but to me, this is meaningless. Instead of telling me you're passionate about cybersecurity, show me what work you've done in the field. Show me the difficult projects that you've done because this will prove that you're passionate.
It's really hard to pass the OSCP without being passionate about cybersecurity. Now, there is EC-Council and the Certified Ethical Hacker certificate. This is a multiple-choice exam-based certificate. In my opinion, it's not the best way to learn ethical hacking. It's extremely similar to the PenTest+, so I would personally rate it as F because doing it will not make you an ethical hacker. It doesn't deliver on the promise, and for these reasons, I'm rating it as F.
The next one is the ISC2 certificates. The CISSP is definitely the most popular certificate for people who have no idea how cybersecurity works. For example, I'll get network engineers who come and ask me, "Should I do CISSP to become a cybersecurity professional?" Or I will meet someone who is a university student who would like to work in cybersecurity, and the first thing they ask me is, "Oh, should I do CISSP?"
The truth is, among people who actually work in cybersecurity, we don't care about CISSP, and there are many reasons for this. The first thing is that the CISSP is actually intended to make you a cybersecurity manager. This is the goal of the certificate. It's meant to be a mile wide and an inch deep, so it touches on many domains but doesn't go deep into any of those domains. ISC2 came up with this certificate thinking this is what cybersecurity managers need.
Another reason we don't really care about CISSP is that the vast majority of cybersecurity managers do not have CISSP, and they don't even care about it. To be a really good cybersecurity manager, you need to have a lot of depth in many topics, but you also need management skills, which the CISSP definitely doesn't teach you.
Another huge disadvantage of CISSP is that if you can't pass CISSP, I know for sure that you've just crammed a bunch of concepts. It's all about memorizing a whole heap of junk, in my opinion. Trust me, memorizing the types of fire alarms has nothing to do with cybersecurity; no one cares.
Now, is the CISSP all that bad? No, there are a few things going for the CISSP. They actually have a group of cybersecurity professionals who contribute to the exams, so the multiple-choice questions you get in the exam have actually come from some really good cybersecurity professionals. They try to emulate the real world as much as possible in a multiple-choice exam. In fact, one of my close friends sits on that committee.
The other good/bad thing about the CISSP is that people who don't work in cybersecurity seem to somehow know about it. So when they do a job search in cybersecurity, they see the CISSP thrown in there for jobs that, frankly speaking, have nothing to do with CISSP. I have no idea why a security analyst would ever need a CISSP. Nonetheless, people still copy-paste the CISSP and put it there. More often than not, this is just a wish list. They will put the CISSP and a bunch of certificates that doesn't mean they absolutely want you to have it; it just means if you have it, it's nice to have.
What you really need is the skill of being a cybersecurity professional. The other advantage of CISSP is that it's a little bit harder than Security+. It's not a lot harder. I personally know people who passed it in two weeks. Those are professionals who work in the field and have the experience, so all they did was read the book quickly and take the exam.
So yes, it is harder than Security+, but it's not that hard. In fact, it's a lot easier than something like the OSCP. So don't be fooled by shiny objects. Just because you see CISSP show up in a job search doesn't mean it's as valuable as some beginners on the Internet seem to think. In the real world, no one cares.
So my personal rating of it is B, and that's mainly from what I see in the industry. Most people who have CISSP usually don't have that much experience. I'm aware that the CISSP asks you for five years of experience, but usually what happens is help desk experience can qualify for you to meet that experience requirement, even if your experience in help desk had nothing to do with the security domains.
It's good; it's a level above Security+, but I wouldn't exactly call it an advanced certificate. There are also two popular certificates from ISC2, which are the SSCP, meant to be a stepping stone for the CISSP. In my opinion, it absolutely serves no purpose, so I would rate it as F.
But then there is a new one called Certified Cybersecurity, aimed at beginners who have no cybersecurity experience or skills. In my opinion, this is useful because it introduces people to the field of cybersecurity, although I personally think it's a little bit watered down. So I would rate it as C, just because there are other alternative beginner cybersecurity certificates that will teach you a little bit more.
Next up are cybersecurity analyst certificates from vendors like Google, IBM, Microsoft, Splunk, and Cisco. These are certificates from big vendors like Google and Microsoft. They are aimed at people who have no IT experience, no technical knowledge, and no degree, and they teach you the basics of cybersecurity. This is fantastic news because, as far as two years ago, we did not have anything like this in the market. So kudos to these companies for creating good quality training aimed at getting more people to work in cybersecurity.
Now, you may be wondering which one is better: the Google cybersecurity certificate or the IBM, Microsoft, Splunk, or Cisco. In my opinion, I wouldn't be splitting hairs on which one is better. I've explored all of them, and I think they're all pretty good. There are minor differences, and I will tier them a little bit differently, but in my opinion, you can't go wrong with any of them, and they're all quite cheap, to be honest.
So if you do one or two or even all of them, it's not going to take you a lot of time, but it will also not cost you a lot of money. Some advantages of these certificates are that a few of them come with hands-on labs, like the Google certificate and even the IBM and Microsoft certificates. They definitely have hands-on labs where you get to practice what you learn, which is huge, especially for someone who's completely new to IT or cybersecurity. It gives you a chance to practice, but it also improves your confidence and helps you retain the information you learned, so you're not just cramming a bunch of concepts to pass a multiple-choice exam.
If I look at the differences between them, I think Google is a great option because it teaches you MySQL, Linux, and Python, which are extremely popular tools that you will use as a cybersecurity professional. The Microsoft certificates teach you a little bit about Office 365 and Microsoft Azure Cloud platforms, which are extremely useful. The IBM certificate will show you how to use things like GitHub and Snort, which are popular tools in the industry.
Then we have the Splunk certificate. I think it's the odd one out because this certificate will not introduce you to cybersecurity as a field, but more so it will introduce you to how to use Splunk as a tool. But Splunk is an extremely popular tool, so it's definitely useful. Then we have the Cisco Certified Support Technician. Again, it gives you an introduction to cybersecurity as a field, which is extremely useful.
So, in my opinion, if I were to tier these certificates, they definitely deliver on the promise that they will introduce you to cybersecurity as a field. To me, that's definitely a tier A, and this goes for the Google certificate, IBM certificate, Microsoft certificate, and Cisco certificate. Splunk, unfortunately, does not really introduce you to cybersecurity; it introduces you to Splunk as a tool, so to me, that's definitely a tier C. Yes, it's useful, but it doesn't deliver on the promise of being an introduction to cybersecurity.
Next up are cloud certificates. This is definitely a hot area in the market. There is a huge demand for cybersecurity professionals who understand and know how to use the cloud. The three biggest cloud providers are Amazon AWS, Microsoft Azure, and Google Cloud Platform. Amazon AWS is still the market leader in cloud, so if you work in cybersecurity or even if you work in IT, chances are you will run into Amazon AWS. They are still by far the most widely used and adopted cloud platform.
In fact, as a consultant, every time I go to help a company with their cybersecurity journey, they always complain about how they have a huge Amazon AWS setup and don't have many people who understand how to secure the AWS cloud. So it's an extremely useful skill.
To explore cloud security certificates, we have vendor certificates from Amazon, Microsoft, and Google, as well as vendor-neutral certificates. Starting with the most popular and most useful one, in my opinion, which is the Amazon AWS Security Specialty. You're meant to do that after you complete something like the Amazon AWS Cloud Practitioner and the Amazon AWS Architect, and then you can do the AWS Security Specialty. It's extremely useful; the information and knowledge in there will definitely help you land a role securing the Amazon AWS cloud.
There is an equivalent to this certificate from Microsoft, which is the Microsoft Azure Cloud Engineer Associate. Again, extremely useful. Yes, in the market, there is more AWS than Azure, but Azure is still widely used. Chances are you will run into companies using at least something like Office 365 and maybe SharePoint, so it's really useful to know about Azure security technologies.
A less known one is from Google, which is the Google Cloud Security Engineer. Google has a much smaller market share; however, doing it is still useful because, believe it or not, all the cloud platforms are extremely similar. Once you learn and get good at one of the cloud platforms, the same skills are transferable to other cloud platforms. You will just find some differences in the names of the tools; that's all.
If I were to tier them, in my opinion, both the AWS and Microsoft Azure certificates are S tier because the skills are definitely highly sought after. The Google Cloud Security Engineer, I would tier as A because it's not as popular, and you're less likely to be dealing with Google Cloud security issues, at least in the present moment.
Now, looking at vendor-neutral cloud security certificates from ISC2, we have the CCSP. This is meant to teach you general cloud security concepts. The claim that this certificate will enable you to become a cloud security professional, unfortunately, I haven't seen this happen in the real world. No one will hire you just because you have the CCSP. As a hiring manager, we're looking for someone who knows how to configure security groups within Amazon AWS or how to configure identity and access management in the cloud. We don't want someone who knows generic concepts about how cloud security should be.
In my opinion, this certificate doesn't really deliver on the promise of making you a cloud security professional. The same thing goes for the Cloud Alliance CCSK. Again, another theoretical certificate that claims to make you a cloud security professional by teaching you a bunch of concepts.
Now, the Cloud Security Alliance has actually used four checklists that I've seen in the industry, where people use the CCSK checklist on how to secure clouds. This can be useful, but just because these spreadsheets and checklists are around doesn't mean that the certificate itself is useful. Security is one of those extremely practical things, so I'd rather you know how to configure security in Office 365 as opposed to memorizing concepts of how the cloud needs to be secured.
If I were to tier them, both the CCSP and the CCSK are F tier because I would never recommend anyone doing them.
A common question I constantly get asked is: "Is the Google Cyber Certificate enough for me to land the job?" "Is the Security+ enough for me to land the job?" "Is the CISSP enough for me to land the job?" "Is this training sufficient?" "Is this boot camp sufficient?" To be honest, the answer is always: it depends on how much experience you have.
But assuming you have zero experience and zero knowledge, and all you did was one or two certificates, the answer is maybe. You might get lucky and get hired with one certificate. In fact, I've seen people get hired with zero certificates; it definitely happens. But chances are, you will probably need more.
The certificates are meant to be used as a structured way for you to learn a subject, but especially those beginner-level certificates are meant to be the beginning of your journey. They are meant to introduce you to the field and get you started on your learning journey.
What ends up happening is after you finish one or two certificates, you'll find that you have to memorize and cram a bunch of concepts, and maybe you start to forget these concepts. You may also not have much confidence in applying for jobs or in landing your first job.
To solve this, I curated a list of practical projects that you can do progressively. You start from beginner-level projects all the way to intermediate projects, and then you do practical intermediate cybersecurity certificates. I created this roadmap specifically for people who've done some cybersecurity certificates and are looking for the next step on what to do. All of this is detailed in this video, and I'll see you then.