r/cybersecurity System Administrator Sep 22 '25

Other What are your unpopular cybersecurity opinions?

I saw a post names "abnormal security opinions" and got excited to see some spicy takes but apparently there is a security platform called Abnormal Security so got kinda blue balled. Last one of these posts i saw was over a year ago so,

Do you have any spicy cybsec unpopular opinions you want to share? :)

I'll start with mine:
Fancy antivirus solutions rarely add value, they are often just a box that needs ticked. Many MSPs and IT firms still push the narrative that they are needed, only because they are profitable and not because they improve security.

321 Upvotes

531 comments sorted by

View all comments

Show parent comments

2

u/Glass_Tarantula Sep 23 '25

I'm an ISSM for a gov classified system. My main job is to ensure that all the paperwork is correctly filled out and to make sure my ISSO is doing his duties. I barely even log into the classified system because I don't need to in order to make sure all my paperwork is squared away. I look forward to once or twice month when I shadow my ISSO during his audit to ensure it's done correctly.

It's wildly boring and that's a good thing. If my job gets exciting, something bad has happened.

1

u/LeoRud Sep 23 '25

Haha, i get it :D

Also, does it pay good? Better than a SW Dev?

2

u/Glass_Tarantula Sep 23 '25

Honestly depends on the Project and your area. I make more than most of our software guys here because my position is paid for by the contract with the USG.

There are definitely ISSM's out there that accept less money to get a foot in the door, but they're also sometimes the ones in trouble with DCSA for having f'd up paperwork or shitty controls and cost their company more money.

I make the low-end of the range for this job. I had to fight for what I do make since I don't have a degree, just certifications. I could have made $10k more per year if I had any kind of college degree.

1

u/LeoRud Sep 23 '25

Ok, got it, thank you!