← Notes

Robert Chapman
I have a love/hate relationship with cybersecurity. I've loved the tech side of it since the early 90s when I first got into computers and hacking. I didn't actually get my first security role until much later in my career, having detoured through other adventures.

One of the biggest challenges I have now is that the cybersecurity space today doesn't feel at all like what it was when I was young. I don't mean in the tech sense; I always expected that to change. I mean in the culture sense.

I've gone to defcon, bsides, blackhat, etc and others and some of the time it feels right and other times I feel like an alien. Part of it is cultural/social. I don't really party and Vegas isn't my scene. I'm not a tattoo guy. I don't "look" the part. I understand that this space is a big tent and I'm painting with a broad brush but there's a stereotype that has been created and I think it's one I don't identify with at all.

There's plenty of nice people and many to learn from, but I rarely feel like I've found my tribe. It's an odd feeling.

I jumped to the vendor side a few years ago. I found a good home here. I get to still be technical but also get the social side of it. It has its own trade-offs. I still feel like an alien among the sales side some days too.

What I like probably most is the actual business of it. This is burying the lede a bit, but this is what I think I stumbled into almost by accident coming to the vendor side: seeing how security and business really meet.

I get annoyed by the white-knighting and crusading that occurs in the security space. It's often so divorced from how organizations and businesses work. There's a place for that conversation, but too often when I see the discourse around security, I think "none of these people have actually had to do this in real life with real people".

A note by Robert Chapman. More notes