Read the Beforeitsnews.com story here. Advertise at Before It's News here.
Profile image
By Arthur Hicken - CodeCurmudgeon
Contributor profile | More stories
Story Views
Now:
Last hour:
Last 24 hours:
Total:

Top 10 Ways to Spot a Cybersecurity Expert (2026 Edition)

% of readers think this story is Fact. Add your two cents.


This is a rewrite of a list I first published here on February 1, 2017. The original is still up, unedited, right here. Some of it held up. Some of it did not, and I’ve said so below.


A friend asked me a question this week. He’d been getting a lot of spam, and he wanted to know the right way to deal with it: report it, reply with “unsubscribe,” or leave it sitting in the inbox undeleted. That last one was in the running because another friend had explained to him, with great confidence, that leaving it alone was the only correct thing to do. Emphatically. As settled fact.

He asked me because it sounded wrong to him. Hold that thought. I’ll come back to it.

Notice what happened first, though. Somebody told him. He believed it for a while. And the only reason he got a second opinion is that he happens to know a guy.

I wrote this list in 2017, as a joke. Nine years later some of it is out of date, a good deal of it isn’t, and I’m not sure which half bothers me more. Old problems are comfortable. I know what they look like. What I didn’t expect was how many of them are still here.

Here’s the 2026 edition. As before, this is really how to spot someone who is NOT a cybersecurity expert.

Also, I wasn’t wearing a suit. That’s probably why he trusts me.


#10 – Wears a suit and tie

Have you ever met someone who really got cybersecurity who was wearing a tie?

I’ll wait.

Man in a dark suit and tie, shown from the chest down, holding a BlackBerry phone.

The phone stopped working in 2022. He’s still in the meeting.

#9 – Carries a phone that stopped getting security updates

In 2017 I said a phone more than a year old was a red flag. That one aged badly and I’ll own it. Apple, Google, and Samsung now ship security updates for five to seven years, so a four-year-old phone in the right hands is perfectly respectable.

The tell was never the age. The tell is a phone that stopped getting patches and a person who has no idea, because he has never once looked.

#8 – Still carrying a BlackBerry

This was a joke in 2017. It’s an archaeological finding now. BlackBerry shut down the services for its classic devices in January 2022, which means the thing in his jacket pocket is a paperweight with a keyboard.

He will tell you it’s more secure. It is, in the sense that a car with no engine is harder to steal.

#7 – Doesn’t use the command line

The reigning champion from the original list, demoted purely on seniority. Everyone with a hacker mentality uses the command line, whatever the operating system. That hasn’t changed at all. It’s just less funny than it used to be, which I suppose is a kind of progress.

#6 – Has password opinions from 2005

Two beliefs, same vintage. That eight characters is plenty, and that the real strength is in the punctuation: P@ssw0rd! and similar theater.

NIST has since come down on both. The current guidance says a password standing on its own should be at least 15 characters, and it tells sites to stop imposing composition rules altogether. No more mandatory capital-number-symbol. Length beats gibberish, and a long passphrase you can actually remember beats a short one on a sticky note under the keyboard.

I’ve been saying this since the first version of this list, and it’s still true.

Here’s a freebie while we’re here. If a site still demands a capital, a number, and a symbol, it’s running on guidance NIST retired in 2017, the same year I first wrote this list. That tells you something about how much attention anyone there has paid since. Be careful what you keep in that account.

#5 – Says “AI-powered” when you ask him how it works

Ask three simple questions. What does it actually find? What happens when it’s wrong? Who reads what it produces?

Someone who has used the thing answers all three in about a minute, and volunteers the part where it’s wrong, because it has annoyed him personally. Someone who has been briefed on the thing says “it’s AI-powered” again, slightly louder.

The technology is real. The sentence is not an answer. It’s a dodge.

#4 – Thinks the code that arrives by text is the good kind of two-factor

That code you get in a text message when you log in is called two-factor authentication. It’s better than no two-factor, so if that’s what your bank offers, turn it on today. It is not what you should be using in 2026.

Here’s why. The code goes to your phone number, and your phone number can be moved onto somebody else’s phone with a convincing call to your carrier. That’s called a SIM swap, and it has been emptying accounts for over a decade. A passkey, or a code from an app on your phone, doesn’t travel with your number.

The fake expert doesn’t know there’s a difference. The real one can tell you which of his accounts still fall back to text messages, because those are the accounts he expects to lose.

#3 – Won’t touch the airport Wi-Fi, but tapped the link in the “your package is delayed” text on the way to the gate

Skipping open Wi-Fi is good hygiene. So is carrying your own charger and finding a wall outlet instead of plugging into the public USB port. So is locking your car, even though your car is a big metal safe with four panes of easy-to-break glass in it.

A determined attacker beats all three. You do them anyway, because hygiene is cheap and habits are what hold up when you’re tired in an airport at eleven at night.

But look at what actually happened to him. A text said a package was delayed and needed a small delivery fee. He tapped the link, got a page that looked like the shipping company’s, and typed in a card number. That’s the entire attack. No Wi-Fi, no USB, nothing clever. It works because he was tired, because he really was expecting a package, and because it took four seconds.

He lectured me about the terminal Wi-Fi and then handed his card to a stranger before we boarded. The precaution wasn’t wrong. It was just the only one he had, and it was pointed in the wrong direction.

#2 – Plugged in the USB stick he found in the parking lot

“I just wanted to see what was on it.”

Researchers have been dropping sticks in parking lots and on campuses for years, and a large share of them get picked up and plugged in, by people who will swear they’d never fall for a phishing email. Curiosity is the exploit. There’s no patch for it.

I have had this conversation with a man whose job title contained the word “cybersecurity,” about a stick he found in the parking lot of a government building. He knew the trick. He had watched it happen on Mr. Robot. He was embarrassed, and he should have been.

I want to be clear that this is not a story about a stupid person. Knowing an attack and recognizing it while it’s happening to you are two completely different skills, and only one of them shows up on a résumé.

#1 – Took the “What’s your superhero name?” quiz, then tagged five friends

First pet plus the street you grew up on. Mother’s maiden name plus your first car.

These are not personality quizzes. They are the security questions your bank still uses to let a stranger reset a password over the phone, and the quiz collects the answers from you, in public, voluntarily, for fun.

Then it asks you to tag friends so they’ll post theirs. That’s the part that makes it work at scale. He didn’t just hand over his own answers. He recruited.

The guy who won’t play along isn’t a killjoy. He’s the one who read the questions before answering them.


Oh, and just one more thing

If he says “cyber” as a noun, turn around and walk the other way.

“We need more cyber.” “The cyber is a big problem.”

Nobody who has ever actually fixed anything talks like this. It’s the verbal tell that the speaker was briefed on the subject rather than having worked in it, and everything that follows will be a summary of a summary.

Here’s the part that isn’t funny. The suit and the vocabulary aren’t incidental to how he got the job, they’re how he got the job. Somebody needed a person who could stand in front of a room and say the word “cyber,” and the résumé that matched was the one that looked the part. And he isn’t merely useless in that chair. He’s a mark. He’s the one who will buy whatever the next fellow in a better suit is selling, with your budget, and put the receipt in a slide deck.

As always: if he uses a term you don’t know, make him explain it. If he can’t explain it, he probably doesn’t understand it very well.

You need somebody real in your life for this. Even more than you did in 2017.


Sorry, just one more last thing. I mean it this time.

Just delete the spam. Don’t reply, don’t click.

My friend’s friend wasn’t making it up, by the way. “Don’t reply and don’t click” is good advice. It just decayed, somewhere along the way, into “don’t touch it.” That’s how most bad security advice happens. It’s real advice with the reasoning worn off.

Stay sharp. Stay safe. And don’t tell anybody the name of your first pet.

Top 10 Ways to Spot a Cybersecurity Expert (2026 Edition) originally appeared on Code Curmudgeon on September 24, 2026.

http://codecurmudgeon.com/wp Twitter: @codecurmudgeon


Source: https://codecurmudgeon.com/wp/2026/09/top-10-ways-to-spot-a-cybersecurity-expert-2026-edition/


Before It’s News® is a community of individuals who report on what’s going on around them, from all around the world.

Anyone can join.
Anyone can contribute.
Anyone can become informed about their world.

"United We Stand" Click Here To Create Your Personal Citizen Journalist Account Today, Be Sure To Invite Your Friends.

Before It’s News® is a community of individuals who report on what’s going on around them, from all around the world. Anyone can join. Anyone can contribute. Anyone can become informed about their world. "United We Stand" Click Here To Create Your Personal Citizen Journalist Account Today, Be Sure To Invite Your Friends.


LION'S MANE PRODUCT


Try Our Lion’s Mane WHOLE MIND Nootropic Blend 60 Capsules


Mushrooms are having a moment. One fabulous fungus in particular, lion’s mane, may help improve memory, depression and anxiety symptoms. They are also an excellent source of nutrients that show promise as a therapy for dementia, and other neurodegenerative diseases. If you’re living with anxiety or depression, you may be curious about all the therapy options out there — including the natural ones.Our Lion’s Mane WHOLE MIND Nootropic Blend has been formulated to utilize the potency of Lion’s mane but also include the benefits of four other Highly Beneficial Mushrooms. Synergistically, they work together to Build your health through improving cognitive function and immunity regardless of your age. Our Nootropic not only improves your Cognitive Function and Activates your Immune System, but it benefits growth of Essential Gut Flora, further enhancing your Vitality.



Our Formula includes: Lion’s Mane Mushrooms which Increase Brain Power through nerve growth, lessen anxiety, reduce depression, and improve concentration. Its an excellent adaptogen, promotes sleep and improves immunity. Shiitake Mushrooms which Fight cancer cells and infectious disease, boost the immune system, promotes brain function, and serves as a source of B vitamins. Maitake Mushrooms which regulate blood sugar levels of diabetics, reduce hypertension and boosts the immune system. Reishi Mushrooms which Fight inflammation, liver disease, fatigue, tumor growth and cancer. They Improve skin disorders and soothes digestive problems, stomach ulcers and leaky gut syndrome. Chaga Mushrooms which have anti-aging effects, boost immune function, improve stamina and athletic performance, even act as a natural aphrodisiac, fighting diabetes and improving liver function. Try Our Lion’s Mane WHOLE MIND Nootropic Blend 60 Capsules Today. Be 100% Satisfied or Receive a Full Money Back Guarantee. Order Yours Today by Following This Link.


Report abuse

Comments

Your Comments
Question   Razz  Sad   Evil  Exclaim  Smile  Redface  Biggrin  Surprised  Eek   Confused   Cool  LOL   Mad   Twisted  Rolleyes   Wink  Idea  Arrow  Neutral  Cry   Mr. Green

MOST RECENT
Load more ...

SignUp

Login