Skip to main content

Command Palette

Search for a command to run...

Tea time#4: Myth vs Reality

Updated
2 min readView as Markdown
H
The internet is messy. Attackers are creative. Security shouldn't be boring. My aim is to serve bite-sized explanations, cybersecurity deep dives, industry news, beginner-friendly guides, and the occasional meme—because learning about threats shouldn't feel like reading a textbook.

Spilling today's cyber tea...

One of the biggest myths I believed when I started learning cybersecurity was:

"I'll get hired once I collect enough certifications."

So I made a list.

CCNA. Security+. eJPT. OSCP. AWS. Azure. Google. Splunk. Linux. Python.

Every time I finished one course, another certification magically appeared on my "must-have" list.

The finish line kept moving.

Then I started reading job descriptions more carefully.

I noticed something interesting.

Recruiters weren't just asking about certifications.

They wanted people who could:

  • Investigate suspicious activity.

  • Analyze logs.

  • Explain security incidents.

  • Write scripts.

  • Troubleshoot problems.

  • Communicate with teams.

  • Think critically under pressure.

A certificate can tell someone you've studied.

It doesn't prove you can investigate a compromised endpoint or explain why an alert is a false positive.

Imagine two candidates.

Candidate A

  • 12 certifications

  • No projects

  • No GitHub

  • No blog

  • No practical experience

Candidate B

  • 2 certifications

  • Built a home SOC lab

  • Documented MITRE ATT&CK mappings

  • Published cybersecurity blogs

  • Created detection rules

  • Can confidently explain their projects

Who would you interview?

Exactly.

What Actually Helped Me Learn:

Instead of chasing every certification, I started asking myself:

"Can I explain this concept to someone else?"

That's when things changed.

I started:

  • Building projects.

  • Breaking virtual machines.

  • Solving CTF challenges.

  • Reading incident reports.

  • Writing blogs.

  • Exploring Windows Event Logs.

  • Learning why attacks work—not just what they're called.

Ironically, that's where the real learning happened.

-Don't Collect Badges. Collect Skills.

Certifications are valuable.

They provide structure.

They validate knowledge.

But they shouldn't become the goal.

The goal is becoming someone who can solve security problems.

Sometimes the best thing you can add to your resume isn't another certification.

It's a project that demonstrates what you can actually do.

If you're feeling behind because someone on LinkedIn earned three certifications this month, remember this:

Cybersecurity isn't a race to collect digital badges.

It's a journey of building curiosity, practical skills, and confidence.

Learn deeply.

Build consistently.

Share what you learn.

The certifications will always be there.

Your growth matters more.

Until next time, keep spilling the cyber tea...☕

1 views