Hello friends! 👋
Welcome to another issue of Simplifying Cybersecurity. This is the weekly newsletter where I distill 25 years of vCISO experience into my favorite ideas, tools, and career hacks. No hype. No fluff. Signal only.
Let's get into it.
🧠 1. A Mental Model for the AI Arms Race
Attackers and defenders are both racing to adopt AI. Here's a framework for thinking about where you fit.
Think of AI in cybersecurity like a force multiplier on both sides of a chess board. On the offensive side, threat actors are generating hyper-realistic phishing emails, building polymorphic malware that evades signature-based detection, and producing deepfakes for social engineering at scale. On the defensive side, AI-powered tools like Darktrace, CrowdStrike Falcon, and Microsoft Security Copilot are detecting anomalies faster, automating triage in the SOC, and reducing incident response times.
A 2025 study found that 88% of security teams report significant time savings through AI (Source: World Economic Forum). Google's Big Sleep AI agent discovered a real SQLite vulnerability (CVE-2025-6965) by proactively scanning for unknown bugs in open-source code (Source: Google Security Blog).
The Hack: You don't need to become an AI engineer. But you do need to understand how AI fits into detection, response, and threat intelligence workflows. Start by learning how your SIEM or EDR vendor integrates AI features. That knowledge is a career differentiator right now.
📋 2. The "Teach Myself" List for the 2026 Job Market
The cybersecurity job market has 3.5 million unfilled positions globally (Source: Cybersecurity Ventures). Entry-level analyst roles average around $85,640/year, and mid-level SOC and threat intel roles range from $107,000 to $130,000 (Source: IronCircle Career Guide).
But hiring managers are shifting away from credentials alone. They want demonstrated skill. Labs. Simulations. Practical exams. Hands-on problem-solving.
Here's a starter "Teach Myself" list for 2026:
Build a home lab and practice log analysis with a free SIEM (Security Onion, Wazuh).
Complete one TryHackMe or Hack The Box learning path per quarter.
Learn the basics of Python scripting for automating SOC tasks.
Study how AI integrates with at least one security platform (CrowdStrike, Sentinel, Cortex XDR).
Practice explaining a technical finding to a non-technical audience (boards, executives, clients).
My Challenge: Pick one item from this list. Block 30 minutes on your calendar this week. Knowledge compounds. Start stacking it. 📚
🔍 3. The Breach Diagram: How a Vendor Became the Backdoor
🔴 The SitusAMC Breach (2025)
One of 2025's most impactful breaches didn't start inside a bank. It started inside a trusted third-party vendor. SitusAMC, a U.S.-based financial services and technology provider, was compromised. That breach then exposed sensitive financial data tied to JPMorgan Chase, Citi, and Morgan Stanley. The banks themselves had strong internal controls. The weak point was the access they gave to an external partner (Source: KyberSecure).
How it happened (simplified):
[Attacker] → [SitusAMC systems breached] → [Vendor access to bank data] → [JPMorgan, Citi, Morgan Stanley data exposed]The Lesson: Third-party risk is business risk. If you're studying for a career in cybersecurity, learn how vendor risk assessments work. Understand what "least privilege" means for third-party access. Every breach post-mortem in 2025 points back to the same gaps: excessive vendor access, weak MFA, and delayed detection (Source: KyberSecure).
🛠️ 4. A Tool to Beat the "Doom-Scroll" Job Search
Career stagnation hits hard when you're between roles. Scrolling job boards for hours feels productive. It isn't.
Try the "One Command" Rule. When the scrolling starts, close the browser and open a terminal. Pick one command-line tool you don't know and run --help. Read the output. Try one example.
Here are three tools worth your time right now:
jq- Parse and filter JSON from API responses and log files.grep -r- Recursively search directories for patterns (a core log analysis skill).curl- Make HTTP requests from the command line (essential for API testing and recon).
Why this works: Movement beats paralysis. Every command you learn is a skill you own. Hiring managers notice candidates who built things, broke things, and fixed things on their own. That matters more than a polished resume with no proof behind it.
🎯 5. The Number That Should Change Your Timeline
The top skill gaps employers report for 2025-2026:
AI/ML security: 41% of organizations report a gap
Cloud security: 36%
Risk assessment: 29%
Application security: 28%
(Source: StationX Cybersecurity Job Statistics)
97% of organizations are using or planning to use AI-enabled cybersecurity tools (Source: StationX). If you're studying for your first certification, that's the signal. Security fundamentals still matter. But pairing those fundamentals with cloud or AI knowledge puts you ahead of most candidates.
Five years from now, you'll be five years older no matter what you do. You might as well spend that time becoming the analyst that companies need.
🚨 The 30 Day Career Sprint: Becoming a Cybersecurity Analyst is now available on Amazon!
If you're ready to stop overthinking and start moving toward your first role in cybersecurity, this book is your roadmap. Grab your copy here ➡️ https://simplifyingcybersecurity.com/30DayCareerSprint
Have a great week!
Jerod Brennen
🔗 Connect with me on LinkedIn
👥 Join the Simplifying Cybersecurity group
Did someone forward this to you? Subscribe so you don't miss next week's issue. Have a question or topic you'd like covered? Hit reply. I read every message. 💬


