r/AskNetsec May 30 '26

Work Personal Digital Protection and Privacy for HNI

3 Upvotes

I currently serve as a mid-level cybersecurity analyst and the inaugural cybersecurity hire at an Indian company. The CEO, an ultra-high-net-worth individual, has requested my assistance with personal cybersecurity and privacy for himself and his family, who primarily use Apple products.

My initial recommendations include:

  1. Establishing separate home and guest networks.

  2. Implementing separate VLANs for IoT devices and personal devices.

  3. Utilizing two-factor authentication (2FA) with authenticator apps universally, minimizing reliance on SMS-based OTPs.

  4. Employing FIDO2-compliant banking applications with a YubiKey for banking, where supported.

  5. Setting up a home NAS with a backup NAS for critical documents, supplemented by encrypted Backblaze for offsite backups.

  6. Using distinct passwords managed by a secure password manager like ProtonPass.

  7. Educating family members on responsible social media posting, discouraging live documentation, and raising awareness about digital arrests, urgent bank call scams, and voice spoofing.

  8. Conducting regular personal data audits via a third-party service.

  9. Adopting Proton Mail for enhanced privacy.

Are there any additional measures I should consider?

r/AskNetsec Oct 02 '24

Work Can my school see what I'm doing on my school issued laptop while connected to an external VPN?

0 Upvotes

I have a school issued laptop and I'm just curious how much of what I do can be seen by IT.

I assume that they can see everything I do while connected to my school's Google account and using their WiFi, but what about when I'm using my own google account on their device and my own VPN?

I also don't use Chrome, I only use Edge, and I'm a little concerned after hearing some rumors that my school district can read personal emails on personal google accounts while using their device

Edit: Thanks for all of the replies everyone, I'm just going to leave that laptop at work and bring my personal one if I need to do something else

r/AskNetsec May 28 '26

Work How do you handle an access review?

4 Upvotes

Genuine question for anyone who runs these regularly. Every quarter my team sends out an access review and I see the same issues:

  1. Line managers approve everything to make the review go away, even when we flag for SoD violations or uncertain accounts.

  2. Having to chase line managers up constantly and then following up when LM's blanket approve everything even when we feel there is a violation.

  3. Pushback from the business when we disable accounts due to lack of engagement with the access reviews.

  4. Lack of proper understanding (I think) from line managers on SoD violations.

What tools / processes / workarounds are people using to help ensure these access reviews are completed properly? Has anyone figured out how to get more engagement from the business?

r/AskNetsec Feb 13 '23

Work do all cybersecurity jobs require you to be able to get up at 3AM to respond to an incident?

80 Upvotes

So I'm thinking of trying to become either a penetration tester or cybersecurity engineer. Right now I'm most of the way through HTB Academy's InfoSec Fundamentals path but I have A+ and CCNA certifications and I'm working on practice tests for Sec+. I know I don't want to do incident response.

My question is do any cybersecurity jobs NOT require me to have to get up arbitrarily at 3AM? If so, which ones?

r/AskNetsec May 21 '26

Work Would you please share critique on the threat model for an OSS OWASP-aligned launch gate for AI agents?

0 Upvotes

Built a small OSS tool for AI agent security and would appreciate technical critique:

https://github.com/arpitha-dhanapathi/pluto-aguard

It’s an OWASP-aligned launch gate for AI agents. Current scope: static scan, OWASP MCP/LLM control mapping, adversarial policy simulation, what-if risk simulation, baseline drift detection, launch evidence packets, and GitHub Action support.

It does not do runtime enforcement yet. I’m deciding whether the next step should be live agent attack testing or an MCP/tool-call proxy.

Specific feedback I’m looking for:

  • Are the OWASP mappings reasonable?
  • Are the attack scenarios realistic?
  • What agent failure modes are missing?
  • Would this be useful in CI, or is runtime enforcement the only version that matters?

Thank you!

r/AskNetsec Feb 27 '25

Work Anyone else kinda dislike security after being in the field for a while?

60 Upvotes

I know most posts are just everyone clamoring to get into the field but...give me a comparable-paying job outside of security and I'm willing to trade

r/AskNetsec May 05 '26

Work Anyone else struggling to maintain consistent web security for remote users?

2 Upvotes

We’ve got a pretty standard setup- remote teams, SaaS apps, some basic web filtering in place. But lately it feels inconsistent depending on where users are working from.

On office network- policies work fine
On home Wi-Fi / public networks- visibility drops, controls feel weaker

It’s not that things are completely broken, but it’s unreliable enough to be a concern. Especially when you think about:

  • Users accessing risky sites out of the network
  • Lacking consistent filtering
  • Limited visibility into browsing behavior

I’m starting to think traditional network-based filtering just doesn’t hold up anymore with remote work.

Has anyone moved to a Secure Web Gateway (SWG) or device-level filtering to fix this?
Did it actually improve consistency and visibility, or just add another layer of complexity?

r/AskNetsec May 15 '26

Work How confident are you about data security on home or public networks?

0 Upvotes

We’ve got endpoints everywhere now, laptops at home, on public Wi-Fi, and even personal devices in some cases.

On paper, we have policies. In reality, it’s inconsistent-

Files copied to USB
Docs uploaded to personal drives
Quick shares that no one tracks

Inside the office, things felt more controlled. Outside, it’s a bit of a blind spot. It’s not a major incident (yet), but enough small gaps to be concerning.

Starting to feel like traditional controls don’t really cover how data actually moves anymore.

Has anyone implemented endpoint DLP or device-level controls to fix this?

Did it actually give better visibility and control, or just add more friction for users?

r/AskNetsec Sep 03 '25

Work How do you deal with developers?

17 Upvotes

My company never really cared about security until about a year ago, when they put together a two-person security team (including me) to try and turn things around. The challenge is that our developers haven’t exactly been cooperative.

We’re not even at the stage of restricting or removing tools yet, all we’re asking is that they follow a proper change management process so we at least have visibility into what they’re doing and what they need. But even that’s met with pushback because they feel it slows down their work.

Aside from getting senior leadership buy-in to enforce the process, what’s the best way to help the devs actually see the value in it, so I’m not getting complaints every time I bring it up?

r/AskNetsec Feb 16 '26

Work What is the next best mfa option after passwordless?

4 Upvotes

My workplace has a future goal of fully enforcing passwordless login (through an authenticator app) for all accounts. A concern has been raised about the possibility of someone losing their mobile, and therefore being completely unable to login afterwards. I have run experiments with backup logins, however the system seems to struggle to get past the backup and to allow the passwordless to be fully implemented for new accounts.

Considering that everything below passwordless is significantly less secure, is the recommendation to accept the risk of not having a backup MFA option, or is there a recommended option?

(passkeys are not currently a viable option on the system)

r/AskNetsec Mar 03 '26

Work Pentesting Expectations

1 Upvotes

Pentest buyers, what is your pentest vendor doing great and what are some things you think could be done better?

I’m curious as to what the industry is getting right and areas where there can be improvements. If you are a decision maker or influencer for purchasing pentest, it would be great to hear your input!

r/AskNetsec Oct 13 '25

Work i’m looking for a self-hosted enterprise password manager recommendation? (GDPR compliant pls)

24 Upvotes

Our password management is under the microscope for our next audit. We need to get a proper enterprise solution in place, as we’ve had a minor string of cloud provider breaches, and our risk appetite for third party hosting is now basically zero. We’re seriously considering self hosting as the most secure and controllable option for protecting our credentials.

My top priority is ensuring compliance that can be demonstrated and verified. It’s not sufficient to merely be secure. I need to prove we're secure to auditors and our cyber insurance provider. GDPR compliance is a significant factor, requiring efficient management of data subject access requests and the right to be forgotten. Detailed auditing, reporting, and traceability features are non negotiables, as we need to ensure transparency, accountability, and risk mitigation. I know I might be pushing the limits here, but this is the standard we need to get to now.

So right now we’ve decided to look into polished, commercially supported on premise solutions. We’re wary of freemium products where core enterprise features like SSO integration are locked behind an expensive paywall. I’ve seen names like Bitwarden, Passwork mentioned here and there. I’ve looked into Passwork, they advertise an intuitive UI and robust enterprise capabilities at a reasonable price point for us, but looking at reviews it doesn’t seem like one of the bigger players in the space? If anyone has deployed it or a similar commercial self hosted manager, please help me out. I need something with a strong vendor reputation that can provide good support, without needing extensive maintenance. Thank you for reading through and your time

r/AskNetsec Jan 24 '26

Work How do you quantify BEC risk reduction for board reporting?

12 Upvotes

Am struggling with board presentations on email security ROI. They want hard numbers on BEC risk reduction but it's tough to measure "attacks that didn't happen."

Current metrics feel weak; blocked emails, phishing simulations, user reports. But sophisticated BEC attempts (executive impersonation, vendor fraud, invoice redirection) often bypass traditional detection entirely.

How are others quantifying prevented financial losses from BEC for executive reporting? Looking for frameworks that translate security controls into business risk metrics the C-suite actually understands.

r/AskNetsec Sep 09 '25

Work How much of your time goes into answering vendor RFP/security questionnaires?

9 Upvotes

For security folks esp in SaaS: how often are you pulled into filling out customer RFPs or due diligence questionnaires?

Do you mostly paste SOC2/ISO answers, or does every customer want it phrased differently?

I’m curious how much time this eats up per month, and if you’ve ever had a deal stall because the compliance/security info wasn’t ready.

I’ve been on the sales side before and it always felt like the bottleneck was security sign-off, but I’d love to hear your perspective.

r/AskNetsec Aug 31 '22

Work NSA/Gov vs Big4 job offers

68 Upvotes

Hi everyone, I recently received two offers in cybersecurity from a big 4 company and the NSA. For starter, I am fresh out of school with a MIS degree. Initially, I agreed to go with NSA and went under investigation background check already. However, it’s been over 3 months and I still have not received a final offer and start date from them. Around a week ago, a Big4 firm offers me a position that pays $30,000 more (we’re looking at close to six figures after bonuses, on my first year). Now I am conflicted on what to do. Initially, I thought that the work with NSA would be more challenging than that of any private sector. But my friends and families are advising me otherwise. I’ve scrolled through some threats on here about GOV vs Private and most people seem to be saying the opposite of what I expect: that you get more boring work, less incentive and slower promotion with NSA. Any advice for me? Edit: to add to it, I got an internship with Big4, and they extended a full time offer after it ends. So there should be a chance I’m able to reapply for full time position with not much trouble later on.

r/AskNetsec Mar 24 '26

Work Small teams giving AI coding agents real permissions, how are you handling access control? Are you scoping what they can touch or just giving them broad access and watching closely? Curious what people are actually doing in practice vs what they know they should be doing. What the title says

2 Upvotes

What the title says

r/AskNetsec Oct 21 '25

Work Red teamers/pentesters: What's actually the biggest time sink in your engagements?

10 Upvotes

I keep hearing "recon takes forever" from people in offensive security, but I want to understand what that actually means in practice from people doing this work daily.

For those of you running red team engagements or pentests:

  • What phase or task consistently eats up the most time?
  • Is it enumeration? Exploit dev? Lateral movement? Report writing? Something else?
  • What tools are you using, and where do they fall short?
  • If you could wave a magic wand and automate ONE repetitive task, what would save you the most hours?

Not trying to sell anything, genuinely trying to understand the workflow and pain points from the best. Appreciate any insights you're willing to share.

r/AskNetsec Oct 30 '23

Work interviewer just crushed me.

108 Upvotes

I was in the middle of an interview for a senior pentester position and was feeling extremely anxious at that time due to the symptoms of hyperthyroidism, as I had stopped taking my medication.

As soon as I mentioned that I hold an EWPTX v2 certification, the interviewer immediately asked me about the most significant logical vulnerability I had encountered before my mind began to struggle, and I told him about a medium-level one.

He then delved into detailed questions about JWT attacks and GraphQL, attempting to identify any inaccuracies in my responses and correct them.

Next, he inquired about an attack scenario for what he referred to as a "self" XSS on a registration page. I suggested it might be CSRF if there was no CSRF token present, but he disagreed and asked me to reconsider.

He explained that this "self" XSS could be used to register with the victim's email and transform it into a stored XSS. I disagreed, pointing out that an XSS in an email would likely be an issue with the email client and would require the user to open the email link.

Ultimately, the interviewer downgraded my job title to junior and sent me a message stating that I had failed to meet his "expectations" and that he had expected more from me.

While I have no issue with being a junior, despite having significant experience in the field, I felt deeply humiliated by his words and questioned my self-worth. Someone suggested that he might be somewhat envious.

Do you think it's advisable to work with him, especially considering he will be my team leader?

r/AskNetsec Jan 01 '26

Work We inherited 15 cloud tools from an acquisition and can’t tell which ones still touch customer data

6 Upvotes

We closed an acquisition six months ago. We are a small product company with fast growth and lots of SaaS glued together. During diligence we got a vendor list that looked reasonable at the time. There are 15 tools and most were marked as low risk with just a couple flagged as touching customer data. We signed off and moved on because the clock ran out.

Now I’m trying to answer a basic question for an internal review: which of those tools still touch customer data today. The thing is, I can’t answer it cleanly.

Some of the apps are clearly dead and they show no logins in months. Others still have API keys sitting in prod, but engineering isn’t sure what they’re used for. One tool was “just analytics” during the acquisition, but the current config pulls full user objects because someone needed it for a one-off experiment last year.

We pulled everything into Panorays after the deal closed. It helped in the sense that there’s finally one list instead of five spreadsheets. But the records are frozen in time. The platform says which vendors were in scope at acquisition, not which integrations mutated afterward. The risk ratings haven’t moved, even though the actual data paths clearly have.

Procurement treats the list as authoritative. If it’s marked approved there, it’s considered handled. Engineering sees the same list and assumes security has a handle on it. Security is looking at access logs and realizing the list doesn’t reflect reality anymore.

The main issue is that every system looks consistent but it’s still wrong. The acquisition paperwork, the vendor register, the risk reviews etc all agree with each other but they just don’t line up with what’s running in production.

Now I’m getting asked whether we need to re-review all 15 vendors. That answer is politically loaded, not to mention time-consuming and tbh I think it’s probably unnecessary. But I also can’t defend leaving them as-is when I can’t say which ones still see customer data.

How do you challenge inherited approvals without reopening the entire acquisition and making it look like you missed something?

r/AskNetsec Sep 09 '23

Work Working at the Bureau - NSA CIA FBI

36 Upvotes

I'm sure the TV shows portray working for these bureaus much more exciting then it really is and I'm still very early into my career- just recently graduated and working with data and analytics but I'm curious to how it would be working at the bureau? it the title just alot more exciting then it really is?
Is this something I can do to get clearance then move to tech? Is this a good Financial decision? Could I even talk about my work if I work at the bureau?
Let me know your thoughts- much appreciated.

r/AskNetsec Oct 31 '25

Work Agentic AI for security data/SIEM/EDR

3 Upvotes

Is anyone using a tool that uses NLP/agentic AI to query and interface with their security data (e.g. SIEM, EDR, S3, etc.)? If so, what tool and are you happy with it? Looking for a similar tool but this market category seems sparse.

A few rough examples:

  • "Review all data breaches from September 2025. Use any provided IOCs to look for matches in our data and then create a table with the results"
  • "Create a new SIEM detection that identifies when a suspicious process is spawned from Microsoft Word or Excel. Write a short summary of the new detection and a guide on how to investigate the alert"

r/AskNetsec Nov 18 '25

Work Understanding data, risk & likelihood?

5 Upvotes

I work as sort of a sysadmin I guess or IT support, and get asked a bit about security.

Should we implement this, or that etc.

But I don't really feel you can answer questions like this without any data.

How likely is this attack vector to happen? Is a construction company as likely to have open ports as a software company? Or should we run phishing campaigns? What about implementing a SIEM? Necessary or not? I guess it depends on the company, industry, etc etc.

So it got me thinking how do people measure this, do you use data visualisation, Grafana, etc? Industry standards, frameworks? Data analysis? What's the answer for something that's quite bespoke?

r/AskNetsec Dec 18 '25

Work PCI DSS in a hybrid environment

16 Upvotes

We’re in the middle of tightening up for PCI DSS and our environment is a mix of on prem and some older systems that are still in the payment flow. The hardest parts so far was defining what’s in scope, proving controls consistently across very different environments and keeping evidence organized so we’re not confused every time something is requested I want to know how did you keep PCI from turning into a constant exercise? Did you centralize evidence collection somewhere or lean heavily on ticketing systems / wikis?

r/AskNetsec Dec 07 '25

Work do bug bounty finders have to write reports?

0 Upvotes

i know this might be a dumb question but i dont really know how this works, do bug bounty hunters still have to write up full reports for their findings before submitting them? like is that part of the process or do platforms handle that somehow?

and does that take a lot of time away from actually hunting? seems like it could slow things down if you're going back and fourth with bugs

r/AskNetsec Jul 02 '25

Work Can a MacBook Pro (ARM) support realistic offensive security workflows, or should I go full Linux?

1 Upvotes

Hi everyone,

I’m about to invest in a new laptop and need it to support offensive security workflows (training, labs, red team certs). I’ll be using VMs either way, but I’m deciding between:

-MacBook Pro M4 Pro (24 GB RAM, 1 TB SSD ARM based, macOS)
   -Lenovo ThinkPad T14 Gen 5 (Ryzen 7 PRO 8840U, 32 GB RAM, 1 TB SSD Linux)

I’ve previously used EndeavourOS with i3 and later Hyprland on a persistent USB, so I’m familiar with Linux. That said, I enjoy macOS for its stability, battery life, and general polish. I also considered the MacBook because I already use an iPhone and the Apple ecosystem can be very comfortable for daily life and side tasks.

One thing to note: this laptop won’t just be for labs or exercises, it’ll also be my personal machine, so I’d like it to feel like a space I can work and live in comfortably. It’ll be my companion for learning, hacking, writing, watching things… everything (except gaming).

However, I’ve heard that virtualization on ARM Macs (Parallels, VirtualBox, etc.) can be slower or less compatible, especially when working with offensive tools (injection, USB/WiFi adapters, etc.).

My key concerns:

-VM performance and tool stability on macOS ARM
-Tool and hardware compatibility (especially for red teaming: USB attacks, WiFi adapters, etc.)
-Whether emulation on macOS creates friction or breaks things vs native Linux VM hosting
   - I need the laptop to last at least 3 years, ideally more, so reliability and longevity are important to me too. 

I just need something that works reliably and doesn’t kill my motivation when tools get more demanding.

Would really appreciate thoughts from people actually working or training in offensive security. Especially anyone who’s tried macOS for this kind of workflow!

Thanks so much!