Free email without sacrificing your privacy
Gmail is free, but you pay with your data. Proton Mail is different.
We don’t scan your messages. We don’t sell your behavior. We don’t follow you across the internet.
Proton Mail gives you full-featured, private email without surveillance or creepy profiling. It’s email that respects your time, your attention, and your boundaries.
Email doesn’t have to cost your privacy.
Every other issue of this newsletter starts with something going wrong. This one doesn't. Instead of an attack, this week is about a number that surprised me enough to build a whole issue around it: more than a third of people currently working in cybersecurity started taking on that work while they were still in an IT role, before their title ever changed.
If you work IT support and have wondered whether a security role is realistic, the honest answer from the data is: it already might be happening, you just haven't called it that yet.
The transition doesn't start with a certification. It starts with noticing you're already doing some of the work.
The data breakdown: what 929 hiring managers actually said
ISC2 surveyed 929 hiring managers across Canada, Germany, India, Japan, the UK, and the US in 2025, specifically asking how people actually end up in cybersecurity roles. The answers cut against the usual assumption that you need a dedicated path in from the start.
Here's what the report found:
36 percent of respondents took on cybersecurity responsibilities while they were still in an IT role, before formally moving into a cyber-focused position.
20 percent moved directly from IT into cybersecurity with no interim step at all.
90 percent of hiring managers said they would consider candidates with IT work experience alone, no formal cybersecurity background required.
89 percent said they would consider candidates with only entry-level cybersecurity certifications.
Put together, that is a majority of hiring managers explicitly saying the on-ramp most IT people worry they don't have is one they'd actually accept.
Why this matters right now
Here's the part of the report that keeps this from being an uncomplicated good-news story: the same research found that entry-level talent exists, but many organizations still expect mid-level capability from day one. In plain terms, hiring managers say they're open to less experienced candidates, and job postings often don't reflect that.
That gap is not your fault, and it is not a sign the path doesn't exist. It is a sign the path is inconsistent, which is exactly why it helps to know what actually moves the needle instead of guessing.
The report also notes that certification curricula have expanded but don't always keep pace with the applied skills employers are actually asking for now, things like cloud security and AI-related risk. That tracks with everything this newsletter has covered in the AI security pillar. The skills gap is not just about getting a certificate, it is about being able to talk credibly about the risks organizations are dealing with right now.
Practical fixes you can apply this week
For IT support staff
1. Write down what you're already doing that counts. MFA troubleshooting, phishing report triage, access requests, patch deployment, log review when something looks off. This is security work with an IT job title on it. Start keeping a running list.
2. Pick one applied skill area and go narrow, not wide. Cloud security basics or a specific detection/response skill will do more for you right now than a broad survey course. The data says employers want applied skill, not just vocabulary.
3. Use free hands-on practice before you pay for anything. You do not need to spend money to find out if this work interests you. More on this below.
For hiring managers and IT leads
4. Check whether your job postings match what you'd actually accept. If 90 percent of managers say they'd take IT-only experience but your posting lists three years of dedicated security experience as required, you are filtering out the exact candidates your own survey response says you want.
5. Give internal IT staff a real path, not just a suggestion. Formal shadowing, a mentor, or a defined set of responsibilities to take on turns "maybe someday" into an actual pipeline.
6. Weight applied skill over credential count. The report is clear that certifications alone are not the differentiator hiring managers say they care about most.
This Week in "Please Don't Do That"
This one's for the hiring managers, not the help desk, for once.
Please don't post a job listing asking for "3-5 years of cybersecurity experience, entry level" for a role you'd genuinely consider filling with someone who has zero years and one relevant certification.
If you would actually accept the candidate the data says you'd accept, write the posting for that candidate. Otherwise you're not hiring entry-level, you're hiring mid-level and calling it entry-level.
Tool worth knowing: TryHackMe (the free tier, used honestly)
If you want to find out whether hands-on security work is actually for you before spending a dollar, this is where to start.
TryHackMe's free tier includes the Pre Security and Introduction to Cyber Security learning paths, covering networking basics, Linux fundamentals, and introductory security concepts assuming zero prior background, plus a large number of free practice rooms beyond those two paths.
Here's the honest limit: complete structured paths, like a full SOC Level 1 track, mix in premium content, so the free tier will not carry you through an entire career-track path for nothing. What it will do is give you real, hands-on exposure to whether this kind of work holds your attention, which is the actual question worth answering before you spend money on anything else.
Once TryHackMe stops being enough
If you go through the free basics and want to keep going, especially toward SOC and blue-team work specifically, this is worth knowing about too.
In September 2025, HackTheBox acquired LetsDefend, the platform built specifically around SOC analyst training: alert triage, log analysis, and the kind of hands-on incident practice this issue keeps coming back to. Account integration between the two platforms took effect in June 2026, so LetsDefend's SOC-focused content now lives under the HackTheBox umbrella rather than as a separate platform.
Quick disclosure: I'm an affiliate for HackTheBox, so if you sign up through the link below I may earn a commission. I'm mentioning it here because it's a genuinely good next step for the exact skills this issue is about, not because of that.
Checklist tie-in
This issue is less about a specific checklist item and more about the mindset behind the whole checklist: security is made of specific, learnable, checkable habits, not a mysterious skill set reserved for people with a particular title. If you can work through the checklist and understand why each item matters, you already have more of the foundation than you might think.
One question for you
If you work in IT support right now, what's one thing you already do that is quietly security work, even if nobody calls it that?
Hit reply and tell me. I'm genuinely curious how many of you already have a running list before I asked. I read every one.
Talk soon,
Ron
Cloud and Cybersecurity Engineer, SecureByDefault
Sources
ISC2, "2025 Cybersecurity Hiring Trends" report, based on a survey of 929 hiring managers across Canada, Germany, India, Japan, the UK, and the US · ISC2 Certified in Cybersecurity (CC) program and pricing status (confirmed no longer free for new enrollments as of May 2026) · TryHackMe, free tier content scope · HackTheBox and LetsDefend, acquisition announcement (September 2025) and account integration timeline (June 2026) · SecureByDefault 25-Point Security Checklist

