Alright, let’s skip the formalities. Cyber security is just as relevant in 2026 as ever. I’m Jake, a sysadmin at an MSP that handles IT and security for places like banks and credit unions. I’ve seen a lot, so here’s how it really feels—straight talk, no romanticizing.
Why’s Cyber Security Still the Big Thing?
Honestly, when I first got into IT, cyber security had the same hype it does now. Everyone treats it like a level-up, like you’ve made it if you’re in. I fell for the dream, too—sneaky hackers, complex attacks, being the hero who outsmarts everyone. Sounds cool, right? The reality? It’s a lot less Hollywood. Once I moved up the ladder from help desk to sysadmin, I got to see what the job actually looks like for cyber folks.
So will it be worth it in 2026? For sure. But you’ve got to understand what the work really is and what you’re walking into.
What’s the Day-to-Day Really About?
If you’re thinking every day is a red team exercise, hacking your own company, you’re dreaming. Most of the time, you set up MFA, run phishing tests, patch things, and fine-tune Microsoft security policies. There’s DNS filtering, chasing compliance, and plenty of tasks people call “boring” but are essential.
You’re not in shootouts with hackers daily. Usually, you’re making things air-tight so those hackers don’t even get a chance. That’s real cyber security. You stop fires from starting instead of playing firefighter all day.
So Why Is Everyone Flocking to Cyber Security?
Cool job titles, solid pay, and endless “major breach” stories on LinkedIn keep people interested. But here’s the catch: everybody’s trying to break in. Entry-level jobs? They’re flooded with people bringing degrees, certifications—A+, Net+, Sec+, all the rest. You’ll see folks with a CISSP in the applicant pool for help desk level jobs. The competition is heavy.
Don’t Shortchange Your Career
I used to ask people if I should jump directly into cyber. A friend told me, “Don’t.” He said figure out IT first—and he was right. If you hyper-focus on cyber too early, you miss how the full stack actually works. So, be a generalist before you specialize. If you want to be great at security, understand how systems, networks, and cloud environments fit together. Spend real time on the help desk or as a sysadmin. When you finally pivot, it’ll make sense and you’ll move faster.
What’s Entry-Level Really Mean Here?
Honestly? You’ll spend a lot of time running phishing simulations, dealing with spam, and handling basic incidents. A lot of that detective work? The tools do it for you now. You’re reviewing logs, investigating alerts, but you’re not Sherlock Holmes over here.
If you’re at a regulated bank, it’s all locked down, breaches are rare. At smaller companies, you’ll see more chaos—usually just untangling bad setups, like no MFA or shoddy firewall rules.
Who’s Actually Protecting the Network?
It’s not just people with “cyber security” in their job titles. Most core security happens at the sysadmin and network engineer level. We’re the ones setting up access controls, configuring firewalls, deploying password managers—doing the stuff that actually builds the wall, not just watching it.
So, Who Should Go Into Cyber Security?
If you don’t have your IT basics down, don’t bother yet. You can’t protect what you don’t understand. If you dig procedures, documentation, and compliance, you’ll enjoy it. If you want fast-paced action all day, you’ll probably get bored out of your mind.
Some folks get obsessed with the technical side—homelabs, chasing certifications, always learning. But if you think it’s all movie-style adrenaline, you’ll get disappointed. Security is process, not just drama.
Jake’s Recommended Path
Start with A+, Net+, Sec+—or Google’s certs if you prefer. But don’t skip the basics: networks, cloud, OS, all that. Work a help desk or sysadmin role for a couple years, then target SOC analyst or beginner security jobs.
Easiest route? Grow into sysadmin or cloud admin, then pivot into security work. If you specialize in security too early, it’s tough to go back into regular IT—but going IT to security is no problem.
Bottom Line
Is cyber security worth it? Still, yes. Not because it’s glamorous, but because it’s crucial. Every good IT pro needs security skills—it keeps the wheels turning in banks, hospitals, everything.
I might go full-on into cyber someday, but right now, I enjoy building and securing the bones of our environment. Good security comes from solid foundations, end of story.
Cyber security isn’t a fantasy or a thrill ride. It’s a discipline, a mindset. The sooner you accept that, the easier everything gets.
If you’re starting out, check out my other guides on certs and “a day in the life” stories. Drop a question if you’re curious. Stay smart out there.
So, 2024—new year, new update. I’m closing out my second year as a SOC analyst, and things have shifted since I started. Here’s what a regular day looks like these days, now that I’ve got a bit more experience.
I work from home 90% of the time. There’s really no difference between remote and in-office when you’re doing this work. Forget those grindy morning routines—it’s not my style.
The Calendar Rules My Day
First thing, I check my calendar. It sets the tempo. Light day? Fewer meetings? Great, I can focus on actual work.
Last year, my meetings were pretty minimal. Now, I’m dragged into bigger stuff—vendor reviews, project planning, one-on-ones with management. It’s not always fun, but that’s what happens as you level up.
Splunk SOAR: Fighting Phish in Bulk
Next up, Splunk SOAR—our alert platform. It pulls in all the user-reported phish, scrubs them with automation, then leaves the actual threats for us. I scan the new phishing events, check the details (like what automations ran, what “artifacts” got flagged), and see how much time we saved—automation is a life-saver.
Catching Phishing Emails: Red Flags
When I check a suspicious email, I look at the subject first—lots of exclamation points? Immediate red flag. Sender look normal, but the greeting’s suspicious? Still a flag.
Hyperlinks always get checked. If the link text says “IT Portal” but goes somewhere sketchy, that’s a problem. I plug the URLs into VirusTotal—if anything pops, I block the sender, wipe out the links, done.
We use low-code playbooks—drag, drop, follow the prompts, and the system handles the rest.
Splunk SIEM: Watching for the Weird Stuff
With phishing cleared, I hit the SIEM dashboards. These pull log data from everywhere to help spot threats. I built dashboards to track things like failed login attempts—good for catching odd behavior early. The queries are a little intimidating at first, but you get good with practice.
Help Desk & Incident Response
Then it’s help desk tickets. People need access or have issues. Most are routine, but sometimes you see actual incidents—odd logins, strange devices, random activity spikes. That’s when you dig deeper, looking for IOCs (indicators of compromise).
Afternooon: ISO 27001 and Vendor Chores
After lunch (and more coffee), I do the heavy stuff: ISO 27001 work. Lots of checklist grinding, tons of meetings with vendors, making sure every app is secure, checking encryption, backups, all that. Tedious? Sure. But it makes your resume better and helps you grow.
Chasing Vulnerabilities with CrowdStrike
I also use CrowdStrike to stay on top of updates. Out-of-date software is an attacker’s playground. I check which machines need patching and push the updates—hoping users don’t hit “postpone” for the twentieth time.
If someone downloads malware—like a sketchy Autodesk keygen—CrowdStrike usually blocks it. If not, I step in and add it to our block list.
Winding Down with Dev Work
End of the day, I get into some dev work—mainly dashboards. I’m a software guy at heart, and it’s kind of my zen after a busy day. I track blocked threats so management realizes we’re actually stopping attacks. Sometimes management wonders why they pay for security if nothing bad’s happened. That’s the point: because we’re doing our jobs, the bad stuff doesn’t happen.
Closing Thoughts
That’s what a day looks like—phishing, SIEM logs, tickets, chasing vulnerabilities, meetings, and building reports. Not glamorous, but it’s solid work. If you found this useful, let me know. Good luck out there!

