Let’s skip the suits and buzzwords—cyber security’s still a big deal in 2026. I’m Jake, sysadmin at an MSP serving banks and credit unions. I’ve seen all sides, so let me give you the real story, not the hype.
Why’s cyber security still such a huge focus?
When I first got into IT, everyone treated cyber roles like reaching the big leagues—you’re fighting hackers, defending systems, pulling some superhero moves. It sounded intense, and I totally bought it. But let’s be honest, most days aren’t like Hollywood at all. Once I traded in the help desk gig for sysadmin work, reality set in.
Is cyber security worth it in 2026? For sure—it just helps to know what you’re actually signing up for.
So, what’s the actual day-to-day?
If you’re picturing yourself hacking away like some red team action movie, sorry, but that’s not most of it. My real days? Setting up MFA, running phishing drills, installing patches, and constantly tweaking Microsoft policies. DNS filtering, compliance headaches—the boring, behind-the-scenes stuff. Thing is, all that boring work is what keeps the bad stuff out.
You’re not fighting hackers every other hour. The goal is to make sure things are so tight that the attackers don’t even get in. Good cyber security is more about keeping fires from starting than putting them out.
So why’s everyone chasing this career?
Well, the titles sound badass. The paycheck’s nice. And news feeds love making every breach a headline. But here’s the catch: entry-level jobs are stacked with competition. Tons of people collect certs—A+, Net+, Sec+, sometimes even CISSP—and all line up for the same gigs. It’s a crowded field starting out.
Don’t skip the basics.
People ask me all the time if they should jump right into security. My answer? Don’t. Get your hands dirty with IT first. Knowing how things work underneath—networks, servers, all of it—sets you up for real success in security. Start as a generalist—help desk, sysadmin—then pinpoint security. Once you pivot, the whole picture makes sense and you move faster.
But what’s it actually like at entry-level?
Expect a ton of phishing simulations, tackling spam, and scrubbing up minor incidents. The cool “investigator” part? These days, automation does a lot of the heavy lifting. Mostly you’re reviewing logs and alerts—not exactly living a detective movie.
If you’re working at a bank, everything’s tight and regulated. True breaches are rare (thank God). At a smaller place, brace yourself—messy setups, missing MFA, firewall fails. More chaos, more hands-on work.
Who’s keeping things protected?
It’s not just the “cyber security” folks. Sysadmins and network engineers are in the trenches—managing access, locking down firewalls, rolling out password managers. We build the walls, not just stand guard.
So, who should actually aim for cyber security?
If you’re still shaky on IT basics, slow down. You can’t lock up what you don’t understand. But if you geek out on processes, compliance, and documentation, you’ll fit right in. Chasing non-stop excitement? You’ll burn out fast.
Sure, some people love homelabs, snatching up every cert, and always picking up new tricks. That learning side is legit—but if you want endless drama, you’re in for a disappointment. Cyber security is about routines and consistency, not a real-life action movie.
Here’s the best route I can suggest:
Start with some basics—A+, Net+, Sec+ (or Google’s version). But don’t ignore the real skills: networks, cloud, OS fundamentals. Grind a couple years at the help desk or as a sysadmin, then slide over to entry-level security, like SOC analyst.
Honestly, being a sysadmin or cloud admin is fantastic, and from there, moving into security is smoother. Jump straight in too early, you may find it tough to back up and get core IT experience later on. But the other way around? No problem.
Bottom line—cyber security is worth it.
Not because it’s glamorous, but because it keeps everything running, everywhere: banks, hospitals, you name it. Every good IT pro needs at least some security know-how.
Will I go full-on security one day? Maybe. But for now, I love building the guts and locking them down. Security is only as strong as your basics.
Forget wild chase scenes and “movie hacker” nonsense. Cyber security is all about mindset. Get that straight, and everything else just clicks.
If you’re new, check out my other guides about certs and everyday life in the trenches. Got questions? Shoot them my way. Stay sharp.
Here’s a quick 2024 update.
I’m now wrapping up my second year as a SOC analyst, and things have shifted since I started out. Here’s a window into what the job really looks like now, with a bit more time under my belt.
I work from home pretty much all the time. For this job, whether you’re at home or in an office—makes no real difference. No need for those fake “morning routine hacks”—if you know, you know.
First thing? Check my calendar.
Meetings run my day now. If it’s quiet, less chaos. It used to be lighter last year, but these days I’ve got more—vendor chats, planning sessions, manager one-on-ones. Not the funnest, but that’s how you know you’re leveling up.
Splunk SOAR: The phishing battle
Next, Splunk SOAR. It scoops up all the phishing emails users report, lets automation clear the boring ones, and leaves us the real threats to chase. I scan through new events, see what automations did, dig into artifacts, and check how much time automation saved (it’s a lot).
Hunting bad emails looks like this:
Sketchy subject lines with endless exclamation points, messages “from the boss” that look fishy, weird links. Anything off, I dump it in VirusTotal—if it comes back bad, I block the sender and clean up the mess.
We use low-code playbooks—just drag and drop, and the system handles most of the aftermath.
Splunk SIEM: Chasing weird stuff
Once that’s done, I head into the SIEM dashboards, which basically pull logs from everywhere and help spot risky activity. I’ve made custom dashboards to catch things like brute-force login attempts—it’s one of the best ways to head off trouble early. The query language seems scary at first, but you get used to it.
Help desk tickets are next. Most are routine—access changes, account oddities. Sometimes you stumble on real incidents: sudden logins from out-of-state, weird new devices, login spikes. Those are fun—you dig in, try to figure out what’s actually going on.
Afternoons: Compliance and patching headaches
Afternoon rolls in and I’m onto the deep stuff: ISO 27001, vendor calls, chasing down app security problems, checking encryption and backups. It can feel like endless checklists, but that’s how you learn and level up fast.
For vulnerabilities, CrowdStrike keeps watch. I scan for outdated software, push updates, and hope users don’t hit “postpone.” If someone grabs some sketchy malware—say an Autodesk keygen—CrowdStrike tries to block it. If not, I block it manually.
End of the day, I sneak in some dashboard coding.
I’m a developer at heart, so this gives me a break from endless tickets and meetings. Plus, I use these dashboards to show management how many threats we’ve blocked—even if nothing awful happens. That’s the goal: be so good that disasters just don’t make it through.
So, that’s my day: phishing, logs, tickets, disagreement with the patch guy, meetings, dashboards. Not glamorous, but solid work. If this helps you picture the daily grind, glad to help. Good luck.
Let’s talk about Anne.
She shops a lot on www.shoppingcart.com—saves her email, address, credit card info, you know, normal stuff. All her details are stored there for easy checkouts.
One day Anne gets an email: “Congrats! You’ve won a discount voucher from shoppingcart.com.” Looks legit. She just needs to log in. She does… and the next thing she knows, a good chunk of cash is gone from her account.
What happened? That email was a scam. Somebody tricked her and broke into her shoppingcart.com account—a straight-up cyber attack. The person pulling the strings? A hacker.
Could Anne have stopped it? Definitely. Cyber security’s about guarding your data, devices, and whatever else you care about from people who want to mess with them. It’s not one magic tool—it’s habits and a toolkit based on what you’re trying to protect and who might come for it.
Here are the common attacks Anne could run into.
Malware—like trojans, adware, spyware. If she’d clicked on a sketchy attachment, she could have installed a virus without even knowing.
Phishing—the trick that got her here. Hackers send fake emails to steal passwords or install malware. Looks real, but it’s bait.
Man-in-the-middle attacks—here, an attacker wedges themselves between Anne’s device and the website, hijacks her IP, and silently snoops on her info. Think sketchy Wi-Fi or after malware is already on her system.
Password attacks—hackers guess or brute-force their way in, trying common passwords over and over until they get lucky.
After her disaster, Anne got her act together.
She set up a firewall—a digital bouncer that decides what data gets in or out. There are software and hardware versions.
She started using honeypots—fake servers designed to waste hackers’ time, keeping her real stuff safe.
She switched to strong, unique passwords, grabbed antivirus software, and started deleting shady emails without opening them. Smart moves.
It’s not just about one person, either.
Big companies and public agencies get hit, sometimes for money, sometimes for sabotage.
Major targets face things like APTs (Advanced Persistent Threats): attackers sneak in and quietly steal data for months or years.
Denial-of-service (DoS) and DDoS attacks? Hackers flood a network with junk traffic to shut down the real business. A DDoS just means lots of compromised devices are in on it.
SQL injection? Hackers mess with a site’s database to steal or change what they want.
Threats keep growing, which is why we need people who can spot and block them.
That’s really what a cyber security career is—it’s outsmarting the bad folks. If you love the chase, think about ethical hacking—find weak spots and fix them before real attackers do.
Or maybe you want to design the big picture as a security architect, or be the top dog: Chief Information Security Officer (CISO).
Quick quiz:
In which attack does a hacker hijack the client’s IP address? Is it A) DDoS, B) man-in-the-middle, C) phishing, or D) password attack? Drop your answer below—three winners get Amazon vouchers.
Cyber attacks aren’t slowing down, and with digital life busier every year, companies need security pros more than ever. If you’re looking at this field, you’re not just running after a trending job—it pays well, too.
So don’t just sit there. Get a certification (check out Simply Learn if you want) and start your journey. If this helped, like, subscribe, or follow to keep up with new tech stuff. Thanks for reading, and stay secure out there.

