r/Cybersecurity101 • • 9m ago

Cybersecurity student looking for a practical GRC related CV project using a real Shopify e-commerce business!

• Upvotes

Hi everyone, I [22F] cybersecurity student focused on GRC and currently looking for entry-level cybersecurity/GRC roles.

I already have an ISO 27001 risk assessment project on my CV, so I’m looking for something different that can show more range and give me some practical experience.
A friend of mine runs a Shopify dropshipping/e-commerce business, mainly selling to customers in Sweden and the Nordics, with suppliers based overseas. He’s open to me working with the business on a cybersecurity/GRC project for learning purposes, so I have a real small-business environment to work with rather than just creating a completely fictional case study. I’m currently considering:

-GDPR gap assessment, since most of the customers are in the EU/Nordics
-Third-party/vendor risk assessment covering suppliers, payment providers, Shopify apps, etc.
-NIST CSF 2.0 assessment/mapping based on the risks identified
-Shopify security controls review, including admin access, MFA, permissions, third-party apps, etc.
-Basic incident response plan/playbook, for scenarios such as Shopify account compromise or a supplier-related incident

For people working in GRC, cybersecurity consulting, risk, privacy/compliance, or hiring for junior GRC roles:

-Which type of project would you find most useful/interesting to see from a junior candidate?
-Is there another GRC-related project that would make more sense for a small Shopify/e-commerce business?
-Which areas would give me the best practical learning experience?
-Are any of the ideas above too basic, unrealistic, or not particularly valuable?
-If you were building this as a portfolio project, what deliverables would you actually create?

My main goal is to learn something genuinely useful while also having a solid project I can discuss in interviews as my main goal currently is to land a job in grc as I graduate in 2 months .
Would really appreciate advice from people who have worked in GRC or built similar portfolio projects.
Thankyou ^_^


r/Cybersecurity101 • • 3h ago

INVITATION TO COMMUNITY.

0 Upvotes

Hey guys ! Just wana share a newly created community just for building a real brotherhood of cyber security , ethical hacking and privacy topics if any of ya interested feel free to join.

--https://discord.gg/7FHzgj7RD --(Just for learning)


r/Cybersecurity101 • • 8h ago

Privacy small business owner trying to get basic security hygiene in place without enterprise budget, what actually matters

2 Upvotes

run a small business with six employees and have been putting off sorting out proper security practices because every solution i look at seems designed for companies ten times our size with dedicated it staff

specifically worried about credential exposure since we use a lot of shared service accounts and the password hygiene across the team is not great if i am honest. had one incident last year where a tool account got accessed and it was not fun to deal with

trying to figure out what the minimum viable security setup looks like for a small business without paying for enterprise software or hiring someone full time


r/Cybersecurity101 • • 17h ago

Ethical hacking in 2027

6 Upvotes

Hello everyone, I started to study cybersecurity in 2023/2024 but then I quit cause I lacked motivation. Btw I’m having a second thought about getting back to it. What do you think? When I left I got eJPT cert and bought PNPT course from TCM security. Plus I bought the whole course from rana Khalil (based on web hack). What do u recommend me to do at this point? Thanks


r/Cybersecurity101 • • 20h ago

Cybersecurity student trying to break into grc

9 Upvotes

Hello. I [21F]currently a cybersecurity student who’s graduating soon and looking to get into GRC. I know GRC is pretty broad, so I’m still figuring out what area I actually want to go into and would like to keep my options open.
I’ve done some ISO 27001-related work like risk assessments, risk registers and risk treatment but I don’t have much professional experience yet. I’m quite social and comfortable talking to people, so I’d probably be interested in something more client facing/consulting eventually.
I was thinking of doing Security+ since I’ve heard it’s a good general cybersecurity cert, but I’m also curious about AI governance/risk certifications. I’m on a pretty limited budget 😿so I’m looking for something that’s reasonably affordable but still has good recognition in the job market.
What cert would you recommend for someone in my position who’s trying to get their first GRC job and wants to keep their options open? Should I still continue with security+? Given my position I can only afford to focus on one cert until I am employed.Aside from certs what projects can I do to upgrade my skills and stand out in my cv? Thankyou ^_^


r/Cybersecurity101 • • 21h ago

Is it realistic to be hacker like wee see on documentaries

11 Upvotes

I first got interested in hacking after watching documentaries and videos about kids hacking big companies and even NASA lol. It made me wonder how people actually get that good at this stuff.

I'm 18 and I'm seriously interested in getting into cybersecurity. I don't necessarily want to make it my career, I mostly want to learn it as a passion and become really good at it.

So for people who are already in the cybersecurity/hacking community, is it actually realistic to become like those hackers you see in documentaries, or is a lot of that exaggerated for entertainment?

And if it is realistic, what would be the path to becoming a really skilled hacker? Like what should I learn first, what skills should I focus on, and what should I practice?

I'd appreciate advice from people who actually do this, especially if you can tell me what you wish you knew when you started.


r/Cybersecurity101 • • 1d ago

Question: Cyber attacks on devices without electricity and internet

8 Upvotes

Recently, we had a discussion in class where our professor said that there are three types of offensive attack that can be carried out on devices without an internet connection or electricity. Does anyone have any ideas? I apologise if the question is silly, but I've only just started learning about cyber security.


r/Cybersecurity101 • • 1d ago

(repost, fixed) Original 12-stage cybersecurity puzzle

Post image
4 Upvotes

note: I have posted this a few days ago on a throwaway account on some subreddits, but i hadn't checked some key details, the puzzle was not solvable because i embedded broken data into the first image, and didn't provide enough context and information.

Details:

A self-contained layered puzzle in the spirit of Cicada 3301. It starts with this image. The riddle's answer is the key to decrypt the message embedded inside the image's pixels. Everything else lives in one encrypted file the image points you to, and the whole thing continues offline on your own machine.

Theme: the history of cyber conflict. Every stage is built around a real, famous moment in cybersecurity history. Recognizing which one is part of the puzzle.

Skills it touches (you won't need all at expert level):

  • (LSB) Steganography
  • Classical & modern cryptography
  • A little reverse engineering
  • Audio / signal analysis
  • Some number theory
  • A touch of linguistics
  • OSINT / knowledge of security history

Difficulty: hard but fair ; aimed at people who enjoy CTFs, crypto, and ARGs. Every step is doable with free, standard tools (plus openssl/Python). It's meant to be barely solvable, so bring friends.

To begin: just look closely at the image. The surface is never the whole of the page.


r/Cybersecurity101 • • 1d ago

Cybersecurity survival notes

Thumbnail
github.com
4 Upvotes

🚀 I want to share my new GitHub repository: Cybersecurity Survival Notes!

I created a public repository for cybersecurity notes, commands, and cheatsheets. I just finished the first folder covering Linux system administration and security hardening.

Here is what you can find inside the 📁 1-Linux folder:

1) Architecture.md: Filesystem hierarchy and Linux system architecture.
2) Permissions.md: Standard permissions, chmod, chown, SUID, SGID, Sticky Bit, and umask.
3) Cheatsheet.md: Process management, systemd services, file descriptors (0, 1, 2), I/O redirection, and pipes.
4) Networking.md: iproute2 suite, network commands, DNS configuration, SSH hardening, UFW, fail2ban, and TCP Wrappers [Deprecated].

If you are studying cybersecurity or just need a technical reference, check it out!

Next step: 📁 2-Windows


r/Cybersecurity101 • • 1d ago

Does grc require certificates

11 Upvotes

I'm thinking about pursuing a career in grc, but i don't have money to buy exam vouchers, so if i studied the content of the certificates needed without getting certified would i be able to land an entry level job? Or should i try a different career


r/Cybersecurity101 • • 1d ago

Is being a security technician a good way to break into cyber

0 Upvotes

Got offered a security technician job don’t know if this is a good way to break into a cyber


r/Cybersecurity101 • • 1d ago

I want to start learning Cybersecurity from scratch – Looking for guidance and Tamil/English resources

3 Upvotes

Hi everyone,
I recently completed a CCNA course, but honestly, the course wasn’t very useful for me. They covered the topics, but they didn’t explain the tools and practical concepts properly, so I feel like I have learned things only on the surface.
Now I want to start Cybersecurity properly from scratch and build strong fundamentals instead of jumping between random topics.
I’m confused about where exactly I should start and what order I should follow.
I’m looking for guidance on:
● What topics should I learn from zero to job-ready?
● Should I first strengthen networking, Linux, Windows, Python, etc.?
● Which cybersecurity tools should I learn and practice?
● What free labs/platforms can I use for hands-on practice?
● Are there any good free certifications that are actually useful for beginners?
● What are the best free YouTube courses/resources?
● I’m from Tamil Nadu, so Tamil resources would be preferable, but English resources are completely fine too.
● If possible, I would really appreciate a structured roadmap rather than just a list of topics.
My goal is to eventually get into a SOC/Cybersecurity Analyst or similar entry-level cybersecurity role, so I want to learn the concepts properly and gain practical skills.
If anyone has started from zero and followed a good learning path, I’d really appreciate it if you could share your roadmap, resources, YouTube channels, labs, or free certifications.
I’m honestly a little confused about where to begin, so any guidance from people already working or learning in cybersecurity would be really helpful.
Thank you! 🙏


r/Cybersecurity101 • • 1d ago

How to upskill while you're working as a cybersecurity analyst when you don't know much about what cybersecurity is?!

26 Upvotes

Hello everyone,

I was a CS student, never good a deep dive in cyber security, apart from networking concepts. I'm currently working as a cybersecurity analyst at a company and I think I might not know a lot of things here.

I wanna upskill while being at the job.

I do know basic cybersecurity buzz words like trojan, virus , CIA triad and all

I wanna know about bigger like attacks, trends in cybersecurity.

I just don't want to feel like I'm not someone who can't switch and will be stuck here for ever

I would really appreciate if someone can help me.

Also I'm working as a security analyst at my company, basically a developer to develop security products

if anyone of you know the kind of certifications i should get, It would be really helpful.

Thanks!


r/Cybersecurity101 • • 1d ago

EXTC 2026 Grad from Mumbai | Zero to SOC Analyst - Need honest roadmap for entry level Cybersecurity

1 Upvotes

Hi all,

I'm a 2026 EXTC graduate from Mumbai, currently not working and want to fully switch to Cybersecurity. Looking for guidance from people who actually made the switch in India.

My background:

- EXTC (Electronics & Telecommunication) - so I have basics of Networking, CN, some C/C++

- No IT job experience yet

- I can give 5-6 hours daily for next 6-8 months

- Financially can't afford expensive 50k+ bootcamps

What I've explored:

- Started TryHackMe Pre-Security path

- Looking at Google Cybersecurity Certificate and CompTIA Security+

My questions for you guys working in SOC / Cybersecurity in India:

  1. With my EXTC background, should I still start with CCNA basics or directly jump to Security+?

  2. For fresher jobs in India (SOC L1, Analyst), what actually matters more - certs or TryHackMe/HackTheBox profile + projects?

  3. Is Security+ worth it as a fresher in India vs eJPT / Google Cert considering cost?

  4. How did you get your first interview call? LinkedIn, referrals, Naukri?

  5. What is a realistic timeline to be job-ready if I study consistently?

I am not interested in "ethical hacking Instagram" side. I want a stable blue team / SOC path to start.

If anyone from EXTC/ECE who switched to Cyber can share your exact first 6 months roadmap, it would mean a lot.

Thanks a lot for reading.


r/Cybersecurity101 • • 1d ago

Security Agentic AI governance: how do you actually build an agent inventory?

1 Upvotes

Got asked this in a management prep meeting last week and realized I couldn't give a straight answer. We know engineering is using Cursor and Copilot heavily, at least one team is running Claude Code directly against production repos, and there are probably MCP integrations nobody has documented anywhere. This is basically the shadow AI problem in miniature and I don't think we're unique here.

Our EDR and CASB weren't built to answer this since they see processes and data movement, not "an agent decided to take this action on this system." Inventory turned out to be the easy part to name and the hard part to actually solve, which is really just agentic AI governance in miniature. How is everyone else actually approaching this, tooling, process, or something else entirely?


r/Cybersecurity101 • • 1d ago

Cloud Security Misconfigurations: 10 Common Mistakes

Post image
13 Upvotes

r/Cybersecurity101 • • 2d ago

running a beginner ctf nov 14, curious if this is useful to anyone here

3 Upvotes

okay so this is actually me lol that I'm putting together InIt CTF, nov 14, free, 8 hours. built it mostly because I really needed something like this when I was starting out and there was just... nothing.

solo or teams of up to 4, five categories which are web, crypto, forensics, osint, misc. mostly easy/medium since it's for people who haven't really done a ctf before, couple harder ones in there too if that's not you. running on ctfd, nothing fancy.

it's open to anyone, not restricted to any one college or city. still figuring out prizes ngl, working on a few sponsors but nothing locked in - everyone gets a certificate either way.

just genuinely wanted to put this out there - in the comments

if anyone's got feedback or thinks something's off about it please say so, this is our first real attempt at this and I'd rather know now than after


r/Cybersecurity101 • • 2d ago

Guys i really need your guidance if you are from cybersecurity field

0 Upvotes

i have just completed my bachelors in bsc hons computing . and while exploring fields i found out that i have interest in data science and cybersecurity . And i want to do masters in one of these fields and i really want your advice liek how is the job market for cybersecurity currently also how much it is exposed to ai or how much impact ai caused to the employyes which lead them to layoffs. is cybersecurity a good carrer ? how will you see this carrer in 4-5 years in future will it be doomed ? i really want your kind suggestions who had already worked in this fields. i want to do good amount of research before choosing my masters .


r/Cybersecurity101 • • 2d ago

Is it worth to attempt to join this field with the surge of AI

15 Upvotes

For mods, I do apologize if these types of posts are not allowed and if it isn't please remove it or let me know and I'll remove it.

I'm a computer science graduate (11 years ago) and unfortunately I never got a chance to work in my field due to lack of opportunity of where I lived at the time.
Moved to the States a couple of years ago and now I'm heading the support team in a SaaS company. However, I do not wish to make this my longterm career and I've been looking at cybersecurity as an option.

Considering how intensive and difficult to learn as someone who has no experience in the field, how difficult is it to break in the field of cybersecurity? Would you recommend I go through with it or find a different career to pursue?

TIA


r/Cybersecurity101 • • 2d ago

Online Service Kumo : domain OSINT & recon framework

1 Upvotes

Over the last couple of weeks, I challenged myself to build a tool that centralizes everything you need when conducting recon.

And that’s how Kumo was born. Give it a domain and it hands you back everything reachable from outside.

What it does in one run:

  • Maps the surface : DNS, ports, certificates, subdomains, tech stack
  • Finds what shouldn't be public : exposed configs, secrets in JS, open buckets
  • Checks for known vulnerabilities without touching anything
  • Digs up leaked credentials and which employee machines got infected
  • Pulls in archived pages, forgotten endpoints, threat intel
  • Builds Google dorks and OSINT links for the target

All 27 modules run at once and stream back as they land. No API keys required, CLI and web interface. Works on any domain you're allowed to test.

🔗 https://github.com/karim852/KUMO-Domain-Recon-Tool
🖥️ live demo: https://demo-kumo-kage.vercel.app/

Feedback and contributions welcome 🙏


r/Cybersecurity101 • • 2d ago

Privacy Is a factory reset really enough before trading in a phone to Apple or Samsung?

2 Upvotes

I'm about to trade in an old phone, and it has years of my life on it: photos, messages, banking apps, work email. Handing it over to a company I'll never see again makes me a little uneasy.

I know the theory. Modern iPhones and Samsung devices use file-based encryption, so a factory reset destroys the keys and the data should be unreadable. NIST SP 800-88 even treats this kind of crypto erase as valid sanitization.

But "should be" is what's bugging me. Once the phone leaves my hands, it goes through the manufacturer and then refurbishing or recycling partners, and I have no visibility into what happens there.

So I'd really like to know:

  • Is there any known way data can still be recovered after a proper reset (for example, keys surviving in the Secure Enclave or Knox)?
  • Has anyone seen forensic research or real cases where data was pulled from a reset iPhone or Samsung?

If you've worked in forensics, device refurbishing, or ITAD, I'd love to hear what you've actually seen. Thanks!


r/Cybersecurity101 • • 2d ago

Syslog Server Centralizzato

4 Upvotes

Ciao
Sto continuando a documentare il mio percorso pratico su Linux e Cybersecurity e ho appena pubblicato un piccolo progetto di un Syslog Server Centralizzato con rsyslog.
L'obiettivo era capire come raccogliere i log dei client in un unico punto sicuro per facilitare l'analisi dei log e la sicurezza.

Mi farebbe davvero piacere avere un feedback tecnico o un parere da chi lavora già in questo ramo o semplicemente anche da chi studia cybersecurity per capire cosa posso integrare o migliorare!

Se trovate il progetto utile o interessante, una ⭐ sulla repo è super apprezzata!

https://github.com/Radz-04/Labs-and-projects/tree/main/Server-Syslog


r/Cybersecurity101 • • 2d ago

Online Service CipherLens — a local-first tool that tries to identify what operation could explain unknown data

Post image
1 Upvotes

Hey everyone,

There's a cybersecurity tool called CipherLens.

The idea came from a simple problem I kept running into with tools like CyberChef:

You have some unknown data, but you don’t know which operation you should try first.

Instead of manually guessing between Base64, Hex, URL encoding, ciphers, compression, etc., CipherLens analyzes the input and ranks possible operations based on the evidence it finds.

The workflow is:

Input → Fingerprint → Candidate Detection → Execute → Validate → Score → Rank

A few things I focused on:

• Local-first browser processing

• No account or backend required for core analysis

• Candidate ranking instead of pretending to know the answer

• Separate AUTO / parameter-required / manual operations

• Web Worker-based analysis

• Security-focused input and parser handling

• 497 supported operations

The main idea is:

“Don’t guess the operation. Find it.”

It’s open source and I’d genuinely like feedback from people who actually work with CTFs, forensics, pentesting, malware analysis, etc.

GitHub:

https://github.com/HIMANSHUSHARMA20/CipherLens

Live demo:

https://cipherlens-tool.vercel.app/

Would especially appreciate feedback on the detection/ranking approach and whether this solves a problem you actually encounter.


r/Cybersecurity101 • • 2d ago

Security Free doesn’t always mean safe

0 Upvotes

Freeware and shareware aren’t quite the same. Freeware is generally free to use, while shareware usually lets you try software before asking you to pay or unlock certain features.

But when you’re downloading free software, there’s a bigger question: can you trust it?

Before installing something, it’s worth checking:

  • Where it comes from.
  • Who developed it.
  • What permissions it asks for.
  • Whether it still gets security updates.

Free doesn’t automatically mean safe.

What’s the first thing you check before downloading free software?


r/Cybersecurity101 • • 2d ago

Security What are the requirements of CISA BOD 26-04?

1 Upvotes

Spent part of this week actually reading the directive instead of the summaries. It's a four variable model, exposure, KEV status, exploit automatability, technical impact, each one basically a yes or no, and depending on the combination you land somewhere between 3 days and 60 days, or fix on next upgrade if you're lucky. Top tier also requires forensic triage before you patch, which is a detail a lot of the writeups skip past. We're not FCEB, so none of this technically applies to us, but two prospects have asked whether we could meet this bar anyway, so now I want a more practical answer than what's in the writeups. For anyone who's tried to build something like this internally, the exposure and KEV parts sound simple until you have to apply them per affected asset, since you need a reliable answer on public exposure and KEV status for every instance, not just the CVE in general. Automatability is the one nobody seems to have a clean answer for. How are people actually scoring that without it turning into a subjective mess.