CSO Online asked practitioners what hiring executives should actually look for in a security leader. Michael Hasse of Itwerx was one of them, on a problem he describes as close to unsolvable.
The over-reliance on certificates
The pattern is companies leaning on certifications at the cost of deep field experience.
“This leads to cybersecurity ‘experts’ who can regurgitate answers to pass tests but don’t actually have a real understanding of what they’re doing. It’s like somebody who’s driven their Honda Civic to work every day for a while with no accidents and thinks they’re a great driver, with no concept of what it takes to drive a big rig, or a Formula One car, or a train.”
The analogy carries the argument. A certificate demonstrates that somebody has covered a syllabus. It says nothing about whether they have been in the room when something went badly wrong, which is the only place certain kinds of judgement get built.
This matters for smaller organisations too, and not only when hiring. It is the same question to put to any security vendor or consultant: what have you actually dealt with, as opposed to what have you passed.
Read the full article at CSO Online.
Itwerx Corp is a service-disabled veteran-owned small business providing IT services across Seattle, Bellevue, Everett and Snohomish County. This is the kind of thing our cybersecurity work deals with – talk to us about yours.

