How to Learn Identity & Access Management? - UnixGuy Cyber Security Career
0m 0s
The discussion emphasizes the crucial role of Identity and Access Management (IAM) in modern cybersecurity, particularly as organizations migrate to the cloud. IAM ensures that only authorized individuals access specific resources, monitors their behavior, and manages access lifecycles. A key insight is that attackers often "log in" using stolen credentials rather than exploiting network vulnerabilities, making robust IAM foundational to zero-trust security models. Despite high demand and lucrative job opportunities in IAM, there is a notable skills gap and a shortage of beginner-friendly training. The expert recommends starting with free foundational resources and vendor-neutral certifications to understand core principles like least privilege and segregation of duties. Practical experience can be gained through labs using tools like Microsoft Entra or open-source platforms. Finally, while AI will automate repetitive tasks, it is seen as a tool that will create new opportunities rather than replace cybersecurity professionals, who remain essential for strategic decision-making and architecture.
Understanding Why Identity and Access Management is Crucial
Hackers don't break in their login.
If you're not doing identity correctly, the concept of zero trust falls apart.
We are moving our workloads on the cloud, our resources on the cloud, even identities are on the cloud.
I had around 24 or 28 Microsoft certification whenever the system admin, you name it, and I have it for identity access management.
If you're not required to access certain resources, I will not give you access.
Do they still need those resources and are they behaving correctly?
Speaker 2
Someone sent me a job identity and access management experience.
That job is 200 K fishing.
Speaker 1
Bombing, cleavage, escalation, golden ticket and pash the hash.
Speaker 2
Most important question is will AI replace cybersecurity professionals?
When people think of cybersecurity, they don't think about identity and access management.
Instead, they think about penetration testing, hacking, and being a SoC analyst.
However, one of the highest area of growth in cybersecurity is actually identity and access management.
However, there aren't a lot of beginner friendly identity and access management training courses for beginners.
So to solve this problem, I'm interviewing someone with over 25 years of experience in cybersecurity.
He held titles such as Chief Information Security officer, he was the chief security advisor at Microsoft, he worked in organizations like EY and KPMG, and he even authored 5 cybersecurity books.
Welcome to the podcast Abuzz.
Thank you for joining us.
Thank you for start with like a fire rapid question.
Sure.
What is identity and access management, especially when it comes to being under the umbrella of cybersecurity?
Speaker 1
Absolutely.
So ideality access management is one of the core discipline of cybersecurity which is not really well known, but good.
You brought up the point because we see a huge skill gap in that area and it is one of the fastest growing discipline within cybersecurity.
To give you overview what is what identity access management in a nutshell is about making sure that who has access to what resources, Do they still need those resources and are they behaving correctly?
For example, in other words, who you are, what access do you have, how long you need that access and are you behaving normally or or is there anything this unforcing things you are doing with your identity access management?
So this is a discipline which talks about everything.
And traditionally if you know what we have been focused on, cybersecurity has been focused mostly on securing the devices and the network.
But now the things are moving into the cloud.
We are moving our workloads on the cloud, our resources on the cloud, our even identities are on the cloud as well, including the API and certificates.
So cloud is becoming the core infrastructure today and identity is the one which ties everything.
It becomes the central of managing everything on the cloud because simply is put together.
Hackers don't break in, they login.
They login by stealing the credentials, identifying the misuse or a compromise password and they get into your environment.
So if you're not doing identity correctly, the concept of zero trust falls apart and all the investment, what you have within your organizations, they just simply crumble around it.
So that's in the.
Simply put, this is what all about, giving the right access to the right people on how long they need and how they behaving normally.
Speaker 2
Yeah, that's that's actually really nice way of putting it.
When you said hackers don't break into companies and all I could think of, well, instead of a hacker trying to destroy the network and break everything in the network, all they do is they turn and steal a password of 1 user and that user when they connect their laptop to to the company or to the Internet.
Now it really is how we manage their identity.
How do we manage their access of the hacker can get their access?
Well, how much can they get to if someone works in IT, do they also have access to financial systems or do they not?
And I guess that's really the beauty and I guess art of identity and access management.
Tracing Identity Management's Evolution from IT to Cybersecurity
What what I really want to understand, Abbas, is because traditionally, let's say password management, like the very basic form of identity and access management, this used to be the job of the IT engineer, or we call them sometimes infrastructure engineers or Windows engineers.
However, more and more I've been seeing the role of an identity and access management professional fall under the cybersecurity team or the broader cybersecurity function.
Do you see that this is something that's changing?
Do you feel like it fits better under the infrastructure team or cybersecurity team?
Speaker 1
Yeah.
If you look at historically the managing of infrastructure was very easy and the very first protocol which came up or dissipate came out is a lightweight directory protocol, LDAP, what we used to call it.
I started my career with a novel network that was the first operating system which called it a network centric operating system where you are now creating an access for somebody who needs to access a certain resources and it was simple username and a password which are stored in a directory in a simple word LDAP.
It used to be novel then Microsoft Active Directory came up.
The name is still relevant right?
Active Directory, you have a directory which has a username which have a password and there are the sources assigned to it.
It was as simple and there was no discipline called cybersecurity or information security.
I started my career as an IT professional.
My first diploma apart from doing my degree in accounting and commerce, I did a diploma in IT and my and my diploma was system management.
There was nothing called ITEL security.
But the world moved on.
We we started creating a network LAN van man all those concepts came into place wide area network and metropolitan area network and the Internet came in.
So our access has started growing from an individual small directory into a single office to a multi office environment.
And that's where the complication started.
It used to be managed by ITII was the one IT administrator in my very beginning role.
I was the one person who will create the username and password and reset the password and give them access to our our employee and the resources.
But later on after Internet started things started moving.
VPN came into place and created more complex.
Then we started segregating.
You are a normal user, you don't have a privilege because now if you have access, extra rights and permission and entitlement, you can harm the network and have access to a lot of data which you are not entitled to, which is the core principle of identity access management.
So we started creating more security around the identity that you can have only access based on need to, no need to do basis, period.
If you are not required to access certain resources, I will not give you access.
So that's where we start building the work of what we call it the life cycle, lever movers and joiner.
That's a concept came into place.
That's the first step in identity security.
Once you have the life cycle, once you join, you get an access.
If you move, we change your access.
If you leave, we remove your access.
That's where security started baking in into the whole IM process.
And then more and more disciplinary discipline of a job started coming in because of the company's large, for example, a large bank or a telecom company where they have 100 thousands of employee, it's not possible for IT to maintain it and we want to segregate as well.
Let IT manage the infrastructure, let somebody in security have a segregation of duty.
IT would give an access but somebody would review it or somebody will own it as a.
So we started having something called a business user.
A business user will define who, what level of access and what application individual will have it.
In the old days it used to be 1 system, everyone access the same system.
But today we have thousands of application in the company and each require a separate set of application and you as an individual will not require to access all the application in the company.
So somebody has to go on you that OK, this is your access, this is what you're going to go and have access it and security will go and review it.
A maker checker concept came into place, a segregation and duty concept came into place.
That's where the security started coming into the whole discipline.
Speaker 2
In this yeah, that's that's fascinating.
I think the most important questions here is are you a novel Certified system engineer?
Still I.
Speaker 1
Am I used to be I was the one of the first CNE certified no engineer and then became the MCSE in the those days of.
Speaker 2
The Microsoft certifications.
Yeah, I.
Speaker 1
I had around 24 or 28 Microsoft certification when I was a system admin.
You name it and I.
Speaker 2
Have it people used to recommend them.
It was funny you say on the technologies you worked at.
I worked at we were the on team Microsoft.
I worked at some Microsystems and our product was Sunlight.
Speaker 1
Certified as well.
Speaker 2
There you go.
So there was actually 2 product one.
It's an implementation of open Eldab.
It's called Sun 1 directories. the US Army actually really loved using it and there wasn't a version called Solaris trusted extensions as well.
Practical Steps to Begin Your Identity Management Career
But I really like you mentioned the concept, you just mentioned it casually, which is segregation of duties.
That is not a new.
This is one of the sort of, to me, cybersecurity one or one one of the fundamental concepts.
And I guess then this ties back into another important question that I get asked a lot.
Because what happens is, let's say someone is a student or they're professional, they go on a job search, they search for cybersecurity jobs.
And actually, in fact, today someone sent me a screenshot of a job that's asking for identity and access management experience.
That job is 200 K.
And he's like, well, how do I even get that type of knowledge?
Because the job was asking for experience in a tool called Sale Point, which does what you just alluded to, mover joiner, but also things like cyber ark and like privileged access management, all these enterprise level tools.
Now my question and, and the big dilemma here is if someone is inspired or you said and OK, they want to work in cybersecurity identity and access management, huge part.
How should they go on about learning this concept and potentially start their career in identity?
And is it even possible that they start their career in identity?
Speaker 1
Yeah, absolutely, absolutely.
You have, you have a very valid point.
All these kind of tools you mentioned Cell Point, Okta, Microsoft Intra Silver, Ford, the company which I've worked for, these are all very powerful and enterprise ready tools, but not easily or freely.
Not everything is easily and freely available because it's a very specific tool and some of the large company have a very big implementation of that through the way.
I would suggest anyone who is thinking of starting their career and want to target these kind of job opportunities, start with the foundation knowledge.
So I have a portal, personal portal called abbasworld.com, ABBASWRLD where I have listed all the basic foundation knowledge which you can gain it from identity access management.
I have a link of all the free training available.
So start with those free training, fundamental knowledge, what is identity access management?
What is identity life cycle management?
Start with that foundation knowledge.
You understand the concept of privilege access management, identity management, governance.
There are some vendor neutral certification as well in the market which you never used to be around.
Speaker 2
Yeah, that's new.
I saw you had one.
That's why I'm asking.
Speaker 1
I have quite a.
Speaker 2
Fairly new, I haven't done them myself but I'm really.
Speaker 1
So one of the my favorite one.
I've done quite a few of them which are vendor neutral.
Irrespective of which product you would, there is something called Pro Certified Identity Professional.
It is by organization called ID Pro, which is one of the upcoming and very, very famous certification.
You will see a lot of more people coming in and there is a chapter as well.
In Melbourne you can join the ID Pro Victoria chapter and we catch up regularly and talk about identity and everything.
So you can start with those and the material is completely free.
Go to ID Pro website and they have something called Program of Knowledge, Body of Knowledge which you can read through and gain the foundation knowledge.
Heaps of video available on that.
As when I have a training material, feel free to reach out to me.
I would give the free training material to anyone who is interested in learning.
Then there is a organization called Identity and Access Management Institute.
They also have a lot of vendor util certification such as certified identity access manager, certified Identity governance export.
There were specific disciplines in identity access management which you can learn it and get qualified as well training material easily available.
You can join a membership and done that.
So start with those foundations and the principal knowledge about the whole discipline then comes in the product.
Now if you pick up the product, for example, one of the most commonly used identity access management is Microsoft Ventra.
And thanks to Microsoft Generosity, they have enabled this training completely free on on the airport.
Speaker 2
On Microsoft.
Speaker 1
Learn.microsoft.com you will find heaps of training material about the fundamental of identity access management and also and DRY as well.
Similarly, Octa has it similarly Auth 0 for those who are developers, they can learn that the concept of zero trust freely available all the training material.
So develop those things and create your own lab.
And there is a key clock which is an open source identity access management as well which you can gives you a good fundamental.
You can create your own single sign on federation environment in your own lab and get the free access or developer access to all those tools such as Octa such as Microsoft and whatnot and start getting hands on experience because this will help you more of a practical experience then first once you finish the theoretical part of it.
Once you do that, then learn from the threat and attack perspective as well, which is also very important because most of the attack which I have seen in the blast four or five years are all identity based attack.
Speaker 2
So interesting.
Yeah, we're.
Speaker 1
Talking about lateral movement, yeah again after identity compromise the phishing identity based attack, MFM bombing identity based attack, escalation with escalation golden ticket as and pass the hash all there are heaps of attack which have been very successful in last few years, which we never used to see before because attackers don't break in they log in going back to the same concept to understand those fundamental from the threat point of view as well, which would give you knowledge, OK,
these are the things happening.
And how do you secure this identity by having MFA by having a single sign on a fishing resistance MFA.
And there are many, many technologies or concept like identity threat detection, identity security, posture management.
So learn those fundamental tool will come into a place once you get into a job and see what product that company is using for access management, for governance and for security.
You can master those tools once you start in that job because these tools are not freely available.
Examples silver Ford or sale point enterprise tools, you cannot do it.
They have a basic training available on the website which will set up for the interview process and you'll get into it.
But having your fundamental knowledge very clear, which will set you for the success you get into the company and move around, navigate.
Even if you get a job as a sock analyst, go and talk to identity access management team.
Tell them I'm interested in discipline.
Do you have opportunity for me to shadow or learn along along the pathway and then jump your job from soccer allies or a Pentasta to specific into identity product per SE?
It pays you well then a lot of opportunities in the market as you said.
Speaker 2
Wow, yeah, those are so many fantastic resources.
Actually, I'll leave links to everything in the description of the episode.
I really like that.
It seems that what what you're really recommending is like, learn the fundamentals, right?
So by fundamentals we mean fundamentals of identity.
So like principle of least privilege, separation, life cycle.
Speaker 1
Management of the.
Speaker 2
User exactly those principles, I guess once you learn them and then the tool itself that the company is using to implement those principles is something you learn.
No one can purchase $200,000 sale point implementation and it's just not feasible.
But also honestly it's not needed.
We all had to learn that on the job.
I think the challenge is always if someone is brand new with no IT background, it can be a bit intimidating, intimidating to go somewhere like Okta and sign up as a developer and start that that can be there.
There is a bit of a gap, but I really like, you know, if you get a job as a help desk, IT help desk or if you get a job as a SoC analyst, that's a perfect opportunity to learn something like identity.
Absolutely.
I believe, like you said, there's so much money because we simply can't find people.
And as organizations get more and more complicated and bigger, there is a heavy reliance on identity solution.
Actually in GRC Mastery we have a module called Identity and we teach exactly that.
So the principles and we have examples on that practicals, but like you said when it comes to enterprise level tools, this is something that we all have to learn.
Speaker 1
Tools can be learned.
Tools are easy to learn.
You have the basic knowledge.
Speaker 2
And that's my point.
I've never seen a tool that that's it's literally just a web interface and click next and data.
It doesn't need skill, but we don't have access to that.
So I can't put it in my resume and say, you know, I'm an expert sale point without having had that experience.
Speaker 1
But you can always say that I'm a certified identity governance expert.
Now you've done the whole process, you know, the entire life cycle of governance.
Leave a mover, joiner, segregation of duty concepts and whatnot here.
Yeah.
Speaker 2
And when we interview candidates, I don't see many candidates with that knowledge.
In fact, they've never heard of these concepts before.
So you will make you really easily stand out.
AI's Transformative Impact and Risks in Cybersecurity
So about the most important question is, will AI replace cybersecurity professionals?
Speaker 1
The most asked questions in any podcast, I say yeah, absolutely.
I would say no, AI is not going to replace the job but AI will replace some of the common task which we do such as repetitive task such as analysing the large logs such as reviewing certain large documentation and getting things out of it.
So definitely those kind of repetitive and mandate task will be automated using AI but it is not going to replace human who is in the picture because definitely we need human for strategic thinking, we need human for making a decision on the architecture.
You need human for reasoning purpose.
So AI is going to create more jobs actually for the security rather than taking taking the things.
But I always say there are there are two opportunities.
Either you work with AI or you work for AI.
So Start learning the basic concept of AI and be be ready because every job you're going to go this year or since last year, last couple of years, everybody expects you to have the fundamental of knowledge of AI and how you can be more productive and more efficient in leveraging these tools.
But not completely dependent on on that as well.
Because in the exams in your university or in the interview, you will not have access to this ChatGPT kind of a tool for answering that.
So basically, you have to have the fundamental knowledge.
You should know how to review the basic logs and to give an example, my son who has recently graduated and he has been preparing for a lot of interview and this is the good example.
I want everyone to listen to it.
One of the very interesting job interview he he had is for the soccer analyst because that's what he loves to do thread hunting and and hacking and whatnot.
So he was asked for an interview.
They it's going to be a practical interview online and the way interview was scheduled is they will send him a raw log file 5 minutes before the interview call immediately.
He has to jump on the call as soon as he received the file and share the screen and walk through what this log has and and tell everything about what's happening from an attack point of view.
Imagine if somebody has to work, they will have a SIM tool like a Splunk and Sentinel and many other thing and they can analyze everything in the tool.
It's a very fancy tool, everything whole map will be there in front of them.
But if you don't know how to read the raw log and don't have the fundamental knowledge tool is just an AD to make you more efficient.
So because he has done a lot of hands on training and I've been grooming him and mentoring him on how to analyze the role log.
He had prepared himself well.
And on the on the interview time when he received the log file, he was able to pinpoint this was the flow of attack, this was identity compromise, This was the attacker IP address.
This was the this was the IP address of the target.
This is the data which was targeted.
This is the folder which was compromised.
He was able to pinpoint all the things.
And he got that job and and then he asked the question as well, will I be allowed to use automated tools such as ChatGPT or a copilot in the job?
He said yes you will have it on the job but you wanted to understand.
Do you understand if what if those tools are not available?
So yes AI will help you be more efficient but don't be dependent on them.
Have your fundamental knowledge, have your hands on skill, be practical enough in your work and AI will help you do that 10 hour job in one hour.
That's what it is there for.
But you need to learn both way normal way as well as how to be efficient leveraging AI as well.
Exactly.
Speaker 2
I really love this example and it also demonstrates something that I've experienced myself.
When you interview a candidate, it takes all of five seconds to know if the candidate know what they're doing or if they don't know what they're doing.
He did practical hands on training, which you preach and I recommend as well.
It doesn't take much time for you to be able to read a log and know it's either you know or you don't.
If you've never seen a log in your life before, you have.
We will have no idea, and the person interviewing you will discover that really quickly.
You're absolutely right.
I will help with some jobs.
However, in the last few months in nearly 90% of the work I have been doing was because of AII offer consulting to a company and all they tell me is, well, we've got these departments that have using AI and from a cybersecurity perspective, it's been a disaster.
We have personal data going into AI.
We have no idea what data is going in there.
Then we have the risk of hallucination.
They've used a company that shall not be named.
They created a chat bot with AI, an agent and the answers that the agent was giving to customers, some of it was rude.
So and that can cause a huge issue for some organizations.
So there is a lot of risk that comes from using AI, which has created more jobs, especially at least for me in the government thing and the GIC world, but also in, in like in my friends in Absec application security.
All these companies are quote UN quote leveraging AI so they can program fast.
What happens is there is more bugs in the code than before.
The secure code review is suddenly hot again and we need more people because AI is spitting out code that looks good, but it's not good.
And it's, to me, it's creating more work.
But also it's like you've been, you've been in the tech world for a long time, right?
Like there was a time when we didn't have a Seam or a Splunk, but we used to have a manual server where we put all the logs in that server.
So we used to do it manual and then we have a tool and then we, we suddenly can do more stuff.
So I believe AI is just an opportunity so we can have more free time to do even more stuff.
And people think cybersecurity professionals would just sit there.
We do a certain number of tasks and then AI is just going to take those tasks.
But the reality, usually we don't have time to finish all the tasks that we have, so now at least we'll have room to breathe.
Speaker 1
I want to highlight A blog which I have recently published around a couple of months back on how AI will transform the security operation center.
And you can you can replace security operation center with any discipline of AI.
So in in to highlight a few things in my blog which I have and I will share the link with you so you can put it in your description is the future organizations of a security of a CISO org.
You will have AI agent and in the and the level 0 or level 1, which will do all the repetitive in the common task.
Level 2 will replace with somebody, we call it the agent operator, a human, a human who knows how to operate these agentic AI operators.
The Level 3 will be somebody who knows how to customize these agents, who knows how to integrate them like APIs and whatnot.
They are the people who will who will be required in the SoC to manage and have a connectivity and security and identity of those agents.
And then you will have your CSO on the top of it.
So level 0 to level Level 3 is completely going to transform because agentic AI will do all the common task in an automated way.
You will have agents for compliance, you will have agent for governance, agent for threat hunting, agent for pen testing, agent for identity and whatnot.
So agent will have a kind of a human.
They will have an employee ID in a way so that you can go on it in a proper manner as well.
So human and non human identity.
Insights into the CISO Role and Practical Career Guidance
Agent yeah.
And this reminds me of in like 2007.
I was Unix engineer, one of the banks and instead of agents I had scripts.
I had script doing a lot of the.
Speaker 1
Work.
Speaker 2
And, and I wrote Pearl scripts and because they are used to monitor servers, so they used to basically generate a, a PDF report for me.
So in the morning I just click on script and I read the report and was doing all the work for me.
You said that with Caesar and I wanna hone in on that.
So Caesar or CISAR stands for Chief Information Security Officer.
You've held that title, yes.
So for those of us who are interested to know, what does a chief information security officer actually do?
A great.
Speaker 1
Question.
There are many types of CISO and again depending upon the company business or the environment or the requirement, they have a various requirement for the CISO.
Sometimes in a company which is a very next heavy company, they need someone who understands the technology very well.
So they want to see so a person who will lead the whole organization from a security point of view, but they expect that person to be very technically hands on as well.
Yeah, there are certain companies, for example, I used to be AC.
So for a consulting company, I was expecting that I know more about the GRC because they had to comply with lot of governance risk and compliance framework such as 27,001 and ISTPCIDSS, APRA, Essential 8 and what not.
So it was expected that I know this framework and make sure they are compliant from this framework and I have to maintain those or certify them.
But there was a core idea apart from other, other knowledge such as managing the security operation, managing the team as well.
So depending upon the organizations to organization, some are very hands on and technical, some are very strategic CSO, some are very leadership kind of a role.
If you look at the top banks, the Siso are very oral leadership.
They don't even have a technical background.
Many bank if you see the Sisos come from a defence area with a very strong leadership skills, but they have a second IC or a third IC people in the team who are technically heavy.
But the main Siso role was to stakeholder management, managing the leadership team, managing all the answerable to anything what's happening as a team and and manage the whole team for them as a leader.
So depending on that changes I have I have a couple of blogs on them.
More than happy to share A blog on that area as well.
What does it do?
And recently written a book chapter in one of the book A Life of a Seesaw.
A day in the life of a Seesaw.
Maybe we can put a link on that.
The main author is a David G but I have written a chapter in that along with all the many 20 plus seesaws around the world.
Speaker 2
Absolutely.
I mean, you say seesaws, some people say so, yes.
Speaker 1
Depending where you are.
Speaker 2
Yeah, look, it is.
It's also it always appears like the top job, right.
So you're cybersecurity professional, the chief cybersecurity professional who manages everyone in the FISO.
But like you said, it's really, I've seen exactly what you said.
Sometimes if it's a small company, besides is also managing the firewall.
It's not everything the analyst thought, you know, happened to to lead the whole function.
But as well in the big banks is just a business manager.
Really.
He's just an executive who makes decision managed stakeholders and far removed from technology and everything in between.
I think also people make the thing that the mistake, I guess is they look at the salary like I want that salary.
But I guess a similar thing I get from I get students tell me I want to become a security architect.
Why?
Like do you even know what about it?
Speaker 1
If you like building things like.
Speaker 2
They look at the salary.
I'm like, I want that salary.
I'm like, well, do you even know what they do day-to-day?
And I explain to them what they do day-to-day.
And sometimes they just Word document and ex.
I'm like, Oh no, I don't want to do that.
Yeah, yeah.
It's just the salary itself can be misleading and it depends on on many factors.
But you did mention that you wrote a chapter in a book.
And for those who don't know a bus have written about 5 books now.
Yes.
So.
Speaker 1
If you were coming up.
Speaker 2
There you go.
So for for those of us, what is it like to write a cyber security book?
See.
Speaker 1
I love being in.
I'm a cyber security professional.
I always say that I'm very passionate about this topic.
The why I write is it helps.
It makes me think and do some research.
So I like to talk.
As you know, I go in many conferences.
I like to read.
I like, I'm a practitioner as well.
I'm I'm very hands on.
I like to teach.
I'm a professor as well and I like to write as well.
Yeah.
So think about everything you can do in cyber.
I do all all those things to and and I'm an advisor.
If you look at my role as an advisor, my customer expect me to know most of the answer, not all the answer, but most of the answer.
And to to stand true to my role and the work I do, I have I need to do a lot of reading and research and when I write something, it cements my understanding and the knowledge of what I have learnt either by giving certification exam, people think, oh, why you're giving certificate at this age.
I do certificate to just through myself and to endorse myself whatever I have read and understood is correct or not.
I only that's the only reason I do certification.
I don't I don't do it for for making more money or finding another job.
Speaker 2
Because you enjoy it.
I enjoy it.
Like some people love to watch, I don't know, horse racing.
I'm like, why do you do it?
Because you enjoy it.
So what you're learning, reading, writing, it's a fantastic thing and people really benefit from it.
Because I know your books are in universities, so cyber security students can buy them in a university and learn about different topics.
So it's a fantastic I think and it's it's a goal of mine.
One day, one day I will write a book.
Speaker 1
We can write together.
Yeah, anytime.
Speaker 2
All right, I'll hold myself accountable, but I'd like you've had a really long career and a really colorful career.
You did mention, you know, started with novel networks and like it was a different time.
If we take the clock back and let's say if you imagine you had to start over today from scratch, you have no degree, you have no diplomas, no technical knowledge.
In fact, you just know how to turn on the computer and you want to start a career in cyber security.
Knowing what you know now.
If you knew it then, what would you difference?
How would you start over?
Speaker 1
Very interesting.
Definitely the time has changed.
When I started in 199495 the world was very different.
At that time knowing how to fix an hardware was very important so you should know how to remove a hard disk or replace the hard disk or put a memory card in your in your big black box was one of the skills that you expect.
Oh I work in with computers.
That's the first thing you like can you fix my printer?
Do you know how to replace a toner or the cartridge in those ways?
Yeah, that was the expectation.
But today everything is plug and plug and play something not work just throw it away and we can buy new with the with the cost of a coffee class right.
So that was time has changed.
But if I had to start today and the advice which I would give anyone who wants to start in cyber security today is understand the language of cybersecurity.
So start your fundamental knowledge of basic networking.
People say oh everything is in the cloud but cloud also works on network.
So start with basic understanding of networking concept, what is TCPIP and how it works, how how Internet operates.
So understand the knowledge of various cloud concepts and basic networking because that is your language of cybersecurity.
Start with that.
Second thing I would say is start building your foundation knowledge or start doing some of the fundamental concepts of identity access management because identity is what stitch everything today.
The world has changed.
So the concept which we discussed earlier about identity access management, more levers joiner, you know, privilege access management.
Understand those concept, understand the threat landscape as well.
Once you do that, start building some home labs for practice.
Try things like try hack me in the box kind of a thing which would give you a practical experience.
Learn the basic understanding of scriptings.
I very very important people think, oh I'm in cyber security, I'm in GRC.
I don't need scripting.
No, you need to learn how.
What is the basic KQL?
The scripting or a Python scripting?
It is.
It's a must requirement anyone who's starting in it because there are tasks you need to do automate.
Yes AI agent will do it, but you have to know how to automate things on a basic scripting things like you said you should do a shell scripting back in the days to automate certain things still required today and still relevant.
If you don't know that you don't need to be a programmer but have a fundamental order of scripting and learn that easy, create your own lab basic certification such as AZ 900.
Again, very easy to do it, easy to learn all heaps of videos and learning material available.
Do Google plus Google certification security fundamental easily freely available, which you also endorse very well in your GRC Mastery, right?
Do that security plus basic certification and not to forget the GRC people miss out the concept of GRC.
It is very, very important and kudos to you for bringing everything together in the GRC Mastery course, which is 1 of my favorite.
I've never known.
Just one year back I came to know about it.
It's a very, very absolutely required course today because there are jobs available.
Apart from security analyst, people are looking for GRC analyst as well who can maintain those certification for that, you know, 27,001 and many others.
So having a knowledge of fundamental GRC concept is a must.
So you you learn the technology, you learn the cloud, you learn the GRC, build a home lab.
And the last but not the least is join the community.
Communities like AIC, communities like Issaka, local chapters.
You know, there are a lot of people who would.
Speaker 2
Go and build your.
Speaker 1
Networking, things like that.
Go and meet people that are free trainings available by most of the vendors who would come online and they will do webinars.
They would create a hands on like Google.
Have ACTF every now and then.
Microsoft runs a free certification boot camp where you can do a two days boot camp with them and get a free by 24 hour 50% voucher for the exam as well.
And one more thing is whatever you learn start creating your public presence.
You have your GitHub portal, start adding all the script which you learn and create it, put it online for the benefits of others and and hold about it because you did it.
Create a LinkedIn profile and add whatever the learning path you are following.
Everyone has their own individual journey.
If you ask my son, he had a different journey.
If you ask me, I had a different journey.
So depending upon what clicks you while you are learning, you can do a mastery in that.
So after you do the basic one, then you can think, OK, I think I like the identity space.
Let's dig deeper into that and then you'll get started on that in that side as well.
Speaker 2
Fantastic.
That's an excellent answer.
And I think following these steps, no one can go wrong.
Absolutely.
We're on the same page.
Thank you so much.
Abbas, if people want to find you, what's the best place to reach out to you?
Is it LinkedIn?
Is it Twitter like?
What's your?
Speaker 1
Abbasworld.com, AWBASWRLD, world.com, All my details are there.
My YouTube link, my LinkedIn, my books, my my booking portal, everything you'll find here with a lot of learning resources, a lot of certification links, a lot of free resources you can find in there.
Speaker 2
Wonderful.
So if someone is passionate about cyber security and identity in specific, this is the place.
Thank you so much.
Speaker 1
My pleasure, thank you for having me.
Podcast Summary
Key Points:
Identity and Access Management (IAM) is a critical, fast-growing cybersecurity discipline focused on ensuring the right people have appropriate access to resources, for the right duration, and that their behavior is normal.
The shift to cloud computing has made IAM central to security, as identities are now cloud-based and attackers often compromise systems by stealing credentials rather than breaking in.
There is a significant skills gap in IAM, with a lack of beginner-friendly training, but foundational knowledge and vendor-neutral certifications are available for career entry.
Practical career steps include learning IAM fundamentals (like least privilege and lifecycle management), using free training resources, and gaining hands-on lab experience with tools like Microsoft Entra or open-source options.
AI is expected to automate repetitive security tasks but will not replace cybersecurity professionals, as human strategic thinking and decision-making remain essential.
Summary:
The discussion emphasizes the crucial role of Identity and Access Management (IAM) in modern cybersecurity, particularly as organizations migrate to the cloud. IAM ensures that only authorized individuals access specific resources, monitors their behavior, and manages access lifecycles. A key insight is that attackers often "log in" using stolen credentials rather than exploiting network vulnerabilities, making robust IAM foundational to zero-trust security models.
Despite high demand and lucrative job opportunities in IAM, there is a notable skills gap and a shortage of beginner-friendly training. The expert recommends starting with free foundational resources and vendor-neutral certifications to understand core principles like least privilege and segregation of duties. Practical experience can be gained through labs using tools like Microsoft Entra or open-source platforms.
Finally, while AI will automate repetitive tasks, it is seen as a tool that will create new opportunities rather than replace cybersecurity professionals, who remain essential for strategic decision-making and architecture.
FAQs
IAM is a core cybersecurity discipline focused on ensuring the right people have access to the right resources, for the right duration, and that their behavior is normal. It involves managing who has access to what, for how long, and monitoring for any unusual activity.
IAM is critical because attackers often gain access by stealing credentials rather than breaking in. If identity management is weak, the zero-trust security model fails, putting all organizational investments at risk.
IAM started as an IT function managing simple directories like LDAP and Active Directory. As networks expanded and internet usage grew, security principles like least privilege and segregation of duties were integrated, shifting IAM into a specialized cybersecurity discipline.
Beginners should focus on foundational concepts like identity lifecycle management (joiner-mover-leaver), principle of least privilege, segregation of duties, and identity governance. These principles are essential regardless of the specific tools used.
Start by learning foundational IAM knowledge through free resources and vendor-neutral certifications like those from ID Pro or the Identity and Access Management Institute. Gain hands-on experience with tools like Microsoft Entra, Okta, or open-source options like Keycloak in a lab environment.
Common attacks include phishing, MFA bombing, privilege escalation, golden ticket attacks, and pass-the-hash. These exploit compromised credentials to gain unauthorized access, highlighting the importance of securing identities.
Chat with AI
Loading...
Pro features
Go deeper with this episode
Unlock creator-grade tools that turn any transcript into show notes and subtitle files.