Technology in Cybersecurity: Cert, Tenure, or Craft?

Technology in Cybersecurity: Cert, Tenure, or Craft?

Three hires, one incident

Three people are currently on your cybersecurity IT team when the incident lands late on a Friday. A sensitive sign-in comes up that doesn't quite “add up” – an account doing something that it shouldn't.

The first one, hired last quarter from a stack of fresh certifications, is the first to lean in. Eager, no hesitation, all the way. They enthusiastically grab the available runbook and work it line by line for the step that “should” matches the screen. However, it isn't in there. The present situation doesn't fit the manual, and that’s as far as it goes.

The second one has been doing this for twenty years and will tell you so. You won’t always find them leaning in on their own determinism. They might start asking why it's landing on their team, who touched what last, wasn't this the other group's “job”. The questions sound like diligence but go nowhere except add time. Ten minutes goes by and the problem doesn’t moved – somehow it belongs in the hands of three other groups. It's Friday, and they'd rather it stayed someone else's.

The third one leans in too. Instead of hunting the runbook or working the room, they read what's actually happening, and inside a minute they know where to look.

Three people, one alert – literally three different responses. Does anything of this sound familiar? What separated them IS NOT on any résumé.

The Paper. The Years. The craft

We lean on two signals when we hire, and both of them can lie to us.

One has the certificates. It proves someone studied the material and successfully passed the tests. Certainly real, and worth something. It however doesn't prove they've ever or is capable of successfully applying what they learned when the moment goes off-script.

The other is tenure. Twenty years in the field feels like proof all by itself, and we tend to hand those people the room without a second thought. But years (or a few silver hairs) simply and only measures time served, not necessarily skill or a master of their craft. Someone can spend two decades doing the same thing but only becoming marginally sharper, never getting caught, coasting on the fact that nobody questions the old hand. Time in the chair shouldn’t be assumed as knowing their craft or being able to use a skill.

So what is? It has an older name. Technology. This word gets stuck on phones and cars and the cloud, but that isn't where it comes from.

Greek: tekhne, meaning art, craft, skill, plus -logy, the study of. The study and practice of a craft. The method of applying what you know and staying good at it, not the knowing and not the badge.

Diagram breaking the word technology into tekhne (art, craft, skill) plus -logy (the study of).
Three-column comparison of a cybersecurity hire judged by certificate, by twenty years of tenure, and by craft.

Anyone can really look at or read up on what multi-factor authentication does, or what a conditional access policy is for. You see traits of this all-over social media. Ten minutes, a search bar and an AI. However, application (the art & skill) is that particular trait that can't simply be looked up. This is the part you're actually trying to hire for – someone who really dives into and uses technology.

You can hold a license (certificate) and never have driven a car. Or you can drive the same short route for twenty years and never learn the remaining or even new parts of the map. The craft is the one who studies the road, drives it, and keeps learning and using it. When you're filling a security seat, that's who you're paying for.

PUTTING THEM HEAD TO HEAD

Give all three the same work and the differences show up fast.

Hand each the task of performing a full conditional access policy review.

  • The certificate hire takes it seriously, reads them top to bottom, and confirms it says what it's supposed to.
  • The twenty-year hire pushes back before reading a line. Why are we looking at this now? Who asked for it? Didn't we sign off on this years ago?
  • The craft hire reads each like a series of sentences, and stops on the various parts that are off. He asks tough questions like, “who's in that exclusion group, and why?”

This is where a sensitive account somebody added years ago that has been walking straight past MFA the whole time. Same policy. One hire tried and came up short. One of them wouldn't start. One of them found it.

Now give them a problem that isn't in any runbook.

  • The certificate hire dives in, reaches for a step, and when there's no step, keeps trying but stalls. Willing, just short on reps.
  • The twenty-year hire turns it into a meeting. Questions that don't connect, a point about how the other team really owns this, a little drama, and by the end the work has stopped and nobody's clearly holding it.
  • The skilled hire asks questions too, but theirs land on the relevant problem, not on whose fault it is. They reason out loud, try something, watch what it does, and take it on themselves to run the cause down, staying with it until it's on the table. Not because they've seen this exact case. Because they understand how the pieces move, and they want to know.

Then there's the part nobody claps for: the write-up afterward. The runbook needs updating, the process that let it happen needs a fix, and the next person needs a trail to follow.

  • The certificate hire tries hard here and means well. They just don't always have the method for it yet, so the notes come out earnest and thin, missing the pieces they didn't know to capture. Time and coaching really helps fill that in.
  • The twenty-year hire pours spackle over it. A quick one-liner that makes the ticket closable, a patch smoothed over the crack so it reads as finished, nothing that would actually stop it from happening again.
Technology in Cybersecurity: Cert, Tenure, or Craft? supporting illustration 3
  • The craft hire treats the write-up as part of the job, not the chore after it. They make certain it's fully addressed, and they do it with the next person in mind, arming whoever picks it up with everything they'd need to carry it forward. They're spending extra time or writing to close the ticket. They're writing so the next incident is shorter.

That's the tell running beneath all three types, and it's where the rookie and the skilled hire actually rhyme. Both lean in. Both want the problem solved. The rookie just doesn't have the reps yet, and watch for them as this comes with time and coaching. The one to watch is the hand who's been there longest and digs in the least. Sometimes that's the loud version: every problem met with a non-sequitur and a reason it belongs to someone else. Sometimes it's the quiet version: someone who probably knows, or could find out, but won't step out of their lane unless the boss points at them and says go. Different styles, same result. The problem sits there, unowned.

The craft hire goes the other way. They own the problem even when it spans three teams, which is the exact seam the deflector slips through. They hunt problems, take some pride in fixing them, and keep sharpening because they want to. They understand the area, study it, and can actually apply it.

Technology in Cybersecurity: Cert, Tenure, or Craft? supporting illustration 4

So hire, and trust, for the craft

On paper, the certificate and the twenty years both look like safety. The interview is where you find out which kind of person you've got. Definitions won't tell you. The rookie and the old hand can both recite those. What tends to work is handing over a broken policy or a strange sign-in log and asking them to talk it through. What's wrong here? What happens if you flip this one setting? The answer matters less than who leans in and who waves it off.

Technology in Cybersecurity: Cert, Tenure, or Craft? supporting illustration 5

The craft hire is hard to find, and often you can't. The upside is the craft can be grown in anyone still willing to grow, and the eager rookie usually is. Willingness is the hard part to teach, and they already have it. It's the twenty-year hand dug in against learning who leaves you the least to work with. Twenty years of steady improvement builds a master. Twenty years of the same Friday builds a habit.

None of this makes the certificate or the experience guy worthless. The knowledge counts, the years can count, and your best hire has real craft (and aptitude) on top of both. That's the one still standing at 2 a.m. when the situation refuses to match the manual, the one who wanted to be there when it broke. The one worth finding. Or worth growing.

Glossary

Technology (this article's sense). The craft of applying what you know and staying good at it, not just knowing it. From the Greek tekhne (art, craft, skill) and -logy (the study of).

Certification. A credential that shows someone studied a subject and passed a test on it. Proof of knowledge, not proof they can apply it.

Tenure. Years spent in a role or field. A measure of time served, not a measure of skill on its own.

Multi-factor authentication (MFA). A sign-in that asks for more than a password, usually a code or prompt on your phone, so a stolen password alone won't get someone in.

Conditional access policy. A rule in Microsoft Entra that decides who can sign in, from where, and what they have to prove first (like MFA) before reaching an app or data.

Exclusion group. A list of accounts a policy skips on purpose. Handy for exceptions, risky when forgotten, because skipped accounts lose the protection.

Service account. A login used by an app or an automated task instead of a person. Often has broad access and gets overlooked.

Runbook. A written, step-by-step guide for a known situation. Useful right up until the situation isn't in the book.

Similar Posts

Leave a Reply

Your email address will not be published. Required fields are marked *