How I Entered the World of Cybersecurity – Part 2

How I Entered the World of Cybersecurity – Part 2

 The Three Days That Changed My Career

Hello again, everyone.

Welcome back to Part 2 of my story about how I entered the world of cybersecurity.

If Part 1 was about how I first became fascinated with information security, Part 2 is about the moment when I finally discovered what I wanted to do with that fascination.

And strangely enough, this part of the story begins with the 2002 World Cup, a stubborn HP server, a few days by the sea, Microsoft PowerPoint — and eventually Ettercap.

It Was the Year of the 2002 World Cup

I believe this part of my story began sometime around 2002.

It was the year of the FIFA World Cup in Japan and South Korea.

I still remember watching that wonderful Brazilian team. Ronaldinho's unpredictable movement, Rivaldo, Ronaldo — there were so many memorable moments.

Sometimes we watched the matches together at the company.

Those memories help me remember what that period of my life felt like.

I was young.

I had graduated from university.

I had already worked as a programmer.

But I still had absolutely no idea what I really wanted to do with my career.

A Huge HP Server Taught Me Something About Myself

One afternoon, a colleague and I went to Metro Cash & Carry — usually just called Metro — to troubleshoot an IT incident.

As was very common at the time, there were problems involving backups, data, and computer viruses.

But this time there was another problem.

There was a huge HP server that wouldn't boot.

And when I say huge, I remember it feeling almost as big as a desk.

We stood in front of it trying to figure out what to do.

To make matters worse, I didn't even know how to properly open the chassis.

Remember, this was long before we could ask an AI assistant:

"How do I open this HP server?"

We had manuals, colleagues, experience, and whatever technical knowledge we carried around in our own heads.

Then my colleague stepped forward.

He had graduated from college rather than university.

I mention that not to look down on his education — actually, quite the opposite.

Because while the university graduate was standing there wondering how to open the server, he looked at it, understood where the joints and release points were, gave the right places a few confident knocks...

and opened the chassis.

I was genuinely surprised.

He simply understood the hardware better than I did.

It reminded me of another embarrassing experience I had when trying to open a Dell desktop for a customer. I used the wrong screwdriver, struggled with the screws, and managed to turn what should have been a very simple job into something unnecessarily difficult.

Those experiences made me ask myself an uncomfortable question:

Was I actually trained to do this kind of work?

And perhaps more importantly:

Was this really what I wanted to spend my life doing?

The answer was becoming increasingly clear.

Probably not.

“What Is Your Philosophy of Life?”

There was another small event that stayed with me.

During an interview, a manager once asked me:

“What is your philosophy of life?”

I just smiled.

I didn't answer.

My thinking at the time was that it was better to give no answer than to invent some profound-sounding cliché just because I had been asked a profound-sounding question.

But strangely enough, that question stayed with me.

After programming, technical support, virus incidents, data recovery, server maintenance, and customer troubleshooting, perhaps it really was time to ask myself:

What did I actually want to do with my life?

Many of my university friends were already becoming established software developers.

Some were starting to move into project management.

Their careers seemed to have direction.

Mine didn't.

Eventually I decided:

Never mind. I'll quit first and figure it out afterward.

Today, I am not sure I would recommend that as a universal career strategy.

But that is exactly what I did.

Three Days at OCAP

I gave myself three days to think.

I went to OCAP, the old name many people used for the beach area in Vũng Tàu.

I spent time by the sea.

I watched the waves.

I drank good coffee in the warm golden afternoon light.

In the distance, high above the city, stood the great statue of Christ the King, arms stretched wide over the mountain.

Everything felt peaceful.

And my mind slowly became quieter.

Sometimes I thought:

Maybe I should just go back to programming.

Then another thought would immediately follow:

But I'm not particularly brilliant at programming either.

So I kept drinking coffee.

Kept looking at the sea.

And still didn't have an answer.

Until the third morning.

Then I Saw a Job Advertisement

On my third morning at the beach, I came across a recruitment advertisement from New Horizons.

They were looking for instructors.

New Horizons was a major international IT training organization, and something about that advertisement immediately attracted me.

Maybe, I thought:

I would enjoy teaching.

There was another thing that fascinated me.

New Horizons had an online learning system.

Today, online learning sounds completely ordinary.

But this was around 2003.

The idea that somebody could learn online, at different times and from different locations, felt incredibly modern to me.

I still remember a slogan along the lines of:

Online. Anytime. Anywhere.

Perhaps I don't remember the exact word order after all these years, but I certainly remember the idea.

It impressed me so much that it later became one of the inspirations behind my own online training system, which I started developing in early 2004.

But at that moment, I wasn't thinking about building my own training platform.

I just wanted to work there.

My Three-Month Probation Began

With my technical background, I passed the initial interview process without too much difficulty and began a three-month probationary period.

During the first month, I was trained in teaching and presentation skills.

One of the subjects I had to prepare and present was:

Microsoft PowerPoint.

There was just one problem.

While I was supposed to be concentrating on PowerPoint...

I was spending most of my spare time studying information security.

I explored Windows domains, Active Directory, Group Policy, permissions, authentication, system recovery, remote administration, and the security weaknesses that existed in enterprise systems of that era.

I became fascinated with how access controls worked.

And, like many young people discovering security for the first time, I was equally fascinated by what happened when those controls didn't work as expected.

I experimented with security and administration tools that were well known at the time.

Among them were Ettercap and AWRC Web Remote Control.

And that opened another door for me.

Ettercap Changed the Way I Looked at Networks

Earlier in my career, I had already seen tools such as dsniff.

But Ettercap showed me just how much risk could exist inside a local network.

Remember the environment of the early 2000s.

Encrypted communications were nowhere near as universal as they are today.

Many network services could still expose credentials through insecure protocols.

Seeing a username or password appear in readable form in network traffic was not as unusual then as it would be today.

And people reused passwords.

A lot.

Actually, people still reuse passwords today.

That combination taught me an important security lesson very early:

A single exposed password may not compromise only one account.

If someone uses the same password for email, remote access, internal systems, and other services, one compromised credential can create risk across multiple systems.

Another tool that fascinated me at the time was AWRC — Web Remote Control.

Remote administration was incredibly powerful, especially in an era when centralized endpoint management was far less mature than it is today.

Together, these technologies taught me lessons that remain completely relevant more than 20 years later:

Don't reuse passwords.

Don't send credentials through insecure protocols.

Apply least privilege.

Protect administrative access.

And never assume that an internal network is automatically trustworthy.

These sound like basic cybersecurity principles today.

But back then, I was discovering them by seeing what happened when those principles were ignored.

Meanwhile, My PowerPoint Presentation Was Going Badly

There was an obvious problem.

I was supposed to be studying PowerPoint.

Instead, I was studying network security.

Eventually, presentation day arrived.

I stood in front of my team leader and director and presented Microsoft PowerPoint.

They watched.

I presented.

They continued watching.

And judging from their faces...

things were not going particularly well.

There were considerably more frowns than smiles.

I had clearly spent too much time on security and not enough time preparing the subject I was actually supposed to teach.

Fortunately, they gave me another opportunity.

They said:

“Choose a topic that you really want to present.”

That was easy.

I immediately chose:

Information Security.

Everything Changed When I Talked About Security

I don't remember exactly what security topic I presented that day.

More than twenty years have passed.

But I remember something far more important.

Their reaction.

This time, the managers smiled.

The difference was obvious.

When I talked about PowerPoint, I was delivering a presentation because somebody had asked me to.

When I talked about information security, I was talking about something I genuinely loved.

Apparently, everybody in the room could see the difference.

Including my managers.

Now I Have to Confess Something

There is another part of this story that I considered leaving out.

It doesn't make me look particularly good.

But if I am going to tell the real story of how I entered cybersecurity, I think I should tell this part too.

I really wanted to stay at New Horizons.

Probably too much.

I was young, technically curious, and nowhere near as mature about professional boundaries and cybersecurity ethics as I am today.

And because I had been experimenting with tools such as Ettercap, I discovered that insecure network communications could reveal information that was never intended for me.

At one point, my curiosity crossed a line.

I accessed communications that I was not authorized to read because I desperately wanted to know what the managers thought about me and whether they intended to keep me.

That was wrong.

There is no clever technical justification for it.

Knowing how to access something does not mean you have permission to access it.

That lesson became much clearer to me as I matured professionally.

And it is something I now teach very seriously:

Technical capability is not authorization.

This is one of the most fundamental principles in ethical hacking and cybersecurity.

You may discover a weakness.

You may know how it could be exploited.

You may even have the technical ability to do it.

But without authorization, you don't do it.

I never repeated that behavior.

But What I Discovered Surprised Me

What I found was something I had desperately wanted to know.

The managers and director were discussing my performance.

And essentially they were saying:

This guy is quite good at information security.

They were considering keeping me, developing me further, and having me teach cybersecurity.

I had looked for that answer in a way that I would absolutely not recommend today.

But the answer itself was remarkable.

Because suddenly everything seemed to connect.

Programming.

Networking.

Virus incidents.

Data recovery.

Remote administration.

Active Directory.

Security tools.

And now teaching.

For the first time, I saw a career that combined the things I actually enjoyed.

Cybersecurity and training.

I Was Hired Two Months Early

My probationary period was supposed to last three months.

Instead, I was officially hired two months early.

And for the first time since leaving university, I felt that I had finally found the direction of my career.

Cybersecurity.

Training.

Research.

Hands-on experimentation.

Learning.

Teaching others what I had learned.

More than two decades later, I am still following essentially the same path.

Looking back, it is funny how careers develop.

I went to university and studied algorithms and programming.

I became a programmer.

Then I fixed computers.

Removed viruses.

Recovered data.

Worked with servers.

Discovered network sniffing.

Became fascinated by information security.

Tried teaching PowerPoint.

Failed to impress my managers.

Asked to teach cybersecurity instead.

And somehow...

that became my career.

There Was One Final Challenge

Before I officially started teaching security, however, my director gave me another challenge.

He wanted me to earn a professional cybersecurity certification.

And the certification he chose was:

CompTIA Security+.

To me, it didn't feel like a punishment or even much of a challenge.

It felt like a gift.

Someone was effectively telling me:

Go study cybersecurity seriously.

That was exactly what I wanted to do.

So I started preparing for CompTIA Security+.

And that leads directly to Part 3.

Coming Next: How I Took My First CompTIA Security+ Exam

In Part 3, I'll tell you about preparing for and taking my first CompTIA Security+ exam in 2003.

That exam became especially meaningful to me because more than twenty years later, I would take Security+ again.

Two Security+ exams.

More than twenty years apart.

And yes...

I still remember the score from my first attempt:

896.

That story deserves its own article.

Thanks for reading.

See you in Part 3.