“However, current demand doesn’t necessarily equate to future demand though.”
I wrote that sentence. August 2021, on this newsletter, in a post called What Makes Cybersecurity a ‘Future-Proof’ Career? You can hear the hurry in it. A “however” at the front and a “though” at the back, the same hedge twice, the sound of a man who knew he owed the reader a caution before he got on with the part he actually wanted to write. I meant it. I just aimed it away from here.
The examples I reached for were other people’s industries. Trucking, where autonomous fleets were coming for the long-haul seat. Law, where, as I put it then, “technology allowed law firms to replace armies of young attorneys with e-discovery software.” I had the instrument. I used it. I pointed it at every profession I could see from where I was standing, and never once at the bottom rung of my own. This issue is me turning it around.
What the man in 2021 had going for him
I want to be fair to him, because he had reasons. The field had ridden every wave of technology it had ever met. Cloud arrived and became one more thing to secure. Mobile arrived and became one more thing to secure. Every new tool for as long as anyone in it could remember had the same effect on this profession, which was to make it larger. I wrote “Cybersecurity isn’t a destination. It’s a way of being,” and against that record I was reading the evidence in front of me correctly.
I had one more reason, and it was the one I trusted most, because it had happened to me. I came through that door myself, off a trading floor, after a long stretch of applications that mostly went nowhere. The seat I landed in taught me the trade. Somebody two chairs over answered my questions for a year. That is the mechanism, stated plainly, and it is the same mechanism for almost everyone reading this who is now senior. Go find anyone with fifteen years in security and ask them where they learned to read a log properly. They will describe a chair, a queue of alerts, and a person nearby who was willing to be interrupted. That is who the “us” in the title is. A specific group of people with one shared origin, and I am one of them.
He was not missing the macro picture
Here is the part that has been hardest to sit with. The frame I was writing inside in 2021 was the Fourth Industrial Revolution reading of what was coming: the argument that automation was about to reorganize whole categories of work rather than shave a few points off them. That frame sits in the subtitle of the other post from that spring, How to Reduce Career Risk and Outrun Job Automation, above the fold, where a reader meets it before the first paragraph.
So I was not guessing. I had the shape of it five years early, in writing, with my name on it. I applied it to trucking, and to law, and to the back office, and to every profession I could name. I never turned it on the chair I was sitting in.
The promise, and what was actually wrong with it
So here is the other sentence, the one I have been circling for two issues. It ran in March 2021, five months before I called the field future-proof, under a headline about reducing career risk. Here it is in full, with its punctuation exactly as I wrote it.
“In order to outrun automation in our careers—and stay ahead of the computers—we must be willing to pivot to roles in which human skills are valued and we’re not competing with algorithms and processors.”
March 2021. That was the advice, and people took it. I have met some of them. The strange part is that I still think it was good advice: the reasoning holds and the destination was chosen correctly. Security work is exactly the kind of work where human judgment is valued, and the senior end of this field is becoming more valuable every year.
The route is where it breaks. To reach the roles where human skills are valued, you first have to spend three or four years in a seat where mostly they are not. Triage. Tickets. The same alert forty times until the forty-first one is different and you finally understand why. That seat is the toll booth on the road I pointed at. And that seat is the one being cut away.
An accounting, not an apology
There is a distinction here I need to make carefully, because it is the difference between the two. As a claim about the profession, future-proof is holding up. The field still rides the wave. Senior work is getting harder to replace, and the problems that reach a senior desk keep getting less routine. If you sat me down and asked me to defend that sentence at the altitude I wrote it at, I could defend it this morning.
To reach the roles where human skills are valued, you first have to spend three or four years in a seat where mostly they are not.
People read career advice at the altitude of their own career, which is the only sensible way to read it. I was writing about an industry. The person on the other end was reading about a Monday morning, a first badge, a job they could actually apply for. I wrote at the altitude of a field and I was read at the altitude of a career, and everything I got wrong lives in the gap between those two readings.
Which is why I want to be exact about the pronouns in the headline and the line under it, because between them they are doing two different jobs. The advice was mine. I wrote it. The automating is ours.
What the season has been circling
Four assumptions have been sitting underneath everything I have written here. First, that there is a ground floor everyone starts on. Second, that the door onto it is wide enough to walk through. Third, that the seat behind that door teaches you the trade. Fourth, that the climb from there is fair, or fair enough to be worth starting. Every one of the four rests on the same tier of work. Pull that tier and all of them lose the thing that made them true. There is a fifth, and it is the strongest of them, and I did not see it until this year.
Fifth, that something at the end would certify you
It never existed, and I know exactly how that lands in a field this full of certifications. I hold some myself and they have been worth holding, so take this as a distinction rather than a complaint. A certification and a certifying institution are two different things, and the difference is the whole of what I missed for five years.
Think about how it works everywhere else. You sit the bar in a given state, you pass, and that state licenses you to practice law. Before that day no employer can wave you through, and after it nobody gets to ask again. One authority, one examination, and a legal permission waiting on the other side of it. Other professions run the same machinery under different names, and in every case the standard is public and the answer is the same for everyone who walks in.
Cybersecurity has nothing of the kind. There is no bar exam here. Our certifications are products, sold by private bodies that compete with one another for the same candidates, and not one of them is required in order to do the work. You can build and run a security program without holding a single one. They tell a hiring manager something real about you, which is why people buy them and why I bought mine. None of them licenses you, and there is no afternoon when an institution looks at your work and says the word qualified out loud.
A certification and a certifying institution are two different things, and the difference is the whole of what I missed for five years.
We use the language of a licensed profession in the loose way people do, and we have never built the thing that makes one. What we had instead was time in the chair. The market read years served as the qualifying event, because years served was the only evidence anybody could point to.
Here are two facts. Set them next to each other and they finish the argument without my help. First, the CISSP requires a minimum of five years of cumulative, full-time work experience in at least two of its eight domains. A bachelor’s or master’s in a computing field, or one credential from ISC2’s own approved list, may cover a single one of those five years. Pass the exam without the experience and you hold the Associate of ISC2 designation while you go and earn it, with six years to accumulate the five.
Second, in ISC2’s 2025 hiring trends research, 34% of hiring managers said they require the CISSP for entry-level roles. The number comes from the issuer, which sells the certification, so read it as the issuer’s own account of how its instrument is being used in the market. That is mid-pack, which is the part worth sitting with. In the same study, 38% said they require CISA for entry-level work, and CISA asks for five years of its own. Credentials that take five years of experience to hold, asked for by more than a third of the managers hiring into the job that is supposed to supply the experience.
Two institutions, and we built neither
Every one of those professions runs two institutions, and each does a different job. A formation mechanism: residency, articling, supervised audit hours, line checks. The part that teaches you the work. A gate: the boards, the bar, the CPA, the type rating. The part that licenses you to do it. Cybersecurity built neither one, and the chair absorbed both jobs without anybody deciding that it should. It did them for free, which is why nobody noticed. So the claim is larger than the one I have been making all season. The productive task and the developmental task were the same activity, yes. Sharper than that: the productive task, the developmental task, and the qualifying event were all one chair.
The hollowing is quiet because the seat is still budgeted
That chair is being cut away now. Early stages, uneven, faster in some shops than in others, and moving. The work at the bottom is being hollowed, not eliminated. The seat is often still there and still budgeted. It is being emptied a task at a time, which is slower to notice and harder to argue with. Which brings me back to the line at the top, and I would rather write it plainly in the body than leave it up there working as a headline.
We are automating the job that made us.
That sentence has an agent, and the agent is us. The same people, the ones the chair made. We are the ones buying the tooling, approving the architecture, and signing the budgets that are hollowing the tier we came up through. Each of those decisions is defensible on its own terms. That is precisely what makes this hard to stop, and it is why I do not think there is a villain in this story worth going to look for.
The next honest step
The question I owe you next is a mechanical one, and I would rather answer it with specifics than with a mood. What is actually doing the hollowing? What does it genuinely do well, and what does it still hand back to a person? A seat losing three of its ten tasks is a different problem from a seat losing seven, and which one we are in decides almost everything about what anybody should do about it. That is the next issue. Until then, one thing for each of you.
The work at the bottom is being hollowed, not eliminated.
If you are trying to get in: keep studying for the certification, and stop treating it as the gate. The course gives you a structured path through material you would otherwise wander around in, and passing shows a hiring manager you cleared a consistent bar, which is worth something real. What it cannot give you is what the chair gave me, which was somebody two chairs over explaining what they had seen that I had missed. Ask a different question in your next interview, out loud, and ask it early. Who is going to teach me, by name, and what do the first ninety days look like? A hiring manager with a real answer is offering you the thing the certificate cannot. A hiring manager without one has told you something useful too.
If you are already up the ladder: you were made by a chair that is being emptied while you watch. You are allowed to say that in a planning meeting. Name what your team’s formation mechanism is now, in plain words, and if the honest answer is that there is not one yet, that sentence is worth more to your organization this quarter than any figure I could put in front of you.
I got this wrong in public in 2021. It seems only fair to correct it in the same place.
— Oritse
A note on where I stand: I spent years running security inside large financial institutions, and I sit on the advisory board of a company building autonomous security tools. Nothing non-public, from anywhere I have worked, goes into what I write here.
Next: what is actually doing the hollowing, and what it still hands back.
