Interview with cyber expert

An Interview with Ivan Salter, Managing Security Consultant

“My relationship with Cyber is like when you have your first love, you lose contact with that person for a few years, and then one day, in a city, you find her at the train station, a little bit different, but with the same smile on her face that made your heart beat so fast. You start to talk with her and from that day you restart with a passionate and never-ending love story.”

Introducing Ivan Salter, a Managing Security Consultant with a breadth of knowledge and experience in all things spanning the vast Cyber industry. This month, I had the pleasure of interviewing him, gleaning valuable insights into how he got to where he is today, his experiences within the different cyber pathways, and his tips for those looking to break into cyber.

I can imagine every day is different, but what does a day in the life of a Managing Security Consultant look like for you?

Each project is a new experience. Of course, the structure and standardisation are provided by a well-developed and designed service catalogue and all the procedures and global practices we have in place. However, NCC Group is always improving and innovating so you must be prepared to learn new skills, which is why it’s important for me to always look towards upskilling. That’s why companies like yours play a key role in the cyber security training and cyber awareness process by providing external services and supporting companies in the development of their employees. In Cyber, you cannot be passive or be a conformist. The cyber threat landscape is constantly changing so you must be prepared to respond to those changes. In a nutshell, a Managing Security Consultant needs to have a solid foundation, soft skills, and technical expertise but also be able to juggle unforeseen changes.

You’ve had a range of different roles within the industry. Which role did you enjoy the most and for what reasons?

I cannot say that I prefer one role over another, but my preference is to make my own decisions; in cyber security you must have a clear, straightforward, strategic mind. Beside my preferences, I have enjoyed every single role. Some of these roles required more technical skills and hands-on experience, others more managerial skills, project management, etc. To summarise, I simply like to be in a cycle of continuous improvement.

Working in Cyber Security Governance and Risk Management gave me the opportunity to see things from the inside, from a second-line perspective, with that level of independence that’s needed to guarantee that your risk assessment isn’t biased or there’s any conflict of interest.

Now, as a Managing Security Consultant I enjoy seeing things as an “external” but inwards for the client.

In Cyber Security Management you must focus on delivery and resource management. People management can be tricky and time consuming but also enjoyable.

There is no perfect role. I enjoy the roles where you get dirty, where you get the pure hands-on, the technical stuff. But I also enjoy those where you see cyber security as a top-down-bottom-up function; you have to deal with governance and compliance, evaluating efficacy and efficiency of the security controls.

Can you tell me a bit about how you got into/found your interest in IT/Cyber?

Perhaps I could explain this with an allegory. My relationship with Cyber / Information Security is like when you have your first love (the one that was so special for you), you lose contact with that person for a few years of your life because your duties and circumstances pull you apart, and then, after you have matured and endured a few challenges, one day, in a city, you find her at the train station, a little bit different, but with the same smile on her face that made your heart beat so fast. You start to talk with her and from that day you restart with a passionate and never-ending love story.

My love story started back in 2004, when I did my first Pen Test for a local TV network as an IT Security Consultant. This was when everyone had a 4-to-6-character password which was a dictionary word, birthday, or pet name. This is when you could find software firewalls, when nobody would give a penny for a cyber security strategy. However, me, as a technical person, with computers from the age of 12, loved this side of the story. The software revolution and small-size PCs arriving at our homes were the golden hen. Security was more a concern for a Department of Defence or a few big financial institutions. But for me, it was love at first sight.

Everything changed when I moved to Scotland in 2009. This is when I really got into the IT world working for Sun Microsystem (then Oracle). Even if it was not a pure cyber role, security was implicit in everything we did. I continued working until I had the chance to be an IT manager at Edinburgh University. This is when I decided to get an academic title: an Information Security MSc in Advanced Security and Digital Forensics. Obviously, this master’s degree not only helped me to evidence the knowledge that I already had but improved it and provided me with new skills. The jump to a pure Information Security role was when I started at Royal London as an Information Security and Risk Manager. Then, my professional life continued along the same path.

What would you recommend to people who’d like to enter the cyber industry but don’t want to go down the university route?

I always say the same, love what you do, love what you study. Do not do it because somebody told you that there is a lot of demand for Cyber Security experts, and they pay well. You may last a few years earning a significant amount of money, but you will be frustrated because you’re not doing something you love.

If you love it but don’t want to take the university route, I simply recommend going and receiving good advice from a company such as yours. You know exactly what the trends are and the industry demand for professional certifications. If you want to follow the more technical route, you have CompTIA, CEH, AWS, Google, or Microsoft (security certifications). If you want to lead projects, be part of governance and so on, CISM, CISSP, CRISC. If you are keener to be on the audit line, CISA, ISO 27001 Lead Auditor. If like me, you have a passion for Information Security, take as many of these courses as you can – not just because you get a title, but you also refresh your knowledge add new skills to your toolkit.

Industry-recognised certifications are the best way to break into the industry. I believe strongly that due to the overall importance of cyber security, and the rise of global cyber threats, governments should fund and support those looking to switch their careers to cyber security.