Issue #11 — Why You Keep Quitting cybersecurity at Month Three

Why people quit cybersecurity

Hey,

Last week was about finding the jobs most people never see. This week is about something that stops people long before they ever apply: the point, usually around month three, where studying cybersecurity suddenly feels harder than it did on day one.

If that's where you are right now, this issue is for you.

🔥 THIS WEEK'S INSIGHT: The Wall Nobody Warns You About

Month one is exciting. Everything is new. Every video teaches you something, every lab feels like a win, and you can feel yourself improving.

Then, somewhere around month three, it changes. The easy wins dry up. You re-read the same page three times. You open a job description and feel further away than when you started. And a quiet voice starts asking whether you're just not smart enough for this.

Here's what's actually happening, and it's not what that voice is telling you.

1. The easy wins are gone. In the first weeks, you go from knowing nothing to knowing something, and that jump feels enormous. By month three, the basics are done. Progress is still happening, but it's slower and quieter, so it stops feeling like progress.

2. You can finally see how big the field is. At the start, you didn't know what you didn't know. Now you've seen SIEMs, cloud, scripting, frameworks, Active Directory, and the gap suddenly looks huge. Learning researchers have a name for this shift: moving from unconscious incompetence (you don't know what you're missing) to conscious incompetence (you can see exactly what you're missing).

That second stage feels worse than the first. But it's a step forward, not backward. You can only see how much you don't know once you know enough to recognise it.

The month-three wall isn't a sign you're failing. It's a sign you're finally learning. And it's exactly where most people quit, right before it starts to click.

📰 ONE THING HAPPENING THIS WEEK

The community now has a weekly Challenge of the Week: a realistic work ticket for your path (SOC, GRC, IAM, or Cloud), with a deadline, peer review, and my model answer afterwards. This month, everyone's "first week" is at a fictional healthcare company called Northwind Health.

I mention it here because it's one of the best cures for the month-three wall. When you finish a real task and see how a CISO would have approached it, progress stops being invisible.

🛠️ FREE TOOL OF THE WEEK: The Weekly Progress Log

The biggest reason the wall feels so bad is that progress becomes invisible. So make it visible. Copy this into a notes app, and fill it in every Sunday. It takes five minutes.

WEEK OF: ____________

What I studied this week:
-
-

One thing I understand now that I didn't last week:
-

One thing I built, broke, or fixed:
-

What confused me most (bring this to the Q&A):
-

Hours studied: ___   Target next week: ___

After four weeks, read back through it. Most people are genuinely surprised by how far they've come, because day to day, you never notice it.

💡 CAREER ADVICE FROM THE HIRING TABLE

Stop comparing yourself to people years ahead of you.

The person posting their OSCP, their new SOC role, or their 50th Hack The Box machine is showing you their highlight reel, not their month three. Every one of them hit this exact wall.

The only comparison that tells you anything is you, now, against you a month ago. Everyone I've hired hit this point. The ones who made it didn't feel it less. They just didn't treat it as a reason to stop.

🎯 YOUR ONE ACTION THIS WEEK

Write down three things you understand now that confused you a month ago.

Not three things you've mastered. Three things that used to make no sense and now do. A port, a protocol, a Linux command, a framework, a concept from Security+.

If you can write three, you're not stuck. You're in the hardest part of the climb, and you're still climbing.

🧰 FREE TOOLS, IF YOU HAVEN'T TRIED THEM YET

🧭 Lost on which path to focus on? path.mpcybersecurity.co.uk turns your background and working style into one recommended path.

📊 Not sure what to study next? skills.mpcybersecurity.co.uk shows exactly what's missing for your target role, so your hours go to the right things.

🧠 Hit the wall on Security+? practice.mpcybersecurity.co.uk explains every answer, so you learn why, not just what.

📄 Ready to apply, but hearing nothing? The CV checker shows what the machine sees first: cv.mpcybersecurity.co.uk

All free. No signup required to see your results.

🔜 IF YOU'RE HITTING THE WALL ALONE

The wall is hardest when you face it by yourself, studying at 10pm with nobody to tell you you're on track.

That's exactly what the CTRL+ALT+DEFEND Community on Skool is for.

Weekly live Q&A, direct with me. Bring the thing that's confusing you most from your progress log.

Weekly hands-on challenges for your path, with model answers, so you can see your progress instead of just hoping it's happening.

Study groups by career path, full of people at exactly the same point, including the month-three wall.

Every digital product I've built, included.

No guarantees. Just a place where you don't have to climb this part alone.

👉 Join here: https://www.skool.com/cybersecurity-careers-guide-1773/about

Hit reply and tell me one thing you understand now that you didn't a month ago. I read every one, and I'd genuinely like to know.

See you next week.

Marius Poskus Global VP of Cybersecurity / CISO CTRL+ALT+DEFEND

Next
Next

Issue #10 - The Hidden Job Market: Finding Roles Before They're Posted