Issue #8 β€” Why 8 Out of 10 People Quit (Plus: A Launch)

πŸš€ SOMETHING NEW: Find Your Cyber Career Path

I turned the Career Changer Workbook into a proper interactive app. It's live now at path.mpcybersecurity.co.uk, free, no signup required, takes about 3 minutes.

Here's the problem it's built to solve. The single biggest reason people stall before they even start is not knowing which path actually fits them, SOC, GRC, Cloud Security, DevSecOps, Pentesting, IAM, or DFIR. Most people guess, pick whichever one has the most TikTok videos about it, and spend months on a path that was never a good match for how they actually think.

What the assessment does:

It looks at your working style, are you a detective, a builder, a strategist, or a breaker, and combines that with whatever your previous career or background is, to give you a specific, personalised recommendation. Not "here are 7 options, good luck." One path, matched to you.

The part I'm proudest of: your previous career is treated as a superpower, not a blank slate.

If you tell it you came from teaching, it doesn't just say "consider GRC." It tells you specifically that classroom management under pressure is the same skill as incident triage, and that lesson planning IS policy writing. If you came from finance, it shows you that audit experience translates directly into compliance auditing, you already understand most of what a security audit requires. Military background, finance, healthcare, IT support, sales, each one gets a specific, honest explanation of what already transfers, not a generic "your skills are valuable" platitude.

And the results page doesn't just leave you there. Once you get your recommended path, you get your first 3 steps to take THIS WEEK, small, specific, free actions using tools you can start today. Not a 6-month roadmap that feels overwhelming on day one. Three things. This week.

Take it here, it's free: path.mpcybersecurity.co.uk

πŸ”₯ THIS WEEK'S INSIGHT: Why 8 Out of 10 Never Make It

Roughly 8 out of 10 people trying to break into cybersecurity never make it to their first role. Not because they lacked talent. Because of three specific, predictable, avoidable patterns.

Pattern one: passive learning. Signing up for a course and treating the labs as optional. Watching when convenient, skipping hands-on exercises because reading the theory "basically covers it." This is cybersecurity's most common failure mode because this is fundamentally a hands-on discipline, and no amount of theory alone gets you past a technical interview.

Pattern two: the generic application. A real, documented case, someone applied to 247 cybersecurity positions. 247. Got 12 phone screens, 4 technical assessments, 2 final rounds, and still no job. The problem usually isn't the volume, it's that 247 applications were the SAME application. Same generic CV. Zero tailoring. Zero portfolio evidence. Candidates who publish 5+ documented projects on GitHub get placed at 2-3 times the rate of candidates relying on certificates alone. That's not a marginal edge.

Pattern three: the guarantee mindset. Believing a bootcamp's "job guarantee" means the job search is someone else's responsibility. Read the actual terms of any guarantee, they require minimum weekly applications, active search proof, sometimes residency requirements. The psychological damage isn't the guarantee itself, it's that believing in it quietly changes your behaviour, you apply less aggressively because part of you is waiting for the guarantee to do the work.

None of these three patterns are about talent. All three are entirely fixable, starting today.

πŸ“° ONE THING HAPPENING IN CYBERSECURITY THIS WEEK

Covered above, but worth repeating simply: the biggest structural fix for pattern one (not knowing where to start) just went live for free. If indecision about your path has been quietly stalling you, that's the specific problem this week's launch was built to solve.

πŸ’‘ CAREER ADVICE FROM THE HIRING TABLE

If you recognise yourself in any of the three failure patterns above, here's the fix for each, in one line. Passive learning fixes with active hours, every session live, every lab actually completed. The generic application fixes with tailoring and a documented portfolio, ten minutes per application, five-plus projects on GitHub. The guarantee mindset fixes the moment you start treating your own job search as the highest-stakes campaign of your career, because it is.

None of this requires more talent than you already have.

🎯 YOUR ONE ACTION THIS WEEK

Take the 3-minute assessment at path.mpcybersecurity.co.uk if you haven't already. Then look honestly at your own last month: which of the three failure patterns have you been closest to? Passive learning, generic applications, or the guarantee mindset? Naming it honestly is the entire first step to fixing it.

πŸ”œ IF YOU'RE READY FOR MORE THAN A RESULT PAGE

The assessment gives you a path and three steps. It can't sit with you every week after that, answer your specific question when you're stuck, or look at the actual CV you end up writing.

That's what the CTRL+ALT+DEFEND Community on Skool is built for. Weekly live Q&A, direct with me. CV and portfolio roasts from someone who reviews real applications for a living. Study groups organised by career path, so wherever the assessment points you, you're not the only person on that track. Every digital product I've built, included at no extra cost.

I'll say what I always say: I'm not promising this guarantees you a job. What I can promise is direct, ongoing access to someone who's spent over a decade hiring for these exact roles.

Join here: https://www.skool.com/cybersecurity-careers-guide-1773/about

This is the last issue of the original run I promised back in Issue #1, but not the last issue, period. If there's a topic you want covered next, reply to this email and tell me. I read every single one.

See you next week.

Marius Poskus Global VP of Cybersecurity / CISO CTRL+ALT+DEFEND

Next
Next

Issue #7 β€” AI Security: The Skill Gap Nobody's Filling