The Cybersecurity Career Newsletter

Issue #5 — One Certification, Then Build

Hey,

Quick recap: Issue #1 was the 7-Day Kickstart. Issue #2 was the 5 interview questions that decide everything. Issue #3 was the 3 mistakes that make your home lab look amateur. Issue #4 was the LinkedIn strategy that gets recruiters messaging you.

This issue tackles the single most expensive myth in this industry: that the next certification is what's standing between you and a job offer.

🔥 THIS WEEK'S INSIGHT: 1 Million People Proved This Wrong

ISC2 gave away one million free cybersecurity certifications. Free course. Free exam. Zero cost barrier, the single biggest excuse in this industry, removed completely.

One million people signed up. Just 65,000 actually finished. That's 6.5%.

I've trained and mentored people trying to break into cybersecurity for years. This is exactly the pattern I see constantly. People don't want to do the work. They want the next certification that will magically open the door. It doesn't exist. It never did.

Here's what I see on CVs every single week: Security+, CySA+, CEH, and SSCP. Four certifications. Zero projects. Zero GitHub. Zero demonstrable skills.

The ISC2 2025 Workforce Study found that 52% of organisations say their biggest challenge isn't finding enough staff, it's finding staff with the right skills. Read that again. It's not a headcount problem. It's a skills problem. And certifications alone don't prove skills.

The fix is simple, even if it's uncomfortable: one certification, then build. Then maybe another certification. Portfolio first, always.

📰 ONE THING HAPPENING IN CYBERSECURITY THIS WEEK

I just published a video called "5 Cybersecurity Certifications You Should Avoid in 2026." CEH, CompTIA CySA+ and PenTest+, ISC2 CC, Cisco's free cybersecurity certificates, and expensive bootcamp certificates all made the list, not because they're worthless, but because the money and time spent on them is almost always better spent elsewhere.

The one certification I recommend to everyone regardless of path? Security+. It's the universal baseline. Everything after that should be practical and hands-on: TryHackMe SAL1, CyberDefenders CCD, or Blue Team Level 1, depending on your direction.

Watch it here: https://youtu.be/jXraUMyZsfY

I also just published a comparison video, "Why I'd Choose GRC Over Pentesting in 2026." If you've been assuming penetration testing is the default "real" cybersecurity career, this video walks through the honest timeline, cost, and competition data most people never see before committing to that path.

Watch it here: https://youtu.be/Qxhj6NKjjFk

🛠️ FREE TOOL OF THE WEEK: Professor Messer's SY0-701 Course

What it is: The complete, free YouTube course covering every domain of the CompTIA Security+ exam.

Why it matters: If you haven't started Security+ yet, this is genuinely the only resource you need for the theory. It's the exact material most bootcamps repackage and charge thousands for.

Where to get it: Search "Professor Messer SY0-701" on YouTube, or find it linked in the Security+ 90-Day Study Planner on my website.

Portfolio move: As you go through each domain, keep a running list of concepts you'd like to demonstrate practically. When you get to Domain 4 (Security Operations), that list becomes your home lab project plan.

💡 CAREER ADVICE FROM THE HIRING TABLE

Here's a quick audit to run on yourself right now. List every certification on your CV. Next to each one, write down the specific project, script, or documented lab exercise that proves you can actually apply it.

If any certification has nothing next to it, that's not a certification problem. That's a proof problem, and it's the single highest-leverage thing you can fix this month.

I'd rather see one certification and three solid projects than four certifications and an empty GitHub. Every single time.

🎯 YOUR ONE ACTION THIS WEEK

Do the audit above, right now, before you close this email. One column: certifications. One column: proof. Anywhere the second column is blank, that's this week's project. Not a new certification. A demonstrable piece of work.

🔜 STRUGGLING TO KNOW WHERE TO START BUILDING?

This is exactly the gap the CTRL+ALT+DEFEND Community exists to close. Free content and newsletters can tell you the principle, one certification, then build, but they can't look at YOUR specific certifications and tell you exactly what project would prove them. They can't answer your question at 9pm when you're stuck deciding what to build first.

Inside the community, you get weekly live Q&A with me, direct, not pre-recorded. CV and portfolio roasts. Study groups organised by career path. And every digital product I've built, skill matrices, home lab guides, the CV template, the Interview Preparation Kit, included at no extra cost.

For less than the price of a few coffees a month, you get ongoing, direct access to someone who has spent over a decade hiring for these exact roles, and who can tell you specifically what to build next.

Join here: https://www.skool.com/cybersecurity-careers-guide-1773/about

If you audited your CV just now and found more certifications than projects, forward this issue to yourself for next weekend. That's when the fix happens.

See you next week.

Marius Poskus Global VP of Cybersecurity / CISO CTRL+ALT+DEFEND

→ YouTube: youtube.com/@mpcybersecurity

→ Skool Community: https://www.skool.com/cybersecurity-careers-guide-1773/about

→ LinkedIn: linkedin.com/in/marius-poskus

→ Website: mpcybersecurity.co.uk

→ TikTok: @mariusposkus0

Next
Next

Issue #4 — The LinkedIn Strategy That Gets Recruiters Messaging You