What does it actually look like to break into InfoSec from the outside, with no technical background, no industry contacts and no idea what half the acronyms mean?
Welcome to Razorwire, the podcast where we share our take on the world of cybersecurity with direct, practical advice for professionals and business owners alike. I'm Jim and in this interview episode, I'm joined by Irina Sordiya, a GRC and compliance professional based in Montreal who came into information security from a finance background.
Not everyone who works in information security started out in IT. Irina's route in began at a career fair where she stumbled into a fintech startup looking for someone who could translate financial regulation into language a dev team could understand. From there she moved into auditing at KPMG and eventually crossed to the other side, leading security posture and compliance in-house.
This is a conversation for anyone considering a career in InfoSec or in the early stages of one. Irina talks openly about feeling like an outsider, not understanding the acronyms and slowly realising that GRC isn't about technical knowledge, it's about understanding risk, building trust and communicating with people. She and Jim also get into the growing problem of grifters in GRC, where Canadian regulation is heading and why the InfoSec community is one of the most welcoming places to build a career.
Three key talking points:
If you're thinking about getting into InfoSec or wondering whether you belong, this conversation is for you.
On what she'd tell herself on day one:
"I would have told myself not to be scared going into this and that there will be always helpers along the way who care about what they do and put ego on the side."
Irina Sordiya
Listen to this episode on your favourite podcasting platform: https://razorwire.captivate.fm/listen
Hello, I am James Rees, the host of the Razorwire podcast. This podcast brings you insights from leading cyber security professionals who dedicate their careers to making a hacker’s life that much more difficult.
Our guests bring you experience and expertise from a range of disciplines and from different career stages. We give you various viewpoints for improving your cyber security – from seasoned professionals with years of experience, triumphs and lessons learned under their belt, to those in relatively early stages of their careers offering fresh eyes and new insights.
With new episodes every other Wednesday, Razorwire is a podcast for cyber security enthusiasts and professionals providing insights, news and fresh ideas on protecting your organisation from hackers.
For more information about us or if you have any questions you would like us to discuss email [email protected].
If you need consultation, visit www.razorthorn.com, We give our clients a personalised, integrated approach to information security, driven by our belief in quality and discretion.
LinkedIn: Razorthorn Security
YouTube: Razorthorn Security
TikTok: Razorwire Podcast
Instagram: Razorwire Podcast
Twitter: @RazorThornLTD
All rights reserved. © Razorthorn Security LTD 2025
For a very long time, I felt like an outsider in the field.
Jim Rees:Many, many years ago, nobody wanted to speak to the security people. They really didn't. You could almost see them groan around the room.
Irina Sordiya:I didn't realize that if something isn't working, I can't say that's an exception. See you next year. Because now that's an exception. I'll see you next week.
Jim Rees:AI is going to be a part of life. It is now possible that we will actually have the AB through AI augmentation to be able to do more with our time in a more efficient way.
Irina Sordiya:Infosec is becoming more commercialized, I feel, because now all these different standards, they're fighting and it's becoming almost like a marketing fight between them, a regulatory race to become the regulation. G is for Grifter and grc. And that is just something that is just something that I've been really noticing.
Jim Rees:You've got all these people now coming up with AI agents that they say, oh, this can replace the ciso. It's like, what? Sorry.
Irina Sordiya:I think it takes a very specific mindset and skill set. I think the right people will always find their way into the infosec.
Jim Rees:Welcome to the Razer Wire podcast, where we discuss all things in the information security and cyber security world, from current events and trends through to commentary from experts in the field, providing vital advisory on what it is to work in the information security and cybersecurity space. And hello, welcome to another edition of the Razor Wire podcast.
Now, today, we are doing another one of our fantastic interviews where we bring on old school people who've been in the industry for a long time, people who are interested, have interesting jobs within the industry, people from different diverse backgrounds and locations around the world. And today I have brought on Irina to kind of tell us a bit about herself and her journey in InfoSec.
Because I've seen a lot of fantastic commentary on LinkedIn. She's followed the channel seemingly for a while. It was very nice. Some of the things that she mentioned just before we got on camera.
And indeed, she's been very supportive on LinkedIn as well. So without further ado, I'd like to introduce to Irina. Irina, do you want to tell everybody who you are? What do you do?
Irina Sordiya:Yeah. Thank you so much for such a nice introduction and very happy to be here on the podcast. I have been following for a while. Love the content.
So it's been great to be invited to join and kind of share a little bit about the journey that I've been on my Journey into the infosec started from finance and the job market was tough because when is it not tough? And I think one of the ways that I was able to even get my first job was I went to a career fair that was finance technology.
And at the time somebody told me technology is really booming here in Montreal. I'm based in Canada, Montreal. And so maybe try your luck in a finance technology place.
And I went there and I had no idea about anything it, anything, technology, anything SaaS. And I just kind of went there with hopes. And I saw one of the startups there, it was big data in capital markets, management startup.
They were looking for a business analyst. And I didn't know what that was, but I thought business analyst is something maybe I could get in there.
And I went there and I started talking to people at the booth and I think they also didn't know what the role was. And somehow I got connected to somebody and they asked me, do you know anything about finance?
We need somebody who translates finance regulatory things to our dev team. And that's. I knew that and so I got in. And from there the road kind of took me more and more deeper into IT and technology.
And then the longest part of my career has been auditing. So it was all the infosec audits at kpmg. And then I went to the dark side. I exited into the industry.
And so currently what I do at my role, I lead the security poster at the company. So multiple different audits. There's SOC1, there's SOC2, different ISOs. And we're going through a few more rigorous Government of Canada programs.
But it's been a very long journey from finance into infosec and a lot of learning and kind of making up for the lack of the technical background and skills and a lot of sitting quiet in the room and trying to kind of absorb and writing down different words and what is seem, what is this, what is that? I didn't know any of that. What is sdlc? And then I would Google it afterwards and try to figure it out many, many years ago.
So that' kind of the overview of the journey.
Jim Rees:I don't think you ever kind of get to grips with all the acronyms in this industry. We have so many and they're always creating new ones. I mean, it is crazy.
And it's interesting to see that, you know, somebody who's come in from the finance side as well. You know, my journey in was obviously very much more technical.
I've now spoken with these kinds of interviews with People who've got in from legal and all the rest of it. But from a finance perspective, it must have set you up pretty nicely for things like the risk management side of things and obviously the auditing.
Because, you know, a role in finance is very cut and dry. It's like, are you doing this or are you doing this? If you're doing this, then it's you, you have to do this.
There's a lot of legal requirements as well within finance. Did you find that kind of set you up really well for that GRC and that audit capacity that you have been doing?
Irina Sordiya:I'm not sure about so much because I was fresh out of my studies in finance so I never really got real world experience. It was all very much like book and modeling the markets. I think I've shared this previously before.
For a very long time I felt like an outsider in the field. Like I just kind of happened to fall into the field even during my interview for auditing.
They just really needed somebody with a bit of background here and there. And they asked me, do you know what this role is? And I said, are you checking security of the passwords? And they said, yeah, yeah, pretty much come.
For the longest time, I think I just kind of really struggled with the technical part of things and I thought maybe I don't really belong here until I started picking up enough to understand how the processes works and maybe challenge some moments here and there.
But I did start to see the value of the GRC side of things and the compliance and how much of what information security is, is having soft skills and people skills.
Jim Rees:Absolutely, 100% agree with you. You know, I mean, again, I came in from the IT angle and it was kind of almost a little bit harder to transition into the grc.
I mean, when I first started getting into that, it was still very early days. I mean, policies and procedures were very, very young is probably the best way to describe it.
And God help you, if you wanted a GRC tool, there was no way that you could find one of those on the market. And if you could, they were hideously expensive. It's heartening to see that people from all kinds of different backgrounds can get in.
And I'm sure it's not easy.
You know, it never is, as you say, you know, trying to understand the more technical aspects when you come from a non technical background can be pretty, pretty harsh. It could be pretty hard going, but you can get there.
And indeed, today there are so many different roles within the infosec field that you don't have to have technical knowledge. It helps, don't get me wrong, you know, but there is a route in for people who don't have that background.
Tell us a bit about what you do now, today, then, you know, what does the average day look like for yourself?
Irina Sordiya:I will talk a little bit about the experience of even transitioning into a fully inside the industry GRC role, from the auditing role to kind of give you a snapshot of what I do today, I think, because I'm still kind of orienting myself even though I've been in this role almost two years. I think when I came from the auditing role into this role, I didn't realize that if something isn't working, I can't say that's an exception.
See you next year. Because now it's. That's an exception. I'll see you next week. And so this is kind of the reality of every day.
It's working with many, many different stakeholders and touching upon different departments and trying to understand the continuous process and what the people are doing and what kind of controls do they have in place and acting as an advisor and just documenting like there is. There's no tomorrow.
So I think the average day in my life looks like looking through customer requests, preparing for many different audits, handling different departments, and just sticking to the calendar of all the pen testing, disaster recovery, internal audit, and just kind of keeping ahead of all of these things that are happening.
And then also kind of being a part time, I don't want to say therapist, but a part time, I don't know, emotional support for a lot of different departments. Because I do feel like people often rely on the GRC team when things aren't happening the way they should.
They come and they ask for advice and they rely on you to kind of provide some guidance.
Jim Rees:But that's a good thing. I mean, many, many years ago, nobody wanted to speak to the security people. They really didn't.
You know, it's like when you walked in the room, especially if it was like going into a project that was working and they needed some guidance, you could almost see them groan around the room. It's lovely to hear that.
There's like a different angle nowadays where people have problems with meeting the GRC requirements or the legislative requirements and they're actually coming to you and saying, look, how do we do this?
You know, rather than go away and I don't have time for this, are you finding it a very positive kind of engagement with yourself and the people that you facilitate?
Irina Sordiya:Yeah, I think that's something that I'm used to as well.
When you come around and the, the auditor is here and it takes, maybe that's something useful that I learned from my previous role is the importance of building that, the relationship and trust so that you're not seen as this great book describes the man. So when I just joined the role, somebody came up to me and they said, oh, they must really hate you. And I was so confused.
And they said, well, you come and you shake your finger and you say, no, no, no, that's not how things are done. And so it does take some time to build that trust.
And I think it's really important to have empathy, but it's definitely streamlining a lot the process once that empathy is and trust established to make things go faster.
Jim Rees:No, you're absolutely right. You know, I mean, at the end of the day, people are trying to get things done.
They're under stress and pressure to make sure that they're meeting their deadlines. One of the interesting things that I wanted to kind of find out a little bit about from yourself.
I mean, we've got a lot of legislation starting to crop up all over the place.
Place here in Europe, we have Dora, we have NIST2, we've got the UK equivalents, we've got GDPR, we've got all the kind of legislation that's coming up just over here. What's it like in Canada? Are they still working on it or are you starting to find that the legislation is getting really tougher?
What's your kind of view on how things are?
Irina Sordiya:I think just even in the past, Canada has always oriented itself around the neighbors and what the neighbors are doing. So in Canada, the main infosec certification slash attestations have been the ISOs or the SoC one, the SoC two.
And even when it comes to the AI governance, it's funny because originally Canada was supposed to be the first country to have an AI governance policy and then it kind of got scrapped. And there were so many, many great things that were happening in Canada around AI.
And for some reason there were some, there was some stalling and now a lot of the companies orient themselves around eu, AI Act.
Jim Rees:Really?
Irina Sordiya:Yeah. And so that's something that I see a lot cropping up in enterprise questions from customers.
I'm seeing more often the ISO:That's kind of the standard that's around in Canada right now, we just orient ourselves and kind of orbit around other regulatory establishments.
Jim Rees:That's good because I'm going to upset some of our American viewers here.
ou audit, especially with ISO:I mean, I'm a PCI, DSS, QSA, good example. And it's very black and white. It's like you either do this or you don't. And what do you do about this? What do you do about that?
But things like ISO and some of the sort of more European centric stuff, it's like, well, you need to define how you're going to do this. You know, you need to be able to show that you are treating security seriously.
It's not a hard and fast set of rules because I don't know what you think, but, you know, you were in kpmg, so you saw a lot of different environments and there's no one hard, fast way of kind of putting security into any particular business. And every business seems to be very individual, even some of them when they're in the same sector. It's. There's a lot to do with culture.
And it sounds like you've really got the culture thing down if you've got people coming to you, because that's not always happening over here in the uk, I could tell you that. I mean, you mentioned the, the, the AI legislation at the moment. You know, we've got 42,001, and you mentioned that you had. Somebody was scrapped.
What happened there?
Irina Sordiya:I tried looking into this and I tried to kind of figure out what exactly. Why is it that we were making such leaps and investing before the AI craze?
You know, Canada was all about the AI and putting massive funding into the researchers, and then all the researchers went to us. That's a story. That's the story all this time for Canada as well, but I'm not sure.
They just said there was reshuffling in the government and that initiative has been paused and now it's not coming back around. So it's unfortunate, but I think Canada has some way to go to carve out their own place in the world.
Jim Rees:I don't think it's just Canada in all honesty. I mean, it's. I think it's the same.
You know, a lot of people are scrapping a lot of legislation or they're holding back on the legislation because everybody really wants to be first with the next version of AI, the free thinking AI. You know, AI agents are going crazy at the moment.
I mean, that's one thing that I think all of us infosec people are kind of a little bit worried about at the moment because everybody seems to be doing everything all at once. Are you finding that over there? I mean, is it hard to kind of keep up with what's going on?
Because every time I go to sleep and then wake up, there's something new that's happened. And all of a sudden we have to start remodeling our grc.
We have to start looking back through the decisions that we've made and we have to start re keying for a new future. Because AI is not slowing down. If anything, the development behind it is speeding up.
Are you finding the same thing or am I talking complete crazy talk?
Irina Sordiya:No, absolutely. I think every day something new happens and then every day, oh, sandboxing used to work, now sandboxing doesn't work.
And then, you know, there's models that are too dangerous to be released to the public and there's a massive panic.
And everybody loves talking about this, but I do feel like there's so many, many different things happening and there is almost a regulatory race to become the regulation. I do feel like.
And I mean, I think this touches on something that I've been observing, which is infosec is becoming more commercialized, I feel, because now all these regulatory bodies and all these different standards, they're fighting and it's becoming almost like a marketing fight between them. Who will be the standard? Which standard are we going to use for AI and now for AI agents?
And then this proliferation of regulatory needs and escalating compliance, I think it creates a lot of questionable things or things that are kind of repetitive. The other day I was reading a 20 page report from a very credible university arguing the smallest point that's already kind of known anyway.
And it's just very strange for me that there's just so much stuff that's being created and not like true essence of things.
Jim Rees:So, well, this is it.
I think a lot of people are frightened that, you know, by putting in legislation, by putting in security concerns or things that you need to make sure are secure, it's going to in some way prevent them from developing the next groundbreaking AI model. And you mentioned before, we've now got AI models that are specific to cyber security. We got Daybreak, that was recently released from OpenAI.
Obviously we've got Mythos, which was the one from Anthropic, but no doubt we'll see one from Grok, we'll see one from all the others.
And I'm interested in seeing where this is going and it'd be interesting to get your view because we've got the large language models, everyone's using it. I mean, you see it all on LinkedIn. Everybody's writing posts utilizing AI prompts. Everyone's now answering those posts with AI prompts.
So everybody seems to have completely lost the ability to think. But AI is going to be a part of life.
It is now possible that we will actually have the ability through AI augmentation to be able to do more with our time in a more efficient way.
Because I remember a time when if you wanted to find out what was going on in a firewall event log, I'd have to spend three or four days just looking through logs, which I don't need to do anymore. I can get the AI to do it and it can do that analysis quickly in a much quicker way than I could.
Because trust me on this one, and you've been an auditor, I'm sure you've probably had to do the same thing. When you're working on, for the sixth hour on looking through something, you get tired, you lose track of where you are.
You can't concentrate anymore. It's like this document, I just want to throw it in the bin. I've had enough of reading it.
Is this the kind of experience you're experiencing with it as well? I mean, where do you think AI could be a benefit to us in security?
Irina Sordiya:Absolutely. I, I'm not. I am a technological optimist. I do love, you know, the new developments, the new technology that's available.
I see massive benefits from AI, one of which is the logs. You know, it's a love hate relationship where all the auditors and their logs.
So much of what we do is documentation and kind of like grunt work almost in a way. And I think so much of that can be.
I don't think AI is coming to take the infosec jobs because so much of information, security, strategic thinking and kind of thinking in advance and so much of it, of the, the smaller or more crucial work can be alleviated with, with AI as long as it's done responsibly. But I do think there is massive benefits for our sector to benefit from that.
Jim Rees:I think you used a really interesting term there of if it's done responsibly and I agree with you, but history tells me it's not. Yeah, it can be such a big benefit. It can be such a big problem. We're already starting to see a lot of changes in, just in the economy.
I mean, you know, we look online now and it's like there's a lot of organizations that are taking away those lower end jobs where, I mean, I'm sure that when you first got in there was a lot of analytics, there was a lot of following around other auditors and sort of, you know, learning, as you say, going through massive log stacks and all the rest of it. But with AI now we won't need people to do that.
And I'm just a bit concerned in this industry that that lower end job role, if it disappears, how are we going to bring new people in? How are we going to have them understand what it is to be in information security if they're not doing at least that analytics job?
Because it's all gone now. After your generation of infosec people, are we even going to have any infosec people? Because what's the learning process?
What's it going to look like?
Irina Sordiya:I learned quite a bit through, you know, digging into those logs and kind of doing the sampling and the populations and whatnot and.
But I think I really can't comment on it too much because I'm not so in the know about, you know, how do we train and what happens in the future, but I think the right people will always find their way into the infosec. I think it takes a very specific mindset and skill set.
One of the best advices I've gotten when I just started working was I asked how can I be good at this job? And I was told you need to have the risk mindset. And that has been kind of the North Star that's been guiding me.
So even when I'm really deep into the procedures and the compliance, I can always take a step back and I can ask myself, but what is the risk?
What am I actually trying to address here so I don't get bogged down into the checklist or a hundred page policy that nobody reads when an incident actually happens. I know this doesn't answer directly the question what will happen and how do we train the new wave of people?
But I do, and maybe I'm just quite optimistic generally, but I do think the right people will find their way into the field.
Jim Rees:I think that's a fantastic way of looking at it. It's good that there's, there's is still sort of hope because I'm seeing a lot of, I'm seeing a lot of concern, for instance, in the legal sector.
I know that they're now using a lot of the AI to analyze cases and all the rest of it. And there's a lot of older solicitors, you know, who are kind of coming to the twilight of their career.
They want to retire, They've, they've made the money, they've done their work and a few of them are saying, well, who's, who's coming into this industry? We don't have the case. People working on like 15 lawyers working on cases.
And even in the financial industry there's a significant concern because one of the first jobs you do if you're an accountant is you go pore over the books, you learn how it all works, you use technology, but you don't let the technology do it for you. There's still an element of understanding that you develop over time.
So maybe it's just as you say, maybe it's just an evolution and old people like me can't figure out how it's going to work going forward because I'm too far removed from it.
So I love your answer and I love that idea around the risk mindset and I think that's quite an important piece for any up and coming people to understand that you do have to understand risk, you do have to understand how to calculate risk in order to be able to communicate to say the board or project managers or whoever. It may well be that if you take this action then we need to look at what could feasibly happen.
What's the worst case scenario, what's the most likely scenario so we can actually make a clear, concise decision on what we want to do. Do you find that it's easier in modern companies to do that than it feasibly was to when you first started? Have you seen a diff. Definite change?
Irina Sordiya:It just makes me remember this one time when I used to audit and it was in the very beginning of my career, I knew that the customer wants a report because they're beholden to their clients. And so, and they often want a clean report or you know, a nice looking one.
So then they can tell them, look, dear client, we're so good at everything we do. And I had the team once tell me when it was just me and the compliance team, they told me they want me to fail them in certain controls.
And it was very unusual for me. And I was trying to understand because from that perspective, I didn't understand, you know, the. All the mechanics of an organization.
And I think they were trying to use that as a way to kind of get some semblance of control or power.
I think they were so kind of boxed into, you just do this, you do, as we say, that they really needed somebody to kind of come in and help them have some, some say in how security is done. And do I see change in that? It really depends on the culture of the organization and the company. I can't say there's been a massive change or not.
Some of it does lie on our shoulders.
Like we do have to kind of, you know, make things happen and be able to translate the risk and not come around slapping everybody with our standards and with our policies, like the policy, you know, not be that rigid kind of person. But I think it depends really on the culture and the mindset of the people in the management positions.
Jim Rees:I do a lot of work all across Europe and offshore locations, you know, and everywhere is different. Everywhere has a slightly different mindset. You know, the people in Germany have one way of working. People in France have a different way.
You go down to Spain, everyone's a lot more relaxed, you know, and it's, it's important that when you build your security and your GRC components within an organization to take that culture into consideration.
And then, you know, you have subcultures as well, and sometimes you have people with access to grind and some people you have who are very hostile towards security. And it's. It sounds like you've done a really good job breaking a lot of the problematic things that we find in information security down.
Based on what you're seeing in today's world with infosec, do you think we're going to have some difficulty adapting to the speed of change? Do you think that things are going to get better going forward and it's going to get easier to do the job that we do?
What are your thoughts on the next maybe two or three years of infosec from what you're seeing over in your neck of the woods?
Irina Sordiya:There are a few trends that I've been noticing, but one that I've been kind of making a little joke in my own head is G is for Grifter and grc. And that is just something. That is just something that I've been really noticing, especially with de escalating regulatory pressure.
I think real practitioners were just kind of. So in theory, we're thinking about all these things. We're kind of trying to look forward.
You know, I caught myself one time discussing in the comments section, do we use Roman numerals for our SoC1 or Sock2? Or do we say, and what's the spacing? How do we use that? And then I was like, what am I doing? Just what.
You know, I'm so, like, bogged in all these details.
Whereas I think there's so much noise that's outside of the little pockets of GRC circles that say things like, you want to break into cybersecurity, you don't want it bad enough, you need to hustle harder. And here's my guide for $100 to get into cybersecurity. And it's just. It's just all these things.
Or here's my template that I made with Claude to get you started with your audit. And it's a very strange place to be because I thought the industry was so niche. How come it's happening?
And I just think because there's so much, so much need for this now, and there's so much need for infosecond compliance, it just creates that space for some of these things to happen.
Jim Rees:I couldn't agree with you more. And it's something that I've noticed time and time again.
You've got all these people now coming up with AI agents that they say, oh, this can replace the ciso. It's like, what? Sorry? I mean, the AI agent may be very good at analysis.
It might even tell you some good stuff about what's going on in the environment. But it doesn't supply you with wisdom. It doesn't supply you with knowledge or context, because it doesn't understand that kind of stuff.
I think the grift has been happening for a little while over here and over in the States and up in Canada and a few other places around the world, because people see the writing on the wall that we are in a state where technology is going to require a good level of security, because if we don't secure it, it's going to be worse. But inevitably, you get the people who come out and they're all trying to earn money.
I mean, I love it when I get comments on the podcast because a lot of people say, oh, you know, I really learned from your guests. You know, I've learned about something that I wasn't too aware of.
I haven't ever dealt with that in that side of infosec and it's really heartening to hear that, you know, there's still places you can go where you can get some decent info. But we do have the Grifters and they will offer you that 1,000 pound course to learn. Don't, don't do it, guys, don't do it.
cism, do your, you know, ISO:So I have my final question to you. This is a question I ask all of my guests. Don't worry, it's not that scary. Let's take you back.
Maybe, you know, the day that you found out that you got your first role in cybersecurity, maybe you were in a bar having a glass of wine, thinking, oh, you know, when am I going to get the call? You got the call. You've just got the call that says, brilliant.
ditor and learn all about ISO: Irina Sordiya:I would give myself that same advice.
You know, you have to know what the risk mindset is and it becomes very, very interesting very fast when you start to talk with different stakeholders and you will discover that the people in the industry are very lovely. I think most infosec professionals, I find them to be very wonderful people. I've made many great friends.
I don't know what it is about the profession that kind of brings together people who love to share, who don't gatekeep, who are so friendly and very passionate about what they do, even though it's quite so niche, we can talk about all these little details.
So I would have told myself not to be scared going into this and that there will be always helpers along the way who care about what they do and put ego on the side. I would have told myself to just have fun and learn and not to be scared.
Jim Rees:That's a fantastic answer. That's a fantastic. And we do have a good community.
Yeah, we've got a few people in it that are interesting and you do see the occasional argument kick off. I think a lot of it is we're kind of on the outliers in security. Quite often we do deal in sometimes very negative things.
We have to, we have to analyze negative outcomes and find interesting solutions to try to reduce that risk or transfer that risk or remove that risk if it's entirely possible. We're used to kind of getting a lot of pushback.
So infosec people as a whole kind of understand what it's like to experience that and none of us want to inflict that as a general rule on each other. So we are a great community and it's lovely that you recognize that.
I think it's one of the only places where you can go on LinkedIn or wherever LinkedIn is, the normal one, and say, hey guys, has anyone got any experience with this? What are your thoughts?
And you'll get 250 comments, you know, underneath most of them will be nice, you'll get an occasional person, but people will be like, oh well, what context, you know, what are you looking at, how you're doing it and all the rest of it. And I, I can't wait to see how things go with your career. I'm reaching the fast, reaching the end of mine. I'm getting old.
But I think, you know, we've got a safe hands with your generation and if any of you out there are looking to kind of get into infosec speak to speak to people, they are very friendly and you can always DM all of us and we'll be more than happy to help. So thank you ever so much for the interview. It's been really, really, really enlightening. It's been fantastic.
Now to all of you out there, thank you ever so much for watching this interview. It means a lot to all of us with the amount of new subscribers we've had and the amount of views that we've had. So please like and subscribe.
Click the notification button so you can be told when we release new content. We've got the razor wire raws, which is our short form content which we release usually twice a week unless I missed out on something.
Then we have podcasts and the interviews which you know, we do on a bi weekly basis. Please comment if you want to DM me. Feel free to. I'll try to get through them all.
I get quite a few these days and I'll try to do any content that might work. But for now, thank you very much to my guest. Look after yourself and we'll be seeing you again soon.
In addition, I do have a book recently come out, the Cyber Sentinel's Handbook, a primer for information security professionals.
Now this book is very much geared up towards professionals, all levels of their career, be they starters, be they newcomers, be they people have been in it for a little while and maybe looking for a little bit more direction, albeit the older ones looking to maybe reground themselves in some of the more important aspects of the trade that maybe they've forgotten over time. Time I've had lots of good feedback from a lot of different readers at lots of different levels. So please feel free to get yourselves a copy.
We've got the E copy, we've also got the paperback copy, and if you don't want to spend any money, you can go on Kindle Unlimited and read the book for free there as well. Thank you ever so much. Again, look after yourselves and we'll be seeing you again soon.