May 11, 2021 By Brian Rhoades Cybersecurity Certifications, Industry News

The Colonial Pipeline attack happened last week. Before that it was a meat processor. Before that it was a hospital system. Before that it was a city government. If you are paying attention to security news right now, ransomware is not a background threat. It is the threat that is actively affecting critical infrastructure, disrupting essential services, and costing organizations real money every single day.

I want to talk about what this means for IT professionals from a skills and certification standpoint, because the practical reality of ransomware as a normalized operating condition changes the conversation about what knowledge actually matters.

Incident response is the most directly applicable skill set. Ransomware attacks follow recognizable patterns: initial access, lateral movement, privilege escalation, data exfiltration in some cases, and then deployment of the encryption payload. Understanding that kill chain and knowing how to detect, contain, and respond to it at each stage is the difference between an organization that recovers in days and one that is down for weeks. The CompTIA CySA+ covers incident detection and response in a way that is directly applicable to this threat category. The Security+ provides the foundational concepts. The CySA+ builds the applied skill on top of that foundation.

Backup architecture and recovery planning deserve more attention than they typically get in certification study material, but they are increasingly relevant. Ransomware has gotten sophisticated about targeting backup systems specifically because backups are the primary recovery mechanism. Organizations that had inadequate backup immutability, poor offline backup practices, or untested recovery procedures have found out the hard way that their backup investment did not protect them the way they thought it would. This is infrastructure design knowledge that maps to a range of certifications but is most directly addressed in the disaster recovery and business continuity content within CISM and in some cloud architecture exams that cover resilient design.

Network segmentation skills are directly relevant to limiting lateral movement once an attacker has initial access. The CCNA and CCNP security content around network segmentation, micro-segmentation, and zero trust network architecture addresses exactly the controls that limit how far a ransomware infection can spread once it is inside the perimeter. Cisco’s current certification details are at the Cisco certifications page.

The endpoint detection and response space, which is where a lot of the practical ransomware detection work happens, does not have a single dominant certification yet. The CompTIA Security+ and CySA+ both cover endpoint security concepts. Vendor-specific training from EDR platform providers is often the most directly applicable preparation for working in that space professionally.

There is a career point here too. Cybersecurity has been a growth field for several years. The ransomware epidemic is intensifying the urgency around filling security roles that have been understaffed in most organizations for a long time. If you have been considering a move into security or a deeper investment in security skills, the labor market for those skills is going to remain strong for the foreseeable future. Build the credentials that reflect the real threat landscape and you will not have trouble finding a place to apply them.

Brian Rhoades

Brian Rhoades is a Senior VMware Instructor and IT veteran with more than 15 years of hands-on experience in virtualization, systems engineering, and cloud infrastructure. He has trained thousands of IT professionals to confidently work with VMware vSphere, vSAN, and NSX, and has authored multiple books and study guides for outlets across the industry. Brian has a habit of being somewhere new every few weeks, which if you've ever tried to pin down a good VMware instructor, explains a lot.