[{"content":"","date":"31 July 2026","externalUrl":null,"permalink":"/tags/cybersecurity-career/","section":"Topics","summary":"","title":"Cybersecurity Career","type":"tags"},{"content":"Every article belongs to one primary editorial track:\nBuild — creating systems with security in mind. Break — testing assumptions and understanding failure. Defend — detecting, investigating, and responding with context. Journey — documenting learning, progress, and professional development. Commentary — perspectives on security practice and the wider industry. ","date":"31 July 2026","externalUrl":null,"permalink":"/categories/","section":"Editorial Tracks","summary":"Every article belongs to one primary editorial track:\nBuild — creating systems with security in mind. Break — testing assumptions and understanding failure. Defend — detecting, investigating, and responding with context. Journey — documenting learning, progress, and professional development. Commentary — perspectives on security practice and the wider industry. ","title":"Editorial Tracks","type":"categories"},{"content":"","date":"31 July 2026","externalUrl":null,"permalink":"/categories/journey/","section":"Editorial Tracks","summary":"","title":"Journey","type":"categories"},{"content":"","date":"31 July 2026","externalUrl":null,"permalink":"/tags/learning-journey/","section":"Topics","summary":"","title":"Learning Journey","type":"tags"},{"content":" Removing the black boxes # I spent years working in IT while many of the systems underneath still felt like black boxes.\nMeteSec is where I make that journey visible: connecting secure engineering, offensive security, and cyber defense through practical work and deliberate reflection.\nExpect technical deep dives, selected projects, commentary, and honest accounts of what worked, what did not, and what I learned along the way.\nBuild systems with security in mind. Break assumptions before adversaries do. Defend with context.\n","date":"31 July 2026","externalUrl":null,"permalink":"/","section":"MeteSec","summary":"Removing the black boxes # I spent years working in IT while many of the systems underneath still felt like black boxes.\nMeteSec is where I make that journey visible: connecting secure engineering, offensive security, and cyber defense through practical work and deliberate reflection.\nExpect technical deep dives, selected projects, commentary, and honest accounts of what worked, what did not, and what I learned along the way.\n","title":"MeteSec","type":"page"},{"content":"","date":"31 July 2026","externalUrl":null,"permalink":"/series/metesec-journey/","section":"Series","summary":"","title":"MeteSec Journey","type":"series"},{"content":"","date":"31 July 2026","externalUrl":null,"permalink":"/tags/network-security/","section":"Topics","summary":"","title":"Network Security","type":"tags"},{"content":"","date":"31 July 2026","externalUrl":null,"permalink":"/tags/offensive-security/","section":"Topics","summary":"","title":"Offensive Security","type":"tags"},{"content":"","date":"31 July 2026","externalUrl":null,"permalink":"/series/","section":"Series","summary":"","title":"Series","type":"series"},{"content":"","date":"31 July 2026","externalUrl":null,"permalink":"/tags/","section":"Topics","summary":"","title":"Topics","type":"tags"},{"content":"Before I started studying for my first certification, I did something that was probably both useful and slightly insane.\nI researched almost the entire certification ecosystem.\nBefore answering a single practice question, I looked at the different providers, their certification paths, how employers viewed them, how useful their content appeared to be and where they seemed to fit into an actual IT or cybersecurity career.\nI looked at CompTIA, Cisco, Microsoft, AWS, ISC2, ISACA, OffSec, GIAC and many others. I compared entry-level certifications, professional certifications, technical certifications, management certifications and certifications that seemed to exist mainly because companies like putting logos into job descriptions.\nI ranked them for myself.\nWhich ones seemed valuable for HR?\nWhich ones appeared technically useful?\nWhich ones had practical exams?\nWhich ones were respected by people actually working in the field?\nWhich ones built on each other?\nWhich ones looked impressive but probably would not teach me much at my current level?\nI had probably researched half of the certification internet before I had properly started learning for one exam.\nAnd every time I learned more about the ecosystem, I changed my roadmap again.\nThe Five Roadmaps Before the First Exam # I made at least five different certification roadmaps.\nThe first one was probably terrible.\nThen I found new certification providers, read more discussions, watched more videos and realized that some certifications I had originally considered important did not really fit what I wanted to learn.\nSo I changed the roadmap.\nThen I understood a little more about the difference between cloud security, offensive security, defensive security, governance, networking and general IT.\nSo I changed it again.\nMy focus kept shifting because I was only slowly finding out what I actually wanted to know. At the beginning, I did not even have enough knowledge to design a good learning path. Researching the ecosystem was therefore already part of the learning process.\nLooking back, this was a very long way to begin. I could probably have asked someone experienced and received a reasonable roadmap within twenty minutes.\nBut I did not really have someone who could show me the full path.\nSo I built one myself.\nThe basic idea behind all versions of the roadmap stayed the same:\nI know almost nothing compared to what exists, so I should start at the bottom and work my way upward.\nI did not want to jump directly into an advanced certification, memorize the content required for that exam and then still have enormous gaps underneath it.\nI wanted to move through the layers.\nGeneral IT first. Then hardware, operating systems, troubleshooting, networking, servers, security, cloud and eventually more advanced offensive and defensive security.\nThe plan was ambitious, inefficient and probably much larger than necessary.\nBut it was a plan.\nAt that point, I felt that I had two options: either I would finally start properly and follow the path through, or I would continue collecting random pieces of knowledge for another few years.\nI decided to start.\nStarting at the Bottom # I began with foundation-level certifications such as IT Fundamentals+, Cloud Essentials+ and Tech+.\nI had already worked in IT before that. I had been a working student in first- and second-level support, had started my first full-time position and later switched roles inside the same company.\nBut I had not completed certifications during that period.\nMy certification journey really began after I moved into consulting for the first time.\nThe early certifications were not extremely difficult compared to what came later. Their purpose was also not to impress anyone.\nI used them to check my foundation.\nI wanted to see which areas I actually understood and which ones only felt familiar because I had heard the terminology before.\nThere is a large difference between recognizing a concept and being able to explain how it works.\nThat difference became very clear once I reached A+.\nA+ Connected Almost Everything at Once # A+ was probably the single most important certification in my entire IT learning journey.\nThat may sound exaggerated for an entry-level certification, but for me it is the truth.\nBefore A+, I already had several years of exposure to IT. I had troubleshot devices, changed settings, followed remediation procedures and worked with different enterprise technologies.\nI was able to perform the work.\nBut the knowledge was spread across different jobs, systems and individual problems. A lot of it existed in isolation.\nI knew that changing a specific setting could solve an issue, but I did not always understand why the setting existed there.\nI knew which remediation steps to follow, but I could not necessarily explain the complete path between the endpoint, operating system, network, identity and backend service.\nThere were many pieces in my head, but somebody had thrown the puzzle box away.\nWhile studying for A+, it honestly felt as if around 80 percent of the synapses connected at once.\nAlmost everything I had seen during my working-student role and my first full-time jobs suddenly had a place.\nHardware, operating systems, storage, permissions, authentication, troubleshooting, networking and security were no longer random individual subjects. They became parts of one larger abstraction.\nFor the first time, I felt that I understood IT.\nNot every product, command or implementation. I obviously did not suddenly know everything.\nBut I understood the construct.\nI knew roughly where something started, where it ended, what it depended on and where it belonged.\nWhen I came across a new technology, I finally had questions I could ask:\nWhich layer does this operate on? What does it communicate with? What comes before it? What happens after it? Which part is hardware, operating system, network, application or identity? Where could the process fail? Before A+, every unfamiliar subject could become a new black box.\nAfter A+, I had a framework for opening those boxes.\nThat framework was far more valuable than any individual exam objective.\nNetwork+ Opened the Next Major Door # The next milestone of a similar size was Network+.\nNetworking had always been one of those areas where I knew many individual terms without properly understanding the complete process.\nI knew what IP addresses, ports, DNS, DHCP, routers, switches and firewalls were. I had dealt with connectivity problems and had seen network-related settings throughout my previous roles.\nBut knowing the pieces is not the same as seeing the network.\nNetwork+ gave me the larger model.\nTogether with the framework I had gained from A+, it opened my eyes to an enormous number of other areas.\nSuddenly, applications were not just applications. They were services communicating over networks.\nAuthentication was not just entering a username and password. It involved clients, protocols, identity providers, directories, tokens and network paths.\nCloud was not a magical location somewhere outside the building. It was still compute, storage, networking, identity and software, only arranged and managed differently.\nSecurity tools were also no longer isolated products. They collected telemetry from endpoints, network connections, identities, applications and infrastructure.\nNetwork+ did not turn me into a network engineer. But it gave me the ability to reason through networked systems.\nWhen something failed, I could ask whether the issue existed on the endpoint, during name resolution, in routing, at a firewall, during authentication or inside the application itself.\nThat may sound basic to somebody who has understood networking since childhood.\nFor me, it was a massive shift.\nA+ and Network+ are still the two certifications I consider the most important decisions in my IT learning path.\nThey gave me the architecture in my head that everything else could attach to.\nSecurity+ Gave Me the Enterprise Security Language # Security+ came afterward and helped me understand how security is structured and described inside larger organizations.\nI had already encountered many security-related technologies and processes, but I did not always know the common terminology or how the individual controls were categorized.\nSecurity+ connected subjects such as identity, access control, vulnerabilities, cryptography, architecture, risk management, incident response and security operations.\nIt gave names to things I had already seen and placed them into a broader enterprise-security model.\nThat was useful, but it was still mostly conceptual.\nI understood the language of security better.\nThe first time I felt that I was actually applying security across several areas came with OffSec SEC-100 and the OSCC-SEC exam.\nSEC-100 Was Where Security Became Real # SEC-100 was different from my previous certifications.\nI was no longer only learning concepts, recognizing terminology or selecting the correct answer from four possibilities.\nI had to use the knowledge.\nI spent around three months working through the material and practical labs. At the end, I took a six-hour practical exam.\nThat was the first time I had to perform live hacking during an examination.\nThe experience pushed me forward more than I expected.\nBefore SEC-100, my general IT understanding had already moved much further than my practical security understanding. I could reason about computers, operating systems, networks and infrastructure, but security still consisted of many separate concepts and products.\nDuring SEC-100, I had to connect the system, the vulnerability, the attack, the evidence and the defense.\nI had to interact with the environment instead of only reading about it.\nI had to investigate, test assumptions and produce actual results.\nPassing the exam did not turn me into an elite hacker overnight. No six-hour exam does that.\nBut the three months of preparation and the practical examination moved me forward by what felt like several years of passive learning.\nIt was the point where my security knowledge began catching up with the IT framework I had already built.\nAnd after that, my actual learning journey really started.\nLearning How to Learn # Of course I had learned things before.\nI had studied, worked in IT and gained professional experience.\nBut after A+, Network+ and SEC-100, I finally understood how I personally need to approach difficult technical subjects.\nA+ gave me the general IT framework.\nNetwork+ showed me how systems communicate and depend on each other.\nSecurity+ gave me the common language and structure of enterprise security.\nSEC-100 forced me to apply knowledge and connect offensive and defensive thinking.\nAfter that, complex and abstract systems stopped feeling impossible.\nThat does not mean every implementation became easy.\nI could not immediately configure every product, write every program or perform every attack.\nBut I could understand the architecture and the concept much faster.\nI knew where to begin.\nI could ask:\nWhat is this system supposed to do? Where does it sit in the architecture? What does it depend on? Which data enters and leaves it? Where are the trust boundaries? What can fail? How could somebody misuse it? Which evidence would that activity leave? The applications and products still required work.\nThe underlying concepts no longer felt unreachable.\nThat difference changed everything.\nWas My Certification Roadmap Efficient? # Probably not.\nThere was redundancy.\nSome certifications repeated topics I had already covered. Some exam objectives added little new knowledge. With the benefit of hindsight, I could design a shorter and more targeted roadmap today.\nBut that is easy to say now that I have the knowledge required to design one.\nAt the beginning, I did not know what I did not know.\nThe long route gave me structure when I had none.\nIt exposed gaps I would otherwise have missed and gave me a reason to move through subjects systematically instead of following whatever happened to be interesting that week.\nIt may not have been the most efficient path.\nBut it was a path, and I followed it.\nThat matters.\nWhy I Disagree With “Certifications Are Useless” # I regularly hear people say that certifications do not matter and that only practical experience counts.\nI disagree completely.\nA certification alone does not prove deep competence. Someone can memorize exam questions, pass a test and forget most of the material shortly afterward.\nBut the opposite statement is just as wrong.\nPractical experience without theory can leave you repeating processes without understanding why they work.\nYou may become very good at one product, one procedure or one environment and still struggle when the context changes.\nTheory gives you the models, terminology, architecture and concepts needed to transfer knowledge from one situation to another.\nPractice shows whether you can actually apply that knowledge when the system is messy, incomplete or behaving differently from the textbook.\nFor me, the relationship is roughly 50/50.\nTheory is at least half the job.\nPractice is the other half.\nWithout practice, theory remains abstract.\nWithout theory, practice can become a collection of habits and memorized remediations.\nThe strongest learning happens when both sides continuously correct each other.\nThat is also why I value certifications differently today. I do not judge them only by the badge, difficulty or reputation.\nI ask what the certification forces me to understand and whether I can connect that understanding to real systems afterward.\nWhere I Am Now # My strongest professional area today is cyber defense, especially detection engineering, security monitoring, SIEM, XDR and security operations.\nAt the same time, I continue learning across general IT, networking, infrastructure, cloud, secure coding, offensive security and defensive security.\nI am not trying to collect every certification that exists, even though my original roadmaps occasionally looked as if that was the plan.\nThe certifications are supposed to give the journey structure.\nLabs, projects, writing, talks and professional experience are what turn that structure into actual ability.\nLooking back, the most important result of my certification journey is not the number of certificates.\nIt is that I stopped approaching every new subject as a completely separate problem.\nBefore, I collected knowledge.\nA+ gave it a structure.\nNetwork+ connected the systems.\nSEC-100 made me apply it.\nAfter that, I finally knew how to continue on my own.\n","date":"31 July 2026","externalUrl":null,"permalink":"/posts/the-long-way-around/","section":"Writing","summary":"Before I started studying for my first certification, I did something that was probably both useful and slightly insane.\nI researched almost the entire certification ecosystem.\nBefore answering a single practice question, I looked at the different providers, their certification paths, how employers viewed them, how useful their content appeared to be and where they seemed to fit into an actual IT or cybersecurity career.\nI looked at CompTIA, Cisco, Microsoft, AWS, ISC2, ISACA, OffSec, GIAC and many others. I compared entry-level certifications, professional certifications, technical certifications, management certifications and certifications that seemed to exist mainly because companies like putting logos into job descriptions.\n","title":"Where My Cybersecurity Journey Began","type":"posts"},{"content":"","date":"31 July 2026","externalUrl":null,"permalink":"/posts/","section":"Writing","summary":"","title":"Writing","type":"posts"},{"content":"","date":"31 July 2026","externalUrl":null,"permalink":"/tags/security-culture/","section":"Topics","summary":"","title":"Security Culture","type":"tags"},{"content":"MeteSec started with a fairly simple realization: I understand things much better when I have to put them into words.\nReading documentation, completing a course or working through a lab can create the feeling that a topic makes sense. Sometimes it really does. At other times, you only notice the gaps when you try to explain the same subject without looking at the original material.\nWriting changes the way I engage with a topic. I have to decide what the main point actually is, which details matter and how the individual pieces connect. I have to question whether I understood the reasoning or merely remembered the result. If I cannot explain something clearly, there is a good chance that I have not understood it as well as I thought.\nI first became properly aware of this while writing my bachelor\u0026rsquo;s thesis. The process of researching, organizing and presenting a subject forced me to engage with it much more deeply than reading alone ever had. I have since noticed the same effect when preparing presentations, explaining something to another person or writing down a new insight in a journal.\nThe explanation is not just the final product of learning. It is part of the learning itself.\nThat idea is one of the main reasons MeteSec exists.\nA Place to Make Knowledge Stick # I spend a lot of time moving between different parts of cybersecurity. Some of that comes from professional work, some from certifications, technical labs, books, documentation, conversations and personal experiments.\nThe problem with learning continuously is that it becomes very easy to move straight from one subject to the next. You finish a module, understand it well enough at that moment and then continue. A few weeks later, you may still remember the general idea, but many of the connections and details have already started to disappear.\nI want MeteSec to slow that process down.\nWhen a topic genuinely changes my understanding, I want to capture what made the difference. When I discover that an assumption was wrong, I want to record what I believed before and why I changed my mind. When I work through something technical, I want to explain the reasoning rather than save only the final command, query or solution.\nThe purpose is not to document every hour of studying. That would quickly become noise. The purpose is to preserve the parts that are worth remembering.\nA Journal, but Not a Private Diary # MeteSec is personal, but it is not intended to be a private diary published on the internet.\nI want it to provide a realistic view of an ongoing cybersecurity journey: what I am learning, what I find useful, what I struggle with and how my understanding develops over time.\nA lot of career content is written backwards. Once someone has reached a certain position, their path is turned into a clean story where every decision appears intentional and every step seems to have prepared them perfectly for the next one.\nReal development usually does not feel like that while it is happening.\nInterests change. Some learning paths lead nowhere. Basic topics sometimes turn out to be more valuable than advanced ones. A subject that initially seems irrelevant can later explain something you have been working with for years.\nI want to document the journey while it is still taking place, including the uncertainty and the changes in direction. That may also give other people in similar positions a more useful point of comparison than another finished success story.\nMy View of Cybersecurity # Another reason for creating this site is that I am still developing my own understanding of what cybersecurity actually includes.\nThe field is often divided into separate roles and labels: engineering, offensive security, defensive security, governance, cloud, application security, incident response, identity, vulnerability management and many others.\nThose categories are useful, but the underlying systems do not respect them as cleanly as job descriptions do.\nA vulnerability may begin with a development decision, depend on an infrastructure configuration, be exploited through an offensive technique and only become visible through defensive telemetry. Understanding the full problem often requires knowledge from several areas.\nMy strongest professional background is currently in cyber defense, detection engineering and security operations. At the same time, I am deliberately expanding into offensive security, secure engineering, software security, infrastructure and other parts of the field.\nI do not want to present myself as equally experienced in all of them. I am not. MeteSec should make the difference visible between subjects I know from professional experience, subjects I have tested myself and subjects I am still trying to understand.\nThe broader goal is to identify which knowledge actually helps connect the different parts of cybersecurity and which information is mainly noise, marketing or repetition.\nMore Than a Blog # I also wanted one place that brings my work together.\nArticles are only one part of that. Over time, MeteSec should also contain selected projects, public talks, certifications, technical experiments and a structured overview of my professional background.\nA social-media profile is not particularly good at representing that kind of work. Posts disappear into a timeline, technical discussions are reduced to a few paragraphs and projects become isolated links without context.\nA traditional CV has the opposite problem. It can list a role, technology or certification, but it cannot show how I think about a subject, what I learned from it or how one area connects to another.\nThis site sits somewhere between those two formats.\nThe CV provides the formal overview. The articles show my thinking. Projects show what I have built or tested. Public talks show the subjects I considered important enough to research, structure and present to other people.\nTogether, they provide a more complete picture than any one of those sections could provide on its own.\nWhat I Plan to Publish # The writing on MeteSec will mainly fall into a few broad areas.\nThere will be posts about my learning journey: subjects that changed my understanding, certifications that were more or less useful than expected and lessons that only became clear after practical experience.\nThere will also be commentary on current cybersecurity events, technical claims and industry discussions. I do not want to reproduce the news. I want to look at what is actually confirmed, understand the technical context and then add my own assessment.\nSome articles will be technical deep dives. These will focus on subjects I have worked with, tested or deliberately researched. They may include code, detections, configurations or lab results, but the main purpose will be to explain the reasoning behind them.\nProjects and talks will have their own sections. A project page should explain what problem I was trying to solve, what I built and what I learned. A talk page should preserve the topic, context and supporting material instead of letting the work disappear after the presentation is over.\nNot everything I learn will become public content. The site is meant to be curated, not complete.\nWriting Without Pretending # Publishing technical content creates a temptation to sound more certain than you really are.\nI want to avoid that.\nThere should be a clear difference between a documented fact, something I have personally tested, an interpretation based on available evidence and a personal opinion. When I am still learning a subject, I want to say so rather than write from the position of an expert I am not.\nI also expect some of my views to change. A conclusion that seems reasonable today may look incomplete after more experience or better information. That is not a failure of the journal. It is part of the reason for keeping one.\nThe objective is not to create a permanent record of always having been right. It is to create a visible record of learning how to think more clearly.\nBuild. Break. Defend. # Build, Break and Defend describe the perspective behind MeteSec.\nBuild is about understanding how applications, infrastructure, tools and security controls are created.\nBreak is about understanding how systems fail, how weaknesses become attack paths and how those failures can be explored in authorized environments.\nDefend is about visibility, detection, investigation, response and building controls that work in real environments.\nI currently approach that model from a defense-heavy starting point. The goal is not to force every topic into one of three boxes, but to keep asking how the different sides affect each other.\nMeteSec is the place where I want to collect those connections, strengthen my own understanding and give others an honest view of the journey while it is still unfolding.\n","date":"31 July 2026","externalUrl":null,"permalink":"/posts/making-the-journey-visible/","section":"Writing","summary":"MeteSec started with a fairly simple realization: I understand things much better when I have to put them into words.\nReading documentation, completing a course or working through a lab can create the feeling that a topic makes sense. Sometimes it really does. At other times, you only notice the gaps when you try to explain the same subject without looking at the original material.\nWriting changes the way I engage with a topic. I have to decide what the main point actually is, which details matter and how the individual pieces connect. I have to question whether I understood the reasoning or merely remembered the result. If I cannot explain something clearly, there is a good chance that I have not understood it as well as I thought.\n","title":"Why I Built MeteSec","type":"posts"},{"content":"","date":"9 July 2026","externalUrl":null,"permalink":"/tags/detection-engineering/","section":"Topics","summary":"","title":"Detection Engineering","type":"tags"},{"content":"This keynote opened the IT-SICHERHEIT web conference on detection and response with MDR and XDR.\nAbout the Keynote # Organizations need to identify and handle security-relevant activity across endpoints, cloud environments, and identities. Phishing, compromised accounts, and suspicious behavior rarely stay inside a single technical boundary.\nThe keynote explains how modern MDR and XDR approaches connect detection and response across those environments and where they fit in relation to traditional SIEM-centered security operations.\nThe session covers:\nthe development from SIEM toward MDR and XDR; typical architectures and data sources across endpoint, cloud, and identity; practical factors for evaluating providers and operating models; the role of automation and AI in security operations; common implementation and operational pitfalls observed in projects. The central question is not which acronym is newest. It is how an organization can build security operations that match its risks, available expertise, resources, and need for external support.\nWatch and Explore # Presentation\nMDR \u0026amp; XDR: Moderne Security Operations verstehen 13 slides · Self-hosted viewer · 1.45 MB\nDownload PPTX Previous 1 / 13\nNext 1 2 3 4 5 6 7 8 9 10 11 12 13 Use the controls, thumbnail strip, or left and right arrow keys to move through the presentation.\nRecording\nMDR \u0026amp; XDR Keynote Full session · Hosted directly by MeteSec\nYour browser does not support embedded MP4 video. Event # The keynote took place from 09:00 to 09:30 on 9 July 2026 as part of the IT-SICHERHEIT web conference Detection und Response mit MDR/XDR.\nView the conference program on IT-SICHERHEIT\n","date":"9 July 2026","externalUrl":null,"permalink":"/talks/mdr-xdr-modern-security-operations/","section":"Talks","summary":"This keynote opened the IT-SICHERHEIT web conference on detection and response with MDR and XDR.\nAbout the Keynote # Organizations need to identify and handle security-relevant activity across endpoints, cloud environments, and identities. Phishing, compromised accounts, and suspicious behavior rarely stay inside a single technical boundary.\nThe keynote explains how modern MDR and XDR approaches connect detection and response across those environments and where they fit in relation to traditional SIEM-centered security operations.\n","title":"MDR und XDR: Moderne Security Operations verstehen","type":"talks"},{"content":"","date":"9 July 2026","externalUrl":null,"permalink":"/tags/security-operations/","section":"Topics","summary":"","title":"Security Operations","type":"tags"},{"content":"","date":"9 July 2026","externalUrl":null,"permalink":"/tags/siem/","section":"Topics","summary":"","title":"SIEM","type":"tags"},{"content":"This section collects selected talks, keynotes, and public sessions together with their context, recordings, and supporting material where available.\n","date":"9 July 2026","externalUrl":null,"permalink":"/talks/","section":"Talks","summary":"This section collects selected talks, keynotes, and public sessions together with their context, recordings, and supporting material where available.\n","title":"Talks","type":"talks"},{"content":"Presented as a job I/O Deep Dive together with Leon Rohde from Deloitte, this session provides an accessible map of the cybersecurity field for people who are still deciding where they might fit.\nWatch and Explore # Presentation\nCybersecurity verstehen: Rollen, Wege und Einstiegsmöglichkeiten 19 slides · Self-hosted viewer · 1.99 MB\nDownload PPTX Previous 1 / 19\nNext 1 2 3 4 5 6 7 8 9 10 11 12 13 14 15 16 17 18 19 Use the controls, thumbnail strip, or left and right arrow keys to move through the presentation.\nRecording\nCybersecurity verstehen: Rollen, Wege und Einstiegsmöglichkeiten Full session · Hosted directly by MeteSec\nYour browser does not support embedded MP4 video. About the Session # Cybersecurity is often presented as a single profession, even though the work spans very different responsibilities, mindsets, and career paths.\nThe talk introduces some of the most common roles and groups them into four broad perspectives:\npeople who build systems and security into them; defenders who monitor, investigate, and respond; attackers who identify and demonstrate weaknesses; governance professionals who translate risk, regulation, and business requirements into a security program. The goal is to make those areas understandable without requiring deep technical knowledge first. Rather than prescribing one perfect route, the session shows how different backgrounds, interests, and strengths can lead into cybersecurity.\nEvent # The session took place on 28 May 2026 as part of job I/O. The original event page contains the organizer\u0026rsquo;s description and speaker profiles:\nView the session on get in IT\n","date":"28 May 2026","externalUrl":null,"permalink":"/talks/cybersecurity-roles-paths-and-ways-in/","section":"Talks","summary":"Presented as a job I/O Deep Dive together with Leon Rohde from Deloitte, this session provides an accessible map of the cybersecurity field for people who are still deciding where they might fit.\nWatch and Explore # Presentation\nCybersecurity verstehen: Rollen, Wege und Einstiegsmöglichkeiten 19 slides · Self-hosted viewer · 1.99 MB\nDownload PPTX Previous 1 / 19\n","title":"Cybersecurity verstehen: Rollen, Wege und Einstiegsmöglichkeiten","type":"talks"},{"content":" Hi, I\u0026rsquo;m Mete # I am a cybersecurity professional with my strongest foundation currently in defensive security, detection engineering, and security operations.\nAt the same time, I am deliberately expanding across offensive security, secure development, cloud and infrastructure security, and vulnerability research. I do not see these as separate worlds. Understanding how systems are built, how they fail, and how they can be defended creates a much stronger picture than staying inside a single discipline.\nWhy MeteSec exists # MeteSec is a public record of that work. It gives me a place to turn private notes, unfinished experiments, and lessons learned into clear explanations that can be revisited, challenged, and improved.\nThe guiding idea is simple:\nBuild systems with security in mind. Break assumptions and understand failure modes. Defend with useful context, reliable detections, and disciplined response. This is not a claim that the journey was perfectly planned or that every question has already been answered. It is a commitment to make the work visible and to keep learning in public.\n","externalUrl":null,"permalink":"/about/","section":"About","summary":"Hi, I’m Mete # I am a cybersecurity professional with my strongest foundation currently in defensive security, detection engineering, and security operations.\nAt the same time, I am deliberately expanding across offensive security, secure development, cloud and infrastructure security, and vulnerability research. I do not see these as separate worlds. Understanding how systems are built, how they fail, and how they can be defended creates a much stronger picture than staying inside a single discipline.\n","title":"About","type":"about"},{"content":"MeteSec aims to remain usable with a keyboard, screen magnification, common screen readers, and reduced-motion preferences.\nThe site uses semantic headings, visible focus indicators, descriptive link text, responsive layouts, colour contrast suitable for the dark and light themes, and alternatives for meaningful images. Decorative images are hidden from assistive technology. Motion is reduced when the browser requests it.\nAccessibility is an ongoing process rather than a one-time badge. If a page, component, document, or code example creates a barrier, please report the URL and the problem through the contact page. Where possible, include the browser, assistive technology, and expected behaviour.\n","externalUrl":null,"permalink":"/accessibility/","section":"MeteSec","summary":"MeteSec aims to remain usable with a keyboard, screen magnification, common screen readers, and reduced-motion preferences.\nThe site uses semantic headings, visible focus indicators, descriptive link text, responsive layouts, colour contrast suitable for the dark and light themes, and alternatives for meaningful images. Decorative images are hidden from assistive technology. Motion is reduced when the browser requests it.\nAccessibility is an ongoing process rather than a one-time badge. If a page, component, document, or code example creates a barrier, please report the URL and the problem through the contact page. Where possible, include the browser, assistive technology, and expected behaviour.\n","title":"Accessibility","type":"page"},{"content":"AI-assisted tools may be used for editorial support, code assistance, layout exploration, transcription, summarization of the author\u0026rsquo;s own notes, or language refinement. They are not treated as authoritative sources.\nEditorial responsibility # Mete Demirci remains responsible for every published claim, example, recommendation, and conclusion. AI-generated suggestions are reviewed, edited, and checked against source material or practical results before publication.\nWhat AI does not replace # AI output does not replace hands-on testing, source verification, professional experience, or subject-matter judgement. A claim is not considered verified because a model produced it confidently.\nDisclosure in individual articles # Material use that is important for understanding an article — for example, a generated research dataset, an AI-created illustration, or analysis performed substantially by a model — should be disclosed on that article. Routine spelling, drafting, formatting, and coding assistance is covered by this site-wide disclosure.\nConfidential customer data, active credentials, and other sensitive material should not be submitted to public AI services for the purpose of producing MeteSec content.\n","externalUrl":null,"permalink":"/ai-disclosure/","section":"MeteSec","summary":"AI-assisted tools may be used for editorial support, code assistance, layout exploration, transcription, summarization of the author’s own notes, or language refinement. They are not treated as authoritative sources.\nEditorial responsibility # Mete Demirci remains responsible for every published claim, example, recommendation, and conclusion. AI-generated suggestions are reviewed, edited, and checked against source material or practical results before publication.\n","title":"AI Disclosure","type":"page"},{"content":"","externalUrl":null,"permalink":"/authors/","section":"Authors","summary":"","title":"Authors","type":"authors"},{"content":" Continuous learning, applied in practice\nCredentials are milestones — not the whole story. Each certification marks a stage in how I built my understanding of IT and cybersecurity: from foundational systems knowledge to infrastructure, cloud, security operations, and hands-on security work.\n14 certifications 5 providers 2022–2026 journey Learning Roadmap # Roadmap concept — a visual guide from foundations toward technical specialization, not a mandatory certification path. CompTIA # My CompTIA path developed from broad IT foundations into networking, infrastructure, cloud, data, Linux, and security. Together, these credentials gave me a structured map of how the individual layers of an IT environment connect.\nCompTIA Linux+ Issued Apr 2026 · Valid until Apr 2029\nStrengthened my practical understanding of Linux administration, command-line work, networking, permissions, services, security, and scripting.\nCredential ID: 4c13e460b70d49159a3ba0a24cd2dabb\nCompTIA Network+ Issued Nov 2025 · Valid until Nov 2028\nConnected network architecture, protocols, operations, troubleshooting, and security into a coherent foundation for infrastructure and defensive work.\nCredential ID: f045b995cf974dfd90355a70c41eb822\nCompTIA Cloud+ Issued Sep 2025 · Valid until Sep 2028\nExpanded my understanding of cloud architecture, deployment, operations, security, resilience, automation, and hybrid infrastructure.\nCompTIA Server+ Issued Sep 2025\nDeepened my knowledge of server hardware, storage, virtualization, administration, security, troubleshooting, and disaster recovery.\nCredential ID: 7EBQE18Q82Q4KVS2\nCompTIA Cloud Essentials+ Issued Aug 2025 · Valid until Aug 2028\nAdded the business perspective behind cloud adoption, including service models, governance, risk, cost, and operational decision-making.\nCredential ID: 3SM7V0KQ0JR1QY2J\nCompTIA Data+ Issued Jul 2025 · Valid until Jul 2028\nIntroduced a structured approach to data analysis, data quality, mining, governance, statistical thinking, and visualization.\nCredential ID: 3N25K4TQVJEQK3YJ\nCompTIA Security+ Issued Jul 2025 · Valid until Jul 2028\nEstablished a broad security baseline across threats, architecture, identity, risk, cryptography, operations, and incident response.\nCredential ID: CLFSM8TYVEEQS442\nCompTIA A+ Issued Jun 2025 · Exams 220-1201 / 220-1202\nBuilt a practical baseline across hardware, operating systems, troubleshooting, support, networking, cloud, and endpoint security.\nCredential ID: QS8YD21YVFB4K35J\nCompTIA Tech+ Issued Mar 2025\nCovered the building blocks of computing, infrastructure, software, databases, development concepts, and basic security.\nCredential ID: B6QX2ZRY4NEEQ342\nCompTIA IT Fundamentals+ Issued Mar 2025\nProvided the initial structured overview of IT concepts that became the starting point for the broader certification path.\nCredential ID: K2M64XZYZNVQQHWZ\nOffSec # OSOSCC-SEC OffSec CyberCore — Security Essentials Issued Feb 2026 · Valid until Feb 2029\nBrought attack, defend, and build together through hands-on scenarios covering exploitation, investigation, remediation, secure coding, and cloud architecture.\nView official credential details → ISC2 # Certified in Cybersecurity (CC) Issued Jun 2025 · Valid until Jun 2028\nReinforced security principles, access control, network security, business continuity, incident response, and security operations.\nMember ID: 2536602\nPeopleCert # PRINCE2 Foundation Issued Jul 2025 · Valid until Jul 2028\nAdded a structured project-management perspective covering principles, roles, planning, risk, quality, progress, and controlled delivery.\nCredential ID: GR466039352MD\nScrum.org # Professional Scrum Master I Issued Apr 2022 · No expiry\nEstablished my understanding of Scrum theory, empiricism, accountabilities, events, artifacts, and how the framework is applied by real teams.\nCredential ID: 790725\nThe Journey Behind the Badges # The individual certifications matter, but the sequence matters more. I explore that progression in The Long Way Around: How Certifications Taught Me to Learn IT.\n","externalUrl":null,"permalink":"/certifications/","section":"Certifications","summary":" Continuous learning, applied in practice\nCredentials are milestones — not the whole story. Each certification marks a stage in how I built my understanding of IT and cybersecurity: from foundational systems knowledge to infrastructure, cloud, security operations, and hands-on security work.\n14 certifications 5 providers 2022–2026 journey Learning Roadmap # Roadmap concept — a visual guide from foundations toward technical specialization, not a mandatory certification path. CompTIA # My CompTIA path developed from broad IT foundations into networking, infrastructure, cloud, data, Linux, and security. Together, these credentials gave me a structured map of how the individual layers of an IT environment connect.\n","title":"Certifications","type":"certifications"},{"content":"For article feedback, correction reports, professional topics, or collaboration enquiries, contact Mete Demirci by email or through one of the public profiles below.\nEmail — direct and correction-related enquiries LinkedIn — professional enquiries and direct messages GitHub — public code, technical work, and repository issues GitHub Discussions — public questions and community discussion For a correction, include the article URL, the relevant passage, and a supporting source where possible. Do not send credentials, customer data, unreleased vulnerabilities, or other sensitive information through a public issue or discussion.\n","externalUrl":null,"permalink":"/contact/","section":"MeteSec","summary":"For article feedback, correction reports, professional topics, or collaboration enquiries, contact Mete Demirci by email or through one of the public profiles below.\nEmail — direct and correction-related enquiries LinkedIn — professional enquiries and direct messages GitHub — public code, technical work, and repository issues GitHub Discussions — public questions and community discussion For a correction, include the article URL, the relevant passage, and a supporting source where possible. Do not send credentials, customer data, unreleased vulnerabilities, or other sensitive information through a public issue or discussion.\n","title":"Contact","type":"page"},{"content":"MeteSec welcomes specific, evidence-based corrections. The objective is not to preserve the appearance of always having been right; it is to leave readers with the most accurate version of the work.\nHow to report an issue # Use the contact page and include the article URL, the disputed passage, your proposed correction, and a supporting source where possible. Security-sensitive reports should not be posted publicly.\nWhat changes look like # Spelling, grammar, formatting, and broken-link fixes may be made silently. Clarifications that do not change the conclusion receive an updated date when they materially help interpretation. Factual errors that affect the reasoning or conclusion receive a visible correction note explaining what changed. An article may be withdrawn if it cannot be corrected safely or responsibly. The URL should remain with an explanation rather than silently disappearing. Good-faith disagreement is not automatically an error. When evidence supports more than one reasonable interpretation, the article may be expanded to represent that uncertainty more clearly.\n","externalUrl":null,"permalink":"/corrections/","section":"MeteSec","summary":"MeteSec welcomes specific, evidence-based corrections. The objective is not to preserve the appearance of always having been right; it is to leave readers with the most accurate version of the work.\nHow to report an issue # Use the contact page and include the article URL, the disputed passage, your proposed correction, and a supporting source where possible. Security-sensitive reports should not be posted publicly.\n","title":"Corrections Policy","type":"page"},{"content":" Senior Cybersecurity Consultant\nMete Demirci Cybersecurity professional with experience across security operations, detection and response, security governance, infrastructure security, and identity and access management.\nLinkedIn GitHub My work combines hands-on technical implementation with security architecture, process development, and stakeholder management. I have supported organizations in healthcare, financial services, and pharmaceutical environments, working on SOC transformation, threat modeling, security hardening, and audit remediation.\nAlongside consulting, I write about cybersecurity and professional development, speak at industry events, and document the lessons behind my technical journey.\nAreas of Expertise # Security Operations Detection and response, SIEM engineering, SOC processes, alert analysis, log-source onboarding, and operational automation.\nSecurity Engineering Secure architecture, threat modeling, endpoint security, system hardening, vulnerability management, and identity security.\nGovernance \u0026amp; Transformation Audit remediation, operating models, policies, standards, procedures, and technical transformation programs.\nLeadership \u0026amp; Communication Technical project leadership, team leadership, executive stakeholder management, proposals, workshops, writing, and public speaking.\nProfessional Experience # Senior Consultant Mar 2026 — Present Deloitte · Germany Working across security operations, managed detection and response, security governance, and technical transformation engagements.\nLead and support SOC and MDR transformation projects Design operating models, processes, architectures, and technical onboarding approaches Develop and optimize Microsoft Sentinel environments, integrations, and reporting Translate audit findings into actionable governance documents and controls Coordinate technical teams, delivery partners, and senior stakeholders Cybersecurity Consultant \u0026amp; Team Lead Jan 2025 — Feb 2026 IBM Germany · Munich Held professional and personnel responsibility for an eleven-member team Delivered engagements covering threat modeling, SOC services, and security architecture Supported technical bids, proposals, and customer-facing solution development Developed security documentation, operating procedures, and automation concepts Cybersecurity Engineer — Infrastructure Security Feb 2024 — Dec 2024 UniCredit · Munich Implemented server and workstation hardening based on CIS and STIG guidance Improved endpoint patching and vulnerability-management processes Collaborated with SOC and incident-response teams to strengthen endpoint security Established and documented technical security baselines Cybersecurity Engineer — Identity \u0026amp; Access Management Feb 2023 — Feb 2024 UniCredit · Munich Managed decentralized and centralized identity and access processes Administered role-based access across enterprise applications Controlled access requests and approvals through ticket-based workflows Supported transparent and compliant authorization management Selected Engagements # Selected client engagements across healthcare, banking, and pharmaceutical environments.\nSOC Capability Development Mar 2026 — Present DAK-Gesundheit\nAdministered and configured Microsoft Sentinel and developed operational workbooks. Selected and onboarded additional log sources and connectors. Analyzed alerts, identified environment-specific false positives, and monitored ingestion costs. Derived technical and organizational improvements, operational rules, and security best practices. Managed Detection \u0026amp; Response Onboarding Mar — Jul 2026 Sana IT Services\nDesigned the target architecture and operating model for an MDR service. Led the technical onboarding and coordinated operational and executive stakeholders. Established project governance, weekly reporting, and supporting proposal material. Designed integrations for Zscaler, Proofpoint, Microsoft Entra ID, Sentinel, and relevant log sources. Security Governance Remediation Mar 2026 — Present Investitions- und Strukturbank Rheinland-Pfalz (ISB)\nDeveloped governance documentation in response to security audit findings. Created organizational policies, standards, operating procedures, and process models. Covered vulnerability management, penetration testing, change management, patch management, and security logging. Translated audit requirements into practical security controls and responsibilities. eHealth Security Architecture Mar — Aug 2025 gematik\nDeveloped a threat-modeling report for a security identity provider. Assessed architectural threats, trust boundaries, and security risks. Supported the development of an endpoint detection and response rollout process. Translated technical findings into recommendations for implementation and architecture. SOC Process Development Oct — Dec 2025 Bayer\nDeveloped automation concepts for SOC analyst workflows using Microsoft Logic Apps. Updated the core standard operating procedure template. Created and structured an inventory of existing SOC procedures. Improved the consistency and automation readiness of operational documentation. Selected Certifications # CompTIA Security+ CompTIA Cloud+ CompTIA Server+ CompTIA Data+ ISC2 Certified in Cybersecurity Professional Scrum Master I PRINCE2 Foundation The dedicated Certifications section provides the broader learning context behind these credentials.\nEducation # M.Sc. IT Security — Studies paused\nTechnical University of Darmstadt · 2020–2022\nB.Sc. Business Informatics\nUniversity of Applied Sciences Landshut · 2015–2020\nFocus: Cybersecurity\nLanguages # German: Native English: Professional working proficiency · TOEFL iBT 100/120 Beyond the CV # A conventional CV captures roles and dates, but rarely the thinking behind the work. My writing, conference talks, public projects, and certification reflections document that wider journey.\n","externalUrl":null,"permalink":"/cv/","section":"CV","summary":" Senior Cybersecurity Consultant\nMete Demirci Cybersecurity professional with experience across security operations, detection and response, security governance, infrastructure security, and identity and access management.\nLinkedIn GitHub My work combines hands-on technical implementation with security architecture, process development, and stakeholder management. I have supported organizations in healthcare, financial services, and pharmaceutical environments, working on SOC transformation, threat modeling, security hardening, and audit remediation.\n","title":"CV","type":"cv"},{"content":"MeteSec is an independently edited personal publication by Mete Demirci. Its purpose is to explain cybersecurity clearly, document practical learning, and publish considered analysis without disguising uncertainty or experience level.\nWhat gets published # Articles are selected because they add a useful explanation, tested observation, practical lesson, or clearly identified perspective. MeteSec is curated rather than comprehensive: not every exercise, certification, news item, or opinion becomes an article.\nEvidence and labels # Content should make a meaningful distinction between:\nfacts supported by primary or authoritative sources; observations from work, labs, or personal testing; interpretation based on the available evidence; personal experience and opinion. When an article depends on external material, sources should be linked close to the relevant claim or listed in a references section. Personal accounts are labelled as such and are not presented as universal advice.\nReview and updates # Technical content is checked for internal consistency, working links, and obvious factual errors before publication. Material changes receive an updated date. Small typographical edits may be made without an update note.\nSecurity changes quickly. A publication date is therefore part of the evidence: readers should not assume that an old tool, product, certification, or recommendation still works in exactly the same way.\nIndependence # MeteSec does not sell article placement or accept payment for rankings. Any future commercial relationship, affiliate link, free review access, or sponsored material will be disclosed clearly on the affected page. Support through Ko-fi does not influence editorial decisions or create access to favourable coverage.\nSafety and ethics # Offensive-security material is intended for authorized environments, defensive understanding, and responsible research. Articles will not knowingly publish private credentials, sensitive customer information, active secrets, or instructions whose primary value is clearly harmful abuse.\nCorrections # Errors should be corrected openly and proportionately. See the corrections policy for the process and the distinction between minor edits and substantive corrections.\n","externalUrl":null,"permalink":"/editorial-policy/","section":"MeteSec","summary":"MeteSec is an independently edited personal publication by Mete Demirci. Its purpose is to explain cybersecurity clearly, document practical learning, and publish considered analysis without disguising uncertainty or experience level.\nWhat gets published # Articles are selected because they add a useful explanation, tested observation, practical lesson, or clearly identified perspective. MeteSec is curated rather than comprehensive: not every exercise, certification, news item, or opinion becomes an article.\n","title":"Editorial Policy","type":"page"},{"content":" Angaben gemäß § 5 DDG # Mete Demirci\nc/o COCENTER\nKoppoldstr. 1\n86551 Aichach\nDeutschland Kontakt # E-Mail: metesec@outlook.com\nVerantwortlich für journalistisch-redaktionelle Inhalte # Verantwortlich gemäß § 18 Abs. 2 MStV:\nMete Demirci\nc/o COCENTER\nKoppoldstr. 1\n86551 Aichach\nDeutschland Hinweis zur Anschrift # Die oben genannte ladungsfähige Anschrift wird über einen Impressum-Service bereitgestellt. Sie dient der Anbieterkennzeichnung und der zuverlässigen Zustellung rechtlich relevanter Post.\n","externalUrl":null,"permalink":"/imprint/","section":"MeteSec","summary":"Angaben gemäß § 5 DDG # Mete Demirci\nc/o COCENTER\nKoppoldstr. 1\n86551 Aichach\nDeutschland Kontakt # E-Mail: metesec@outlook.com\nVerantwortlich für journalistisch-redaktionelle Inhalte # Verantwortlich gemäß § 18 Abs. 2 MStV:\nMete Demirci\nc/o COCENTER\nKoppoldstr. 1\n86551 Aichach\nDeutschland Hinweis zur Anschrift # Die oben genannte ladungsfähige Anschrift wird über einen Impressum-Service bereitgestellt. Sie dient der Anbieterkennzeichnung und der zuverlässigen Zustellung rechtlich relevanter Post.\n","title":"Impressum","type":"page"},{"content":"MeteSec is designed as a static website with minimal data collection.\nController # The person responsible for this website is:\nMete Demirci\nc/o COCENTER\nKoppoldstr. 1\n86551 Aichach\nGermany Email: metesec@outlook.com\nThis site # MeteSec currently does not run advertising trackers, behavioural analytics, account systems, or a first-party comments database. Search runs in the browser using a static site index. The site does not intentionally set marketing cookies.\nHosting # The site is hosted through GitHub Pages. As the hosting provider, GitHub may process technical request information such as IP addresses, timestamps, requested URLs, and browser details for security and delivery. See GitHub\u0026rsquo;s privacy statement for its practices.\nExternal links and services # Links to GitHub, LinkedIn, Ko-fi, or other external sites take you to services with their own privacy policies. External widgets are not loaded unless they are explicitly enabled. If comments are enabled in the future, the article will load the configured discussion service and this page will be updated.\nGitHub Discussions is available as an external community area. Opening or using it sends the usual connection data to GitHub. Posting requires a GitHub account and is governed by GitHub\u0026rsquo;s own terms and privacy information.\nEmail newsletter # MeteSec uses Brevo to manage voluntary email subscriptions. The subscription form on the Writing page is submitted directly to Brevo. It does not load Brevo JavaScript or tracking resources before you submit it.\nWhen you subscribe, Brevo processes your email address, confirmation status, timestamps, and the technical information needed to receive and secure the request. This information is used only to manage and send the newsletter on the basis of your consent. A double-opt-in email is sent, and your subscription becomes active only after you confirm the address.\nYou can withdraw your consent at any time through the unsubscribe link included in newsletter emails. The data is retained for newsletter delivery and consent documentation until you unsubscribe or the information is no longer required, subject to applicable record-keeping obligations. More information is available in Brevo\u0026rsquo;s privacy policy.\nContact # If you contact MeteSec through an external platform, that platform processes the message under its own terms. Information you provide is used to respond to the request and is not sold.\nThis page will be updated when another service materially changes data processing on MeteSec.\n","externalUrl":null,"permalink":"/privacy/","section":"MeteSec","summary":"MeteSec is designed as a static website with minimal data collection.\nController # The person responsible for this website is:\nMete Demirci\nc/o COCENTER\nKoppoldstr. 1\n86551 Aichach\nGermany Email: metesec@outlook.com\nThis site # MeteSec currently does not run advertising trackers, behavioural analytics, account systems, or a first-party comments database. Search runs in the browser using a static site index. The site does not intentionally set marketing cookies.\n","title":"Privacy","type":"page"},{"content":"This section will document selected projects across building, breaking, and defending systems.\nEach project write-up will focus on more than the final result. It will capture the problem, constraints, design decisions, trade-offs, validation, and lessons learned so that the work remains understandable and reproducible.\nThe first project entries are being prepared.\n","externalUrl":null,"permalink":"/projects/","section":"Projects","summary":"This section will document selected projects across building, breaking, and defending systems.\nEach project write-up will focus on more than the final result. It will capture the problem, constraints, design decisions, trade-offs, validation, and lessons learned so that the work remains understandable and reproducible.\nThe first project entries are being prepared.\n","title":"Projects","type":"projects"},{"content":"MeteSec aims to make the basis of an article visible instead of asking readers to trust confident wording alone.\nSource priority # When possible, technical claims are checked against primary material such as official documentation, standards, vendor advisories, source code, research papers, or direct test results. Reputable secondary reporting is useful for context, but it should not silently replace the underlying source when that source is available.\nPractical verification # Commands, configurations, detections, and lab observations should be tested in an appropriate environment before they are described as working results. The article should state important limits: product version, date, assumptions, or areas that were not tested.\nPersonal experience # Career reflections and learning reports use first-hand experience as their main source. They can be useful without being universal. These articles distinguish what happened to the author from what another reader should necessarily do.\nUncertainty # If available evidence is incomplete or contradictory, the article should say so. Inference is presented as inference. Marketing claims, anonymous screenshots, and repeated claims without a traceable origin are not treated as confirmation.\nReader verification # Links and publication dates are included so readers can inspect the material themselves. If a source disappears, changes materially, or no longer supports the claim, please use the contact page to report it.\n","externalUrl":null,"permalink":"/sources-and-verification/","section":"MeteSec","summary":"MeteSec aims to make the basis of an article visible instead of asking readers to trust confident wording alone.\nSource priority # When possible, technical claims are checked against primary material such as official documentation, standards, vendor advisories, source code, research papers, or direct test results. Reputable secondary reporting is useful for context, but it should not silently replace the underlying source when that source is available.\n","title":"Sources \u0026 Verification","type":"page"}]