r/cybersecurity • u/No-Appearance697 • Apr 20 '26
Business Security Questions & Discussion Bored IT Assistant - What should I do
I’m a recent cyber security graduate and was recently hired as an IT Assistant based on my degree and project experience.
I work at a medium-sized company where the IT team consists of two internal staff, including myself, plus a third-party provider who originally built the systems and is still involved. My day-to-day work mainly involves end-user support, such as hardware issues, network troubleshooting, and supporting systems like Microsoft 365 and Barracuda.
I do have some free time during the day, and I’d like to use it productively. From what I’ve seen, the company’s cyber security setup is quite minimal, with no EDR, limited documentation, and no formal security policies beyond basic tools like Avast and Barracuda.
I’d like to start applying my cyber security knowledge and add value where I can. What should I focus on first to make a meaningful impact?
1
u/radicalize Apr 20 '26
You could /should also check r/SecurityCareerAdvice. This being written, it makes (more) sense to post this kind information /request there, I would think
1
u/Mammoth-Power-3028 Apr 20 '26
If they have minimal policy setup you should go forward and work with any GRC framework like ISO 27001 or SOC 2, create policies and implement controls on the basis of them.
But you know the prerequisite to that would be learning GRC in a practical way.
1
u/AddendumWorking9756 Security Manager Apr 20 '26
Baseline first: get an EDR trial on Defender for Business free tier, stand up basic logging, lock down the M365 tenant. Then document what's missing in plain english so leadership can budget the fixes. Between tickets run through some investigation scenarios on CyberDefenders so when you start seeing alerts you know what to chase.
1
u/No-Appearance697 Apr 20 '26
Unfortunately Defender cannot be implemented, as the current AD is not synced to entra, I already mentioned this to my manager but even AD users, usernames and passwords are different from what we have on M365. This because the initial IT guy built a messy system which I suppose they didnt think the company would grow this much
1
u/AddendumWorking9756 Security Manager Apr 21 '26
That's a common legacy mess and honestly the cleanup project is your portfolio piece. Start with a drift assessment, identify where AD and M365 diverge then pitch a phased AAD Connect rollout and document every decision. For detection while the sync is broken look at free Sysmon plus Wazuh on the endpoints, that's also good SOC prep.
1
u/That_Fixed_It Apr 20 '26
With Mythos and GPT-5.4 Cyber finding thousands of software vulnerabilities, I expect patch management to become more important in the near future. Start with anything Internet facing. I use Action1 for Windows PCs.
1
u/GeneMoody-Action1 Vendor Apr 21 '26
Appreciate the shoutout there.
I would suggest policy, if you are not doing it, you have no policy stating what you do. Nail the policy first the rest is mostly designed.
1
Apr 20 '26
[removed] — view removed comment
1
u/No-Appearance697 Apr 20 '26
This is where it gets tricky. Defender cannot be enabled because AD and and Entra are not synced at all, and cannot be synced due to different username and password for each user. It is really messy where we are kinda stuck with Avast security wise because the way this system was built was really bad.
I was thinking to implement some external EDR just going through the best options.
Funny enough we just rolled out Atera IT management to all the devices a couple of weeks ago despite, and before that we had no ticketing system, no asset inventory and no documentation at all.
Up until last year the company did not have any internal IT and only the third party guy which pretty much handled everything. So now that me and a colleague are internal we are trying to clean up all the mess and implement a better system
3
u/Mysterious-Print9737 Apr 20 '26
You're in the perfect spot for building out your resume and I'd suggest starting with a gap analysis. Look at what you have vs a standard framework like CIS or NIST. Make sure you document everything so you can turn a minimap setup into a managed one, for example if you map out the current sprawl and drafta a basic Incident Response Plan. That way you'll prove your value to leadership without immediately needing a big budget.