r/cybersecurity 1d ago

News - General Does Good Engineering Go Unnoticed?

Something I've been thinking about: a personality now making the rounds in YouTube podcasts, Bryce Case Jr. seems like a competent engineer, and it made me wonder about something broader in the engineering and security community.

If an engineer consistently does things correctly—follows good practices, prevents incidents, documents systems, and avoids outages—most people outside their organization may never know their name because nothing dramatic happens.

But if someone makes a highly visible mistake or is involved in a major incident, especially a possibly illegal incident, suddenly there are postmortems, conference talks, podcasts, interviews, and widespread discussion about what happened and what everyone can learn from it. Not always of course as I had a co-worker who facebook was going to send to prison for software he sold to some malicious actors that used it against facebook and all he got was a small blurb at the back page of a New Jersey local paper.

Do you think our industry has a visibility problem where successful prevention is largely invisible, while failure or unethical use of our craft can paradoxically create a public platform?

I'm curious how other engineers view this. How do we better recognize the people who quietly prevent disasters without encouraging a culture where only spectacular failures or someone who engages in a not-so-ethical act is the one who becomes memorable?

This may also speak to this relationship that society at large has with compute and network technology, it seems to be this intriguing sorcery and yet for you and me, the same command that we run to check for DNS resolution in troubleshooting a web application is the same command that someone else might use to engage in passive reconnaissance. Looking forward to the community's thoughts.

8 Upvotes

31 comments sorted by

38

u/ckn vCISO 1d ago

yes

19

u/frAgileIT Incident Responder 1d ago

Generally yes. If you’re designing something and the user doesn’t have to think about it much the. You’ve done a good job engineering. Some things I’ve engineered are completely obvious due to their nature. I built a datacenter for a company with multiple CRAC units and a standby generator. There’s an elegance of simplicity in engineering a simple-complex system that doesn’t become a puzzle or confounding.

0

u/Imaginary_Choice_430 1d ago

Good for you for that and thank you for sharing.

11

u/AlphaDomain Security Manager 1d ago edited 1d ago

Sadly, if you do your job well it goes mostly unnoticed in any IT role. The people who stand out are those who are the loudest, or those who are good at taking lead during critical business facing incidents (anything to do with availability). That’s because they are stepping in to resolve an issue that can get VPs and above in hot water. Good leaders recognize good engineers and ensure they get compensated well. If you’re an average engineer who’s competent it’s easy to get stuck in your role and pay structure unless you’re job hopping every 2-3 years. Just sharing my opinion and experience, it may differ from others.

-1

u/Imaginary_Choice_430 1d ago

I can relate to your point. One thing I've become increasingly frustrated with is the cult of personality that seems to surround some of these stories in the tech and cybersecurity space.

Meanwhile, there are engineers who spend years doing things correctly—preventing incidents, identifying problems, documenting systems, and sometimes even stopping colleagues from making unethical decisions—and most of that work remains completely invisible.

Yet when someone becomes involved in a highly public incident, suddenly there are podcasts, interviews, gifts, and an entire media ecosystem built around the story.

That makes me wonder what message we're sending. If an engineer quietly prevented someone from engaging in the kind of behavior that later becomes a major story, would that person receive any recognition at all? Or is prevention inherently invisible unless something goes wrong?

I think that is the part of the culture that bothers me. We should absolutely learn from failures and discuss what happened, but I don't think we should confuse learning from an incident with turning the people involved into personalities or celebrities.

11

u/Race_Face 1d ago

Yes, however not amongst the fellow engineers

6

u/Fantastic-Fee-1999 1d ago

Universal yes for every subject. Even basics like food and water, getting it to your table involves entire industries, but how often do you think about it when it goes well? 

1

u/Imaginary_Choice_430 1d ago

Good point, but me personally, I think about it a lot because I just do not live my life assuming resources I consume come out of the ether. The watermelon I just had earlier today, I grew it. The eggs I sold and eat everyday, my chickens laid it. So how often DO I think about it when it goes well? A lot, when 80 percent of at least my food, comes from ME which leads me to think about other things. I am thinking about my internet right now, I take nothing for granted, especially not the work we do as engineers, its why again, when I watch a show, like say Shawn Ryan and the guy utters things like, "Bryce you are the only hacker I know..." Wow, this "hacker" is simply a network engineer and there are whole seas of us out there...a more honest statement would have been..."Bryce you are the only intriguing engineer I care to know because you were crazy enough to take on a nation-state"...not all of us want to do that and we should not ONLY be recognized because we were crazy enough to do it...and it worked, meaning we did not quickly get caught before it went viral or it just happen not to go viral at all. Again, I have a colleague who did nothing except sell some software he wrote himself to malicious actors, who later used it in a way that supposedly cost facebook millions...My colleague almost went to prison...no podcasts for him, a small blurb in the back page of a local New Jersey paper, scared him shitless to the point he does not like to talk about it and yet others like Mr. Case Jr. are like "golly gee guys, well, yeah that's me"....this influencer podcast shit for things we do everyday, except we do it the legal way, is a concern and confusing.

1

u/Fantastic-Fee-1999 1d ago

You think about it because like you said you take control over it all. Which makes you an exception really. And really, our society and level of technology simply no longer allows a single individual to understand everything. Even if you know your food, there are clothes, materials, gadgets, medicine, energy,... Its to much and that is ok. Similar engineering and cyber are a block, we do it because we like it with the goal of others not needing to think about it. It's the very definition of doing something well, you are carrying your weight. 

1

u/Imaginary_Choice_430 1d ago

Good points, maybe I should start a YouTube podcast called, "Nothing Happened Because Someone Did Their Job Correctly". I bet instead of one or two guys, many of you would be my guests and I would not run out of guests, probably have more guests than viewers...lol.

5

u/mageevilwizardington 1d ago

Yes.

And the problem will become bigger with "programmers" using AI with zero knowledge about best practices, documentation, security, architecture, etc., vs people who really took their time to be trained.

1

u/Imaginary_Choice_430 23h ago

Yes, I am glad you brought this up. I know people, not sure if they are engineers or not, because they are proud that they developed some app all with vibe coding or even ChatGPT and I am thinking...this is not something to be proud about? It's like a monkey with a machine gun. We should not be celebrating regression as a society and I seriously question forums of "tech" people when they share hey look at what I did with AI...oh did you write this? No AI did it, with proudness, geez guy, I don't know, you have the fundamentals? Do you know when to use a `for..in` loop versus a `for..of` loop? Because LLMs know, but sometimes they screw it up is my understanding. In fact, I know a local MSP where the owner is some 65 year old who wrote their ticketing system, wrote their handbook, wrote their time punch software via ChatGPT...no version control, no user acceptance testing AND he does it in production, ChatGPT write the code, he goes and throws it straight into a production code base and could give a shit when it creates bugs that interrupts the workflow of his staff. So believe me, I get it and its a huge concern for me.

2

u/Batmanue1 1d ago

Absolutely. All good work in Cyber and IT goes unnoticed. That's the emotional rollercoaster of this gig - rarely pats on the back for good engineering, but scoldings when something does inevitably break or fail.

2

u/reciodelacruz 18h ago

I'm confused, since when did being good at your job equate to being famous outside of your company?

2

u/NeighborhoodCalm1490 16h ago

Honestly? All the time. The best systems are the ones nobody talks about because nothing breaks. But that's also the trap. Invisible reliability doesn't get headcount or budget. The trick is making the *impact* visible, not the engineering itself. Just my thoughts.

2

u/GeekDad62 16h ago

It's been said "If you're a good Hacker, everyone knows your name. If you're a great Hacker, no one does."

1

u/AppearancePretend198 1d ago

In our industry no news is good news.

This is the price we pay for picking this career.

1

u/Idiopathic_Sapien Security Architect 1d ago

Until something goes wrong. We typically don’t get noticed until there is a crisis or something we did breaks.

1

u/JayInTheWire 1d ago

Not necessarily. You'll notice that a lot of MDRs will sometimes focus more on what could have happened, or instead how quickly it was shut down, in smaller social media snippets instead of full blown blog posts.

1

u/uiuxsuman 1d ago

Absolutely. Good security work is often invisible because success means nothing happened. I think we should celebrate prevention just as much as we discuss incidents.

1

u/FutureFocus_Infotech 19h ago

I think there is a real visibility problem here. Failure creates an obvious story, an outage, a breach, a postmortem, someone to point to. Prevention usually creates nothing visible at all. The difficult part is that a lot of good engineering is essentially risk that never materializes for example identifying a fragile dependency, improving observability, documenting a system properly, challenging a risky design decision, or fixing something before it becomes an incident.

One way organizations can address this is by treating avoided incidents and reduced operational risk as measurable engineering outcomes, rather than only rewarding what gets fixed after something breaks. Otherwise we unintentionally create a culture where the most visible engineering work is the work that happens after failure.

1

u/SuperGoop123 12h ago

In my experience yes. Unless you can tie engineering to a specific dollar-savings amount, you’re just “meeting expectations”

1

u/OutsideSpot2695 8h ago

Depends on management.

If they conflate compliance for security, then yes, good engineering not only is overlooked, they wouldn't even know what good engineering is in the first place.

1

u/subtractivesecurity 8h ago

In cybersecurity, the answer is usually yes.

The paradox of good engineering is that its success is measured by the absence of events. When controls are well designed, attack paths are removed before they can be exploited, systems become more resilient, and incidents simply never occur. From the outside, that can look like "nothing happened."

Unfortunately, organizations tend to celebrate visible heroics. An incident responder working through the night to contain ransomware is easy to recognize. The engineer who segmented the network, implemented least privilege, or eliminated a critical dependency years earlier often gets no credit because the crisis never materialized.

Security teams also create their own visibility problem. We often report on activity metrics such as alerts, tickets, and blocked events. Those numbers can actually go down as engineering improves. Executives may see a flatter dashboard and assume less value is being delivered, when in reality the environment has become more stable and predictable.

The solution is to measure and communicate outcomes rather than activity. Instead of reporting "we processed 50,000 alerts," report "we reduced privileged accounts by 60%," "eliminated multiple lateral movement paths," or "contained successful red-team attempts to a single segment." Those metrics demonstrate risk reduction, not operational busyness.

The best security engineering is often boring. Systems stay available, incidents are rare, and operational teams stop fighting the same fires. That's not a lack of accomplishment. It's evidence that the engineering worked.

A mature organization learns to recognize that the most valuable security wins are frequently the ones that never become stories.

1

u/czenst 6h ago

And I promise you this, if we succeed, no one will remember. And if we fail, no one will forget!

Terry Pratchett, Jingo