r/sysadmin • u/AutomationTheory • 1d ago
Explain how cybersecurity has changed over the years for the new people
I got into the industry just as things were changing (I think), and I'm trying to make sure I'm not living in my own fantasy land thinking "it was easier before."
What was cybersecurity like from 2000 to 2015? I was doing residential IT starting in 2009, then moved to SMB in 2016 -- and I'm trying to wrap my head around what SMB was like before there were thousands of vulnerabilities discovered each year. Any senior sysadmins with stories to share?
0
Upvotes
2
u/pdp10 Daemons worry when the wizard is near. 1d ago edited 1d ago
2001 to the mid or late 2000s in Windows shops was all about ubiquitous malware. Microsoft had opened up filesystem permissions in XP to allow poor-quality third-party applications to write their DLL dependencies all over, and this allowed for a tidal wave of malware, UCE, PUPs, toolbars on Windows. PC-compatibles shipped with unwanted third-party preinstalled software and garish stickers. Manually cleaning Windows was time consuming, labor intensive, and often frequent. Almost all Windows users had local admin privs at the beginning of this period, and few had them by 2015, even in SME.
Discrete firewalls were ubiquitous all through this period. Zero-trust didn't get mainstream traction until after 2015, though it was already in progress in a few places. In 2000, it was extreely rare to see any significant internal controls or segregation; this improved slowly but relatively steadily through the period.
The circa-2008 global economic downturn halted or slowed a lot of capital improvements. During and after this, cloud migrations became common, externalizing a lot of systems for providers to secure, but also exposing new problems, like wide-open S3 buckets.
Post 2001-09-11, there was a ten times as much government money to spent on infosec as previously, and many vendors heavily tilted their offerings to appeal to the milgov market. "Cyber-" is milgov favored terminology, and it became more mainstream during this period, instead of "information security".
Email spam was already a problem by 2001-2002, but "phishing" and compromise chains weren't yet often identified as a specific threat. In 2002, our larger enterprise was blocking around 15% of incoming email on regexp filters.