惯性聚合 高效追踪和阅读你感兴趣的博客、新闻、科技资讯
阅读原文 在惯性聚合中打开

推荐订阅源

G
Google Developers Blog
阮一峰的网络日志
阮一峰的网络日志
A
About on SuperTechFans
大猫的无限游戏
大猫的无限游戏
Engineering at Meta
Engineering at Meta
V
Visual Studio Blog
Martin Fowler
Martin Fowler
Cyber Security Advisories - MS-ISAC
Cyber Security Advisories - MS-ISAC
博客园 - 叶小钗
I
InfoQ
B
Blog RSS Feed
aimingoo的专栏
aimingoo的专栏
Y
Y Combinator Blog
Blog — PlanetScale
Blog — PlanetScale
IT之家
IT之家
P
Proofpoint News Feed
WordPress大学
WordPress大学
小众软件
小众软件
B
Blog
MongoDB | Blog
MongoDB | Blog
人人都是产品经理
人人都是产品经理
量子位
Hugging Face - Blog
Hugging Face - Blog
月光博客
月光博客

Latest from TechRadar in Pro

VodafoneThree gets Ofcom approval to bring satellite connectivity to your smartphone Is this the tipping point for AI at work? New Gallup survey finds half of all US employees now use it in some way 'Every Apple user needs to know about this nasty scam': Fake warnings tell users their iCloud data will be… 'Makes it even more disappointing': Microsoft backs fossil fuel big time with $7 billion deal in race for AI… 'Maybe it’s not science fiction': Solar panels are causing rainwater to fall in one of the driest places… Maine becomes first US state to pass data centre construction ban Dozens of WordPress plugins hijacked to target thousands of sites Drone-killing laser weapons greenlit for use in US airspace – FAA and Defense Department say high-energy weapons are ‘ready to protect all air travelers from illicit drone use’ despite airspace restrictions and friendly-fire incidents 'We are currently being extorted' — crypto giant Kraken says it is facing extortion attack, here's… I tried 7 free MTD software – now I've ranked my top picks as a freelancer Jackery McGraw Hill becomes latest to see its Salesforce data hacked Looking for a new PC? Now might be great time to upgrade, as Gartner figures claim shipments are rising — while… The new engineering playbook: how AI design copilots are reshaping product development Farewell Surface Hub — Microsoft kills off its super-sized touchscreen displays, but you might still be able to get one if you act fast 'We have no interest in patient data in the UK': Palantir UK head defends record as criticisms rise Amazon’s new AI Bio Discovery tool can provide ‘every researcher’ with ‘lab-in-the-loop drug discovery’ – 40+ AI biology models can filter 300,000 novel antibody candidates down to the top results for testing in just weeks Over 100 Chrome Web Store extensions found stealing user data from thousands of accounts Europe wants tech sovereignty but is this realistic? Enterprise AI governance cannot live in a prompt. So where is the safety net? Why 2026 is the year of flexibility without friction: solving the multi-platform crisis OpenAI reveals its Mythos rival designed for cybersecurity pros When cyberattacks are inevitable, recovery becomes the strategy Closing the cloud complexity gap LaLiga uses AI to fight illegal streaming that costs its clubs $800m a year Intel and Google expand long-term chip partnership to power AI systems 'Chatbots respond not just to what you ask, but how you ask it': Report finds AI agents might be sucking up to… 'Smartphones have physical limitations': Report explains why AI is kickstarting a billion-dollar hardware arms… 'I’m pretty sure actually we really do not need to work for five days' Zoom CEO calls for end of traditional work schedules — says 3-day working week should become the norm 'It's more common than you think': Experts reveal how hackers are trying to hijack your inbox with these…
We need a cybersecurity curriculum taught by hackers
Daniel Spice · 2026-05-01 · via Latest from TechRadar in Pro

Dark web forums are now hosting resumes. Not from seasoned criminals – now, from teenagers and recently laid-off tech professionals looking for work.

At the same time, the global cybersecurity workforce shortage remains dire. ISC2 estimates there’s a gap of 4.8 million cybersecurity professionals worldwide.

Article continues below

CSO of Ivanti.

Early influences and the path to cybercrime

The skills I gained as a teenager, guided by mentors and a strong ethical foundation, ultimately determined which path I would take in cybersecurity. My curiosity was nurtured by industry professionals – an opportunity not everyone receives. Without that support, my trajectory could have been vastly different.

Statistics from the NCA are telling: the average cybercriminal is now just 17 years old, and the median age for referrals to their cybercrime prevention team is 15. Children as young as nine have been caught launching DDoS attacks.

It starts small: chat codes, account takeovers, or DDoS attacks on rival gamers. A kid gets banned – sometimes unfairly – and retaliates. Others watch and learn, with techniques spreading quickly through Discord servers and private forums.

Each successful exploit lowers the bar for the next one. The thrill of accomplishment, combined with peer validation, turns minor boundary-crossing into routine behavior. Desensitization grows slowly, then suddenly accelerates.

Sign up to the TechRadar Pro newsletter to get all the top news, opinion, features and guidance your business needs to succeed!

Money isn’t the primary motivation for young hackers at first. The NCA discovered that reputation and status within their online communities are what matter most. By the time financial incentives become important, habits and allegiances are already formed.

We built this pipeline problem

We trust that curious, technically skilled young people will find their way into legitimate security careers. We trust that credential systems and hiring processes will capture the right people.

That trust is, to put it bluntly, failing. Measuring and assessing risk is a significant part of my job. I constantly ask myself: what systems and processes do we actually trust, and what happens when that trust fails? The same skills that make someone valuable to a security team make them valuable to criminal enterprises.

The difference often comes down to which opportunity arrives first. Right now, threat actors are showing up earlier and with better offers.

Pay people

Criminal recruiters appear to understand one thing: young people with technical skills need money. Displaced professionals need money.

Whereas companies set job requirements emphasizing certifications and degrees, and design hiring processes for candidates with conventional backgrounds. As a result, they overlook an entire generation of talented individuals simply because they don’t know how to reach them – or even how to communicate with them.

Paid mentorship programs and early opportunities change the equation. Experienced security professionals – including ethical hackers – are needed for mentoring teenagers through structured curricula.

Start early, during the teen years, when skills are developing and career paths haven't been set. Partner with schools to embed these programs directly into education. Pay the mentees too, so legitimate work competes with illegitimate offers.

This isn't charity. It's a recruitment strategy.

Why hackers specifically

Social engineering and phishing are still the primary methods threat actors use to breach organizations. Defending against attackers requires people who think like attackers. That mindset doesn't come from textbooks.

Ethical hackers who've spent careers probing systems understand how threat actors operate. They know the techniques. They know the psychology. They know which defenses actually hold up under pressure and which ones just look good in a presentation.

A curriculum designed by people who've done the work – legally – transfers practical knowledge that traditional education misses. It also signals to young people that their unconventional skills have legitimate value.

What we get from this

Embedding mentorship into school programs and industry partnerships does two things:

It creates a viable alternative to criminal recruitment. When a technically skilled teenager has a clear path to paid, legitimate work, the dark web job posting loses appeal.

It also builds defenders who learned by breaking things. We need people who understand how systems fail, not just how they're supposed to work.

Timing, mentorship and opportunity often distinguish a security researcher from a cybercriminal. The existence of this talent pipeline is not within our control; however, we have the opportunity to determine the direction in which it progresses.

Criminal enterprises aren't moving slowly

Every month we delay building our talent pipelines, criminal enterprises are filling theirs. They don't require certifications or degrees. They meet talented people where they are and offer them work and mentorship.

We can do the same thing. Pay experienced hackers to teach. Pay young people to learn. Build curricula that transfer real skills.

Or keep posting job requirements that filter out exactly the people we need. The skills exist.

Where they end up – that is on us.

We've featured the best online learning program.

This article was produced as part of TechRadar Pro Perspectives, our channel to feature the best and brightest minds in the technology industry today.

The views expressed here are those of the author and are not necessarily those of TechRadarPro or Future plc. If you are interested in contributing find out more here: https://www.techradar.com/pro/perspectives-how-to-submit