What's your opinion on CEH & EC Council
from Cyber@feddit.uk to cybersecurity@infosec.pub on 06 Aug 22:48
https://feddit.uk/post/53471007

Just a bit of an open discussion really…

I did my CEH a few years ago and luckily work paid for it - if it was my own money, I’d be asking for a refund.

The course content included stuff from ~10 years earlier, inc. referring to tools that hadn’t been maintained (ie in github) for years and basically didn’t work any more… and topics like warchalking… ok, it’s interesting to know the history, but as the Wikipedia article mentions, I don’t think it really took off and no-one uses it anymore.

So, I let my certification slide and the EC Council have been continually trying to “remind” me to pay for my membership.

I just don’t have the feeling that they’re really trying to keep up and improve the industry.

I’m now managing a team of Cyber Security Engineers and this came up as a training topic recently, so I’m looking for others to help me reset my bias.

So… did you have the opposite experience?

#cybersecurity

threaded - newest

SpaceMan9000@lemmy.world on 06 Aug 23:20 next collapse

While I don’t have the certificate myself, I have seen a lot of colleges go for it since they see it as easily attainable.

I must say that I’ve met quite a few people who have the cert and we’re basically useless.

orbital@infosec.pub on 07 Aug 00:29 next collapse

I had a CEH but let it expire, like you. I’ve taken & passed a handful of certifications over several years. (Haven’t failed one yet.) More value and higher quality content, both academic and practical, can be found in other certification programs. CompTIA Security+ would be a prime example. It’s roughly “entry level” much like CEH.

frongt@lemmy.zip on 07 Aug 01:16 next collapse

Most certs are like that.

Cyber@feddit.uk on 07 Aug 08:25 collapse

True, although some are good differentiators, like CISSP.

But, for CEH, it felt like doing a CCNA from 1982

driftWood@infosec.pub on 07 Aug 05:01 next collapse

I am in the same situation. I have decided its not worth the time, effort and money to renew it. I have enough industrial experience now that the cert doesn’t matter. I still keep it in resume to get past the initial screening where they only check if someone has some certs.

UnpopularCrow@lemmy.world on 07 Aug 08:15 collapse

It isnt respected in the hacker community but it is in the HR community for job postings. Sec+ has better content and is a fraction of the cost. And if you want to prove hands-on skills, OSCP is nearly the same price and well respected by everyone.

In my opinion, CEH has done a tremendous job at branding. Non-cyber tech people all know it. But the content is beginner level stuff.

Cyber@feddit.uk on 07 Aug 08:23 collapse

Good point on the branding, I think most of the fees are.going to the marketing dept. not the course content dept.