One of the things that concerns me about the direction of Information Security as a discipline is the focus on what I call "gee whiz security". This is the flashy, trendy stuff like new attacks and the marketing terms of the moment (that often are actually meaningful terms that marketing people misuse or misappropriate). It is good to stay on top of new developments, new attack vectors, new defense ideas, etc. but (for most of us that are employed by a company) our job is to provide solutions to solve these issues or provide suggestions on how to mitigate the risks associated with these threats. If all you provide is a constant stream of risks and concerns without any meaningful solutions or ideas on how to manage a problem, your employer is likely going to have to look elsewhere. This is why when folks ask me about penetration testing as a career choice I advise them to consider a more balanced approach. You can find any number of people or companies that will tell you...
Ideas, tips, tricks, and theory on Information Security, risk management, forensics, and e-discovery.