Cybereason is now LevelBlue. Proven endpoint protection, now with greater scale and expanded capabilities. Learn More

Day in the Life of a Cyber Research Communicator: From Threats to Takeaways

Cybersecurity research, threat intel, and novel findings produce no shortage of information. Every day brings new vulnerabilities, malware campaigns, proof-of-concept exploits, threat reports, headlines, and predictions about what comes next.

But what has proven difficult is sorting through the noise to determine what's worth following.

That's a big part of my role as Manager of the SpiderLabs Communications team at LevelBlue. I work between our research teams and our Public Relations and Media teams, helping turn highly technical research into information that customers, security professionals, and the broader public can understand and use.

Ultimately, my goal is to make our threat research meaningful, accessible, and understandable for security practitioners.

 

A career built on constant change

I started working in security in 1995, administering a Sun Solaris network for a CAD company. At the time, the internet looked very different from what we know today. I eventually moved into security reseller field services, managing Check Point and SecurID deployments, became a certified instructor for several security products, and later joined Internet Security Systems as part of the X-Force Education Team. That eventually led to IBM after its acquisition of ISS in 2006.

Over roughly 30 years, I’ve watched the security industry evolve alongside the technology it protects.

When I started, I was the administrator for a Wildcat BBS used to transfer digital blueprints. Today, organizations deal with cloud environments, complex supply chains, AI, ransomware, zero-days, and a globally spread attack surface that would have been difficult to imagine back then.

That history has made me a bit of a security generalist. I’ve worked across enough areas of the industry to understand that the technical details matter, but so does the ability to explain those details to someone who doesn't live in them every day.

That translation is where much of my work begins.

Dedicated to hunting and eradicating the world's most challenging threats.

SpiderLabs

The job starts with a question: does this actually matter?

A typical day might start with something fairly mundane: cleaning out my inbox, flagging new tasks, and prioritizing what needs to happen that day.

From there, things can move quickly.

I might be reviewing a SpiderLabs blog post, coordinating telemetry requests for a threat report, analyzing data returned by one of our research teams, responding to a media request, or helping coordinate LevelBlue’s response to a major emerging threat.

My team also supports LevelBlue’s Responsible Disclosure program. When our researchers identify a new vulnerability in a product or service, we help coordinate communication between the researcher, the vendor, and our legal team until an appropriate fix can be developed.

The work varies, but there’s a common thread: figuring out what information people need and how to communicate it clearly.

That starts with knowing what deserves attention in the first place.

I monitor internally generated threat intelligence, major security news and social media, but I try to distinguish between events that create meaningful real-world risk and headlines that simply generate attention. Cybersecurity has plenty of the latter.

When deciding whether something deserves deeper investigation or escalation, we look at several factors. How old is the threat? Is there an active or publicly available proof of concept? Is it part of an active campaign? How broadly is it affecting organizations? Is the targeted technology widely deployed? And, perhaps most importantly, is there something organizations can actually do about it?

Those questions help separate urgency from noise.

 

Turning technical research into something people can use

Once a research team has uncovered something significant, the next challenge is communicating it without losing what makes the research valuable.

That can mean editing a technical blog post, pulling telemetry and metrics for a report, or working with researchers to make sure an explanation is accurate while still being accessible to someone who isn't an expert in the underlying technology.

That translation matters because education is one of the most practical forms of security.

A technical blog post might reach a security professional who changes a configuration. A threat report might give a customer the context they need to investigate an environment. A presentation might help a security leader make a different decision about a project.

Recently, I saw that happen firsthand.

During a client presentation about AI and security, we had just published research about the risks of allowing AI to monitor security logs without appropriate human oversight. One of the client’s security team members told me that their manager was considering a project that followed exactly that model.

The timing of the research and the conversation helped them reconsider the approach before introducing additional risk into their environment.

That’s the kind of outcome that makes the communication side of cybersecurity meaningful. The goal isn't simply to publish information. It’s to give people something they can use before a problem becomes an incident.

 

Security communication is also a form of risk management

There’s a tendency to think of communications as something that happens after the technical work is finished.

In cybersecurity, that distinction is harder to make.

When a critical vulnerability or widespread malware campaign emerges, communication becomes part of the response. Researchers need to understand what others are seeing. Security teams need actionable information. Customers need to know whether they could be affected. Media organizations may be looking for context. And everyone needs accurate information quickly.

My role can become particularly reactive during those moments. But a lot of our work is proactive, too.

The lessons learned in a research blog published today may help someone avoid a compromise months from now. A threat report can give a security team a better understanding of what to watch for and how to prioritize their response. Responsible disclosure can help a vendor address a vulnerability before it becomes a widespread problem.

The value isn't always immediate or visible.

Sometimes the best outcome is the incident that never happens.

 

The foundation still matters

Cybersecurity can make it sound like there is always a new problem that organizations need to solve.

There will always be new technologies, new attack techniques, and new vulnerabilities. But that doesn't mean security has to be an endless race to catch up.

One of the biggest misconceptions I see is that everything in security is changing so quickly that it’s impossible to keep up. In reality, organizations that establish strong security fundamentals are in a much better position to adapt when something new comes along.

The fundamentals still matter: understand your environment, protect what matters, keep systems updated, maintain good visibility, and build processes that allow you to respond when something goes wrong.

New threats may change the details, but the underlying principles don't change nearly as often as the headlines suggest.

 

Keep learning, keep translating

After three decades in cybersecurity, the part of the job I enjoy most is still learning.

I figured out early in my career that education teaches the teacher as much as anyone. Working with researchers forces me to keep learning about new technologies, techniques, and threats. Translating that work for different audiences forces me to understand it well enough to explain why it matters.

That makes communication more than a final step in the research process. It becomes a way of testing whether we actually understand what we've found.

If we can explain a complex security issue clearly, connect it to real-world risk, and give people something useful to do about it, then the research has moved beyond information.

It has become action. And in cybersecurity, that's ultimately the point.

About the Author

Karl Sigler is Security Research Manager, SpiderLabs Threat Intelligence at LevelBlue. Karl is a 20-year infosec veteran responsible for research and analysis of current vulnerabilities, malware and threat trends at LevelBlue. Follow Karl on LinkedIn.

About LevelBlue

LevelBlue secures what's next with intelligence-led security delivering visibility and speed to stop threats faster. As the world’s largest and most analyst-recognized pure-play managed security services provider, our AI-powered managed services and cyber expertise across managed, advisory, and incident response services help clients operate with confidence. Learn more about us.

Discover how our specialists can tailor a security program to fit the needs of your organization.

Request a Demo