Studied Journalism. Now I Work in Cybersecurity. Here’s What Actually Matters.

by Tomasz Szulczewski | Jul 27, 2026 | Career, Cybersecurity | 0 comments

I work in cybersecurity, and at almost every conference talk or professional presentation, someone asks the same question:

"How did a journalism graduate end up in cybersecurity?"

Without a computer science degree. No connections in tech. No Plan B. Just one book about Exchange Server - and 25 years of building from there.

Here's the honest version of that story.

work in cybersecurity
work in cybersecurity

Follow your talent, not your passion

Professor Scott Galloway has a line that I've thought about for years:

"Don't follow your passion. Follow your talent. Anyone who tells you to follow your passion is already rich."

Journalism was youthful idealism. I wasn't bad at writing. But I also wasn't determined enough, or talented enough in the right ways, to break into the group of people who make real money from it - especially in Poland in the late 90s.

What I had was a natural feel for computers. People always said I was "good with tech." And at the end of the 90s, when businesses were building their first internal networks, that actually meant something.

So I stopped chasing the vague ideal and moved toward what I was actually good at.

A job posting in a newspaper decided easy. (Yes, job postings were in newspapers back then.)

One book. One interview. One career.

If you think that work in cybersecurity was my primary choice, you’re wrong. But here’s how it started. The company was looking for an Exchange Server administrator. I did not know what Exchange was.

I went to a bookstore and bought Exchange Server Administration 5.5. Read it cover to cover. Memorized it, basically.

Then I walked into the interview.

The man who interviewed me knew even less about Exchange than I did. I got the job.

That was the year 2000. Twenty-five years later, I work remotely, earn $100/h as a cybersecurity consultant, and build my own brand. Nobody planned this path for me. There was no plan B - just that one book.

What 25 years in IT actually looks like

The next decade-plus was a steady climb: helpdesk, network admin, sysadmin, engineer, architect. Every promotion meant learning something new - because I had to, because I was curious, because in IT, standing still is moving backwards. I do not believe that you can work in cybersecurity without prior experience in basic IT stuff. You can easily check my journey on my LinkedIn profile.

Microsoft became my environment. Active Directory, Exchange, SharePoint, then the full Microsoft 365 stack. Certifications came along the way, but they were always the byproduct of curiosity and project requirements - not the goal.

In 2015 I became an independent consultant. That was the leap I’d been afraid to make for years. A full-time job feels safe. Consulting meant building my client base, managing my own finances and reputation - entirely fresh territory.

What I learned quickly: clients don't care about certifications. They care about whether you can solve their problem. And whether you can explain it in plain language - not in documentation jargon they didn't ask to read.

This is where journalism came back. Writing clearly for non-specialists, explaining complex things simply, building a narrative - the same skills I'd thought were wasted turned out to be exactly what clients needed from a cybersecurity advisor.

Why I do work in cybersecurity. Why SMBs specifically.

Cybersecurity didn't arrive in my life through a dramatic decision. It crept in through M365 projects.

Every implementation ended the same way - questions about phishing, about MFA, about whether the Defender licenses anyone was paying for actually did anything. Slowly, without planning it, I kept adding pieces to my portfolio.

Today I specialize in securing Microsoft 365 environments for companies with fewer than 300 people. Very specific niche.

These are businesses that have Microsoft 365 Business Premium, but nobody ever told them what to do with the security features. They have licenses for Defender for Endpoint. They are in possession of Intune. They are buying tools that are completely unconfigured, similar to a smoke alarm with a dead battery.

Large corporations have entire security departments. I work with companies where the owner asks "are we secure?" and nobody in the room can answer.

The client who got lucky

A few months ago I worked with an 80-person manufacturing company. They called me after receiving an email "from the CEO" requesting an urgent wire transfer.

Fortunately, someone picked up the phone and called the actual CEO before clicking send. A Business Email Compromise attack failed because of one good instinct.

When I ran the audit of their Microsoft 365 tenant: no MFA, no Conditional Access policies, Defender and Intune licenses completely unused. This company was literally ten minutes from a disaster they avoided through luck - not through any security controls.

Research shows that roughly 60% of SMBs that suffer a cyberattack shut down within six months. These aren't abstract statistics. They're real businesses, real owners, years of work disappearing because of one email that looked legitimate.

This is why the work matters. Not technology for its own sake. So companies stay open. So people keep their jobs.

What I'd do differently

Specialize faster. The years I spent as a generalist built valuable foundations, but the real demand - and the real rates - came with a specific niche. M365 security for SMBs is more compelling to the right client than IT consultant who does everything.

Don't wait for perfect conditions before going independent. The right time doesn't arrive on its own. You create it. If you want to work in cybersecurity, there’s no perfect time; you'll never be ready, there’s always something to improve.

And pay attention to burnout earlier. I stayed too long in one role - stable, well-paid, and slowly draining. When the thought of sitting at a computer started to feel physically repulsive, that was a signal I should have acted on sooner.

Work in cybersecurity - the Bottom line

In IT, the winner isn't the one with the diploma. The winner is the one who doesn't stop.

A cybersecurity career doesn't require a CS degree. It requires curiosity, consistency, and genuine willingness to keep learning for the rest of your working life.

I started with a book about Exchange Server. Almost 30 years ago.

You can start today.

Written by Tomasz Szulczewski

Hi, my name is Tomasz Szulczewski, and I have been in love with information technology for over 25 years, but I still have an IT passion and feel like a geek. I am a person who is problem solver who thinks that not all people must be experts in IT.

Related Posts

I want to be Programmer after 40

Programmer after 40

Programmer after 40? Why not? You can always make a career change to IT at 40, but does it make sense? I have decided to write this post as my personal situation has changed again 🙂 . Anyway, I also wrote about it on my Polish blog, and I was shocked that I got so...

read more...

0 Comments

Submit a Comment

Your email address will not be published. Required fields are marked *