My Personal View on Cybersecurity (CySec)
Nature of Work
Academic
Profession
Assistant Professor
Email Address
[email protected]

Jehad Hamamreh

Nature of Work
Academic
Profession
Assistant Professor
Email Address
[email protected]
My Personal View on Cybersecurity (CySec)

The Only Way to Get Close to Secure? Build It Yourself.

A Personal Reflection

I have a confession that makes me sound like a paranoid hermit living in a bunker: I don't trust the devices I buy.

Not fully. Not ever.

It's not that I think companies are out to get me—well, not most of them. It's that I've realized something uncomfortable over the years. Security isn't something you can buy. It isn't something you can download. It isn't even something you can fully delegate to the smartest team of engineers in the world.

Security is something you have to build.

And I don't mean that in a metaphorical sense. I mean it literally. If you want to get anywhere close to being secure—truly secure—you have to understand your devices, your networks, your systems, and your applications from the ground up. You have to be willing to get your hands dirty.

I know how extreme that sounds. I know it's not practical for everyone. But stay with me, because I think this philosophy has something to teach all of us—even if we never write a single line of code.


The Illusion of the "Secure" Box

Let me paint you a picture.

You walk into a store. You buy a router. You take it home, plug it in, type in the default password, and connect your laptop. You feel good. The box said "Enterprise-Grade Security." The reviews were great. You're safe.

Except you're not.

That router? It's running firmware written by a team you've never met, in a country you've never visited, with priorities you don't understand. It has backdoors you don't know about. It has default settings that prioritize convenience over safety. It has vulnerabilities that won't be discovered until a hacker in a basement somewhere decides to make a name for themselves.

And that's just the router.

Your phone, your laptop, your smart TV, your doorbell camera—every single one is a black box. You press buttons and hope for the best. You trust that the people who built them knew what they were doing.

But here's the thing about trust: it's not a security strategy. It's a gamble.


Why Building Changes Everything

I didn't always think this way.

For most of my life, I was a consumer. I bought things, plugged them in, and assumed they worked. Then one day, I decided to build my own computer. Not because I needed to—I could have bought one cheaper—but because I wanted to understand.

I wanted to know what every component did. I wanted to choose every part, assemble it myself, install the operating system from scratch, and configure every setting.

It was messy. It took hours. I made mistakes. I almost fried the motherboard.

But when I finally booted it up, something had changed. I wasn't just a user anymore. I understood the machine. I knew which ports were open and why. I knew what services were running and what they did. I knew exactly where my data lived and how it moved.

That machine wasn't more secure than a store-bought one in any technical sense. But I was more secure—because I knew its ins and outs. I could spot anomalies. I could make informed decisions. I wasn't flying blind.

That experience changed everything for me.


The Network: Your Digital Neighborhood

Let's talk about networks, because this is where most people's security falls apart.

Your home network is like a neighborhood. All your devices are houses, and they're all connected by streets. If one house gets broken into, the burglar can wander the streets and try the doors of every other house.

Most people never think about their network. They plug in the router, connect their devices, and call it a day. They don't segment their smart home devices from their work devices. They don't monitor who's knocking on their digital doors. They don't even change the default password.

I get it. It's boring. It's technical. It's easier to just not think about it.

But here's what I've learned: building your own network—even in a small way—changes your relationship to it.

When I set up my home network, I did it from scratch. I chose the hardware. I installed open-source firmware. I configured the firewall rules myself. I set up VLANs to separate my IoT devices from my personal machines. I monitored the traffic for a week just to see what was normal.

Was it overkill? Probably. Did it take forever? Absolutely.

But now I know my network. I know what normal looks like. And when something looks off, I notice it immediately. I don't wait for an antivirus alert or a data breach notification. I see it in real time.

That's not paranoia. That's awareness.


Systems and Applications: The Parts You Actually Control

This is where the philosophy gets real.

If you're running a business—or even just managing your own digital life—the applications you use are your biggest vulnerability. Every piece of software is a potential entry point. Every plugin, every integration, every third-party service is a door you've opened.

Most people outsource this entirely. They use WordPress with fifty plugins. They connect every tool to every other tool. They give permissions without reading the fine print. They click "Allow" on anything that makes their life easier.

I used to do that too. Then I got burned.

After that, I made a decision: I would only run software I understood. Not software I wrote necessarily—I'm not a full-time developer—but software I had vetted. Software I had configured myself. Software I could monitor.

If an application required permissions that didn't make sense to me, I didn't install it. If a plugin had a suspicious number of security advisories, I found an alternative. If I couldn't explain to someone else exactly how a system worked, I assumed I didn't understand it well enough to secure it.

This approach is time-consuming. It's impractical at scale. I fully admit that.

But here's the thing: security isn't about convenience. It's about trade-offs.


Why This Isn't Just for Techies

At this point, you might be thinking: This is great for you, but I'm not a systems administrator. I don't have time to build my own router. I just want to live my life.

And you're right. This approach isn't for everyone. It's not realistic for most people.

But here's what I've realized: you don't have to build everything yourself. You just have to understand it.

Understanding your devices doesn't mean assembling them from raw components. It means knowing where your data goes. It means changing default passwords. It means turning off features you don't use. It means asking questions before you click "I Agree."

Understanding your network doesn't mean setting up VLANs from scratch. It means knowing what's connected to it. It means separating your work devices from your kids' tablets. It means rebooting your router occasionally and checking for firmware updates.

Understanding your applications doesn't mean writing your own software. It means reading the permissions. It means deleting accounts you don't use. It means being intentional about what you connect to what.

The principle isn't about technical ability. It's about agency.


The Hard Truth No One Wants to Hear

Here's the uncomfortable conclusion I've reached after years of thinking about this:

You will never be completely secure. And that's okay.

The goal isn't invulnerability. The goal is awareness. The goal is reducing your attack surface. The goal is making it harder for someone to hurt you than it's worth.

Every device you add, every network you join, every application you install is a new potential vulnerability. You can't eliminate risk—you can only manage it.

And the best way to manage risk is to know what you're dealing with.

When you build your own devices, you know their limitations. When you configure your own network, you know its boundaries. When you vet your own applications, you know their flaws. You're not in denial. You're not relying on marketing claims. You're operating in reality.

That's what security looks like. Not a fortress. Not a guarantee. Just a clear-eyed understanding of what you're up against.


What I've Learned Along the Way

Let me leave you with a few lessons from my own journey:

First: start small.
You don't need to build a data center. Just set up a Raspberry Pi. Run a home server. Play with open-source firmware on an old router. The goal isn't perfection—it's curiosity.

Second: read the manuals.
It sounds boring, but most security flaws come from default settings and basic ignorance. Take an hour to understand your devices. You'll be shocked at what you learn.

Third: trust but verify.
If a company says they care about security, ask how. Look for transparency. Read their incident reports. Check their track record. Don't take their word for it.

Fourth: build a habit of maintenance.
Security isn't a one-time project. It's an ongoing practice. Update your software. Review your permissions. Audit your connections. Make it part of your routine.

Fifth: accept that you'll make mistakes.
I've locked myself out of systems. I've misconfigured firewalls. I've accidentally exposed data I shouldn't have. It happens. Learn from it and move on.


The Bottom Line

I'm not telling you to become a cybersecurity expert. I'm not telling you to build your own laptop from scratch.

I'm telling you to take ownership.

Because at the end of the day, security isn't about technology. It's about relationship—your relationship with the digital tools you rely on every single day.

If you treat your devices as mysterious black boxes, you're vulnerable. If you treat them as extensions of yourself—things you understand, things you maintain, things you've intentionally built—you're far closer to being secure than any piece of software could ever make you.

The boxes don't protect you. Your knowledge does.

So get curious. Get your hands dirty. Build something.

It's the only way to get close.


This article reflects my personal philosophy, not professional advice. I'm not infallible, and neither is my setup. But I sleep better at night knowing exactly what's in my digital world—and that's worth more to me than any certification ever could.