B.C. — 001 / 2026SG · GMT+8
CH · 00 / HEROSCROLL ↓
◉ Brandon Cheong
00 / HERO

Jul 14, 2026

Teaching

Teaching offensive security without giving HR a heart attack.

How to make breaking things feel like a legitimate career path to students who still think hackers wear hoodies in summer.

The first thing I tell students is that most hackers spend their day reading documentation, not typing into green terminals. The second thing is that the documentation is usually wrong.

Offensive security is a hard sell in a classroom. It sounds illegal, or at least impolite. I start with the boring parts: scoping, rules of engagement, evidence handling, and how to write a report that does not make the client cry.

Once the bureaucracy is normalised, the fun starts. We look at real CVEs, build intentionally vulnerable machines, and break them in increasingly theatrical ways. The theatrics are not gratuitous — they help people remember why a buffer overflow matters when they are three hours into an exam.

My best students are the ones who ask annoying questions. The ones who want to know why the payload works, not just that it works. Those are the people who end up good enough to stop needing me.