this post was submitted on 06 Aug 2026
5 points (100.0% liked)

cybersecurity

6404 readers
34 users here now

An umbrella community for all things cybersecurity / infosec. News, research, questions, are all welcome!

Community Rules

Enjoy!

founded 3 years ago
MODERATORS
 

Just a bit of an open discussion really...

I did my CEH a few years ago and luckily work paid for it - if it was my own money, I'd be asking for a refund.

The course content included stuff from ~10 years earlier, inc. referring to tools that hadn't been maintained (ie in github) for years and basically didn't work any more... and topics like warchalking.. ok, it's interesting to know the history, but as the Wikipedia article mentions, I don't think it really took off and no-one uses it anymore.

So, I let my certification slide and the EC Council have been continually trying to "remind" me to pay for my membership.

I just don't have the feeling that they're really trying to keep up and improve the industry.

I'm now managing a team of Cyber Security Engineers and this came up as a training topic recently, so I'm looking for others to help me reset my bias.

So... did you have the opposite experience?

top 9 comments
sorted by: hot top controversial new old
[–] UnpopularCrow@lemmy.world 1 points 6 days ago (1 children)

It isnt respected in the hacker community but it is in the HR community for job postings. Sec+ has better content and is a fraction of the cost. And if you want to prove hands-on skills, OSCP is nearly the same price and well respected by everyone.

In my opinion, CEH has done a tremendous job at branding. Non-cyber tech people all know it. But the content is beginner level stuff.

[–] Cyber@feddit.uk 1 points 6 days ago

Good point on the branding, I think most of the fees are.going to the marketing dept. not the course content dept.

[–] SpaceMan9000@lemmy.world 2 points 1 week ago

While I don't have the certificate myself, I have seen a lot of colleges go for it since they see it as easily attainable.

I must say that I've met quite a few people who have the cert and we're basically useless.

[–] orbital@infosec.pub 2 points 1 week ago

I had a CEH but let it expire, like you. I've taken & passed a handful of certifications over several years. (Haven't failed one yet.) More value and higher quality content, both academic and practical, can be found in other certification programs. CompTIA Security+ would be a prime example. It's roughly "entry level" much like CEH.

[–] driftWood@infosec.pub 1 points 1 week ago

I am in the same situation. I have decided its not worth the time, effort and money to renew it. I have enough industrial experience now that the cert doesn't matter. I still keep it in resume to get past the initial screening where they only check if someone has some certs.

[–] FergleFFergleson@infosec.pub 1 points 1 week ago (1 children)

My experience with it wasn't quite the same, but was similar. When I was looking at it, it was very much in that category of cert that was mostly about memorizing the study guides/books, and less about building/proving a skillset (which, as mentioned, is hardly uncommon with IT certs unfortunately).

Where it did have some "value" was that it was a well-known cert that was very useful for "proving" that your org was in compliance. A badge you could hang to auditors and costumers/clients that said you knew your stuff. Again, hardly uncommon with IT certs. :\

I don't think it's completely worthless. Depending on where you're at in your career, it can be a useful experience. But it should, I think, be treated like a (relatively) beginner-tier cert. Something you might consider at an early point in your journey, but not one I'd necessarily build your resume around. I also think that it's value may depend a lot on exactly what your role in an organization looks like. CEH for an entry-level pen tester or incident handler? Yeah, maybe. For something like an IAM developer or a privacy analyst... eh, less so.

[–] Cyber@feddit.uk 1 points 6 days ago

Yep, partially we see the certs as just differentiators between us and "the others" for our customers.

In reality, we don't even do half the things needed to get the certs (take CCNA for example... IPv6 still isn't in use for our customers)

[–] frongt@lemmy.zip 0 points 1 week ago (1 children)
[–] Cyber@feddit.uk 1 points 6 days ago

True, although some are good differentiators, like CISSP.

But, for CEH, it felt like doing a CCNA from 1982