GetCyber Dan Duran, MSc Cybersecurity, MBA, CISSP, CCSP

Advisor & Speaker for

I analyze how attackers navigate modern attack paths, using those insights to advise organizations and lead industry discourse on critical security strategy.

Real Attack Path Analysis

Research-driven analysis of privilege, access, escalation, and data exposure.

Clear, Prioritized Decisions

Authoritative findings, real-world impact, and practical, outcome-driven next steps.

  • Government and public sector
  • Critical infrastructure & defense
  • Healthcare and sensitive data
  • Regulated financial systems
  • Legal, tax, and professional services
  • Institutional & higher education
Cybersecurity advisory and conference presentation
The Hybrid Advantage

Hacker Insight. Executive Judgment.

Security work is only valuable if it leads to clear decisions. I bridge the gap between technical exploitation and strategic risk management to ensure your defenses are built for the actual threat landscape, not just a checklist.

The Hacker's Lens

Attacker Perspective

I assess your environment by identifying realistic attack paths—informed by my ongoing research into identity compromise, over-permissioned access, and cloud exposure.

  • Identity-First: Hunting for initial exploitation, privilege escalation and lateral movement paths.
  • Data Exposure: Locating overshared M365/SaaS data before an attacker does.
  • Realism Over Theory: Prioritizing vulnerabilities that are actually exploitable.
  • Validated Findings: Grounding risk in technical proof and industry-leading research, not scanner noise.
The Advisor's Lens

Advisory Judgment

Findings are translated into a prioritized roadmap. I help leadership move from technical uncertainty to strategic clarity through research-backed insights.

  • Risk-First Approach: Aligning security needs with business impact and industry-standard best practices.
  • Actionable Remediation: Providing clear, direct steps to close exposure gaps quickly.
  • Decision Support: Reducing uncertainty with the same clarity I provide to my global industry audience.
  • Governance Alignment: Contextual mapping to NIST, CIS, and ISO 27001 principles.

No Compliance Theater

I avoid long, generic reports and "checkbox" security audits that offer no real protection.

Research-Led Insight

I focus on assessment-first strategies that prioritize deep human insight over automated tool saturation.

High-Signal Output

You get a concentrated analysis of your actual attack surface and an authoritative path to fix it.

Personable. Built on Trust.

Why Organizations Work With GetCyberTM

Assessments built to identify meaningful exposure, reduce risk, and provide clear next steps in modern, sensitive, and regulated environments.

Expert-Led

Work directly with Dan informed by technical depth, business context, and real-world attack paths.

About Dan

Assessment-First

Clear assessments with bounded scope, practical outcomes, and a disciplined approach to risk review.

View Assessments

Actionable Findings

Get prioritized findings and next steps that can support remediation, planning, and better security decisions.

Discuss Your Requirements

Efficient Process

Short engagements designed to surface high-impact issues without turning the work into a long consulting cycle.

See the Process

Industry Authority

Engage with a recognized voice whose research and insights are followed by over 40,000 industry professionals.

Speaking & Workshops

Relevant to Sensitive Environments

Assessments are especially relevant where identity, cloud access, sensitive data, AI use increase security stakes.

Explore Sector Focus
Secure Your Environment or Engage an Expert Voice

Whether you need a focused security assessment to identify critical exposure or a recognized authority to speak at your next event, I provide the technical depth and executive judgment needed to navigate modern risk.

Security Assessment Services

Entry-point assessments designed to identify material exposure in sensitive, regulated, and operationally critical environments.

Why This Matters

Most breaches today do not start with infrastructure. They start with identity, access, and data exposure across cloud systems.

How It Works

A clear process for identifying meaningful exposure and turning it into practical next steps.

01

Initial Review

We review your environment, current concerns, and operating context to define the scope of the assessment around the areas with the highest potential risk.

02

Assessment

We analyze identity, access, cloud exposure, data handling, and other relevant controls to uncover realistic attack paths, weaknesses, and control gaps.

03

Findings & Next Steps

You receive prioritized findings with practical recommendations so you can address the most important issues first and move forward with clarity.

Case Studies

Real examples of risks identified and resolved across client environments.

Reducing Identity-Based Attack Paths

Problem Over-permissioned accounts exposure across critical systems

Broad permissions across finance, operations, and shared systems increased the impact of a compromised account and created unnecessary exposure across critical areas of the business.

Read more

A manufacturing organization had accumulated broad user and account permissions over time without enough restriction or review. Access had expanded beyond actual business need, increasing the risk associated with identity misuse or compromise.

The core issue was not just excessive access on paper. It was the ability for one compromised account to move laterally into business-critical areas, exposing sensitive data, operational workflows, and administrative functions that should have been more tightly segmented.

Solution Access was reviewed, reduced, and aligned to least privilege

Permissions were reviewed and reduced to better match actual job function, with tighter boundaries between sensitive systems and roles.

Read more

A focused access review was conducted to identify over-permissioned accounts, outdated access rights, and weak separation between business roles. Permissions were reduced to match actual responsibility, privilege boundaries were tightened, and segmentation between sensitive areas was improved.

This approach limited unnecessary access paths and reduced the likelihood that a single compromised identity could be used to pivot across the environment.

Results Lower exposure, stronger control, and better visibility

The organization reduced cross-system exposure and gained stronger control over how identity-based access was managed across the business.

Read more

The organization finished with a more controlled identity environment, reduced cross-system exposure, and stronger alignment with least privilege principles.

Internal access was more disciplined, potential attack paths were narrowed, and leadership gained clearer visibility into identity-based risk across the business.

Reducing IT Overspending in an Educational Institution

Problem Rising technology costs with limited visibility into waste and overlap

The organization was spending heavily across IT services, software subscriptions, and security tools without clear visibility into duplication, underused licenses, or unnecessary recurring costs.

Read more

An educational institution had accumulated a mix of software subscriptions, outsourced services, cloud tools, and security products over time. Many decisions had been made reactively, often to solve immediate operational needs, without a full review of how the overall environment fit together.

The result was growing monthly cost, limited accountability around vendor value, and overlapping tools that created budget pressure without clearly improving service delivery or security. For an organization with finite resources, this reduced the funds available for core mission priorities.

Solution IT and security costs were audited to reduce waste and overlap

A focused audit was performed across vendors, licensing, services, and recurring technology spend to identify unnecessary cost and recommend practical reductions.

Read more

The assessment examined software licensing, managed services, vendors, duplicated capabilities, inactive or underused tools, and areas where spend had grown without enough strategic oversight. Existing contracts and service dependencies were reviewed to separate essential operational requirements from avoidable cost.

Recommendations focused on reducing overlap, consolidating tools where appropriate, right-sizing licensing, and improving decision-making around future technology purchases. The goal was not simply to cut cost, but to reduce waste while preserving operational continuity and necessary security coverage.

Results Lower costs, better visibility, and more efficient resource allocation

The organization gained clearer visibility into where money was being spent and where recurring costs could be reduced without weakening essential operations or security.

Read more

By the end of the audit, leadership had a more structured view of technology spending, clearer understanding of vendor value, and a prioritized set of cost reduction opportunities that aligned with the organization’s operational reality.

This created a more sustainable IT model for the institution, improved budgeting discipline, and helped ensure more resources could be directed toward mission-critical work rather than unnecessary technology overhead.

Led by Dan Duran

Dan Duran, MSc Cybersecurity, MBA, CISSP, CCSP

Cybersecurity Researcher | Sr. Risk Advisor

Dan works directly with organizations to identify real attack paths, reduce exposure, and improve security posture across Microsoft 365, modern SaaS, identity, data, and AI-related environments.

Combining technical depth with a recognized industry voice, Dan provides both focused security advisory and authoritative speaking for conferences and leadership events—translating complex risk into clear, strategic action for sensitive and regulated environments.

20+ Years

Experience across cybersecurity, development, systems, and advisory work.

MSc Cybersecurity • MBA

Technical depth combined with business and strategic perspective.

CISSP • CCSP

Industry-recognized certifications in security and cloud security.

Practical Risk Focus

Practical guidance on identity, cloud exposure, sensitive data, and modern attack paths.

Next Engagements

Upcoming speaking appearances, podcasts, event sessions, and media content.

AI  |  CYBER Apr 22, 2026

Panelist: Top Skills for 2026 – AI, Cybersecurity, Cloud & Beyond.

Dan Duran joins triOS College as a panel speaker for “Top Skills for 2026 – AI, Cybersecurity, Cloud & Beyond.” This session brings together industry leaders to discuss how modern IT environments are evolving—and where real risk is emerging.

  • Venue: Virtual (via Zoom),
  • Date & Time: May 20, 2026, 5:PM EST
  • Duration: 30–40 min, 15–20 min live Q&A
CYBER Apr 22, 2026

Defensive Strategy: Protecting Your Digital Identity & Assets

Dan Duran delivers high-impact cybersecurity insight tailored for the risks facing established adults. Moving beyond basic tips, Dan bridges hacker logic with practical defense to help you recognize sophisticated scams, secure your financial footprint, and use technology with total confidence.

Videos

Watch the latest videos on cybersecurity, development, and technology. Stay informed with expert insights, tutorials, and industry updates.

Latest Posts

I write about Cybersecurity, DevOps, and Technology. Don't forget to subscribe to my newsletter for the latest updates.

CYBER Apr 22, 2026 | Comments: 0

Defensive Strategy: Protecting Your Digital Identity & Assets

In an era of AI-driven phishing and sophisticated social engineering, "being careful" isn't enough. Dan Duran, cybersecurity researcher and founder of GetCyber, provides a deep dive into the current threat landscape, specifically designed for seniors and their families. Dan will take the lead in providing a comprehensive view of how …

AI  |  CYBER Apr 22, 2026 | Comments: 0

Panelist: Top Skills for 2026 – AI, Cybersecurity, Cloud & Beyond.

Dan will share a practical, attacker-informed perspective on how organizations are compromised across identity, cloud, and data layers, and what that means for the next generation of professionals. The discussion focuses on the skills that actually translate into value in the field: understanding attack paths, securing access and permissions, and …

DEV  |  AI Jan 08, 2026 | Comments: 0

Learning Programming In 2026 Is Not The Same As In 2016

The landscape of learning programming languages in 2026 has fundamentally shifted from a "memorization" game to a "verification" game. We are no longer just "writers" of code; we are its architects and auditors. While AI provides unprecedented velocity, the data suggests that using it as a crutch rather than a …

DEV Apr 01, 2025 | Comments: 0

Anatomy of a Django Project: A Comprehensive Guide to Files and Structure

Django's conventional project and app structure is a cornerstone of its "batteries-included" philosophy, fostering rapid development, maintainability, and seamless collaboration. While the initial startproject and startapp commands generate a standardized foundational layout, real-world applications quickly evolve beyond these basics, incorporating a diverse array of files and directories to manage complexity …

DEV  |  CYBER Mar 01, 2025 | Comments: 0

Pen-Test Lab PART 3 - Installing an Ubuntu VM on QEMU/KVM

This guide will walk you through installing an Ubuntu virtual machine using QEMU/KVM. Prerequisites Ubuntu ISO file (already downloaded and moved to /home/<USER>/ISO/Linux/ubuntu-24.04.2-desktop-amd64.iso) QEMU/KVM environment set up (from the main tutorial) Step 1: Create the Ubuntu VM sudo virt-install \ --name ubuntu-vm \ --memory 4096 \ --vcpus 2 \ --cpu …

DEV  |  CYBER Mar 01, 2025 | Comments: 0

Pen-Test Lab PART 2 - Installing a Windows VM on QEMU/KVM

This guide will walk you through installing a Windows virtual machine with QEMU/KVM and setting up the necessary drivers for enhanced functionality like copy/paste, shared folders, and better performance. Prerequisites Before starting, make sure you have: - A Windows ISO file (Windows 10 or 11) - You can download Windows …