People hear "cybersecurity" and picture a hooded figure behind a keyboard.'

My path didn't look like that.

I came into cyber through law enforcement. Working traffic enforcement, running interdiction, and spending time around gang investigations. It was real-world threat work: patterns, indicators, intent, networks, and consequences. Back then, the "environment" was roads, neighborhoods, faces, plates, and paperwork.

Now the environment is logs, IPs, endpoints, cloud consoles, and incident timelines.

But the work feels familiar.

Because cyber investigations, at its core, is still investigation.

Traffic enforcement taught me to see what other people miss

Traffic enforcement gets dismissed as "just writing tickets" by people who haven't done it.

But anyone who has worked the road knows it's not that simple.

It teaches you to read the environment fast:

  • what "normal" looks like in a lane of traffic
  • what behavior doesn't match the situation
  • how to spot the small details that usually lead to the bigger story

You learn quickly that most big things don't announce themselves loudly.

They show up as something slightly off: a hesitation, a pattern, an inconsistency, a detail that doesn't fit.

That same exact skill transfers into cyber.

In cyber investigations, most serious problems don't start with a dramatic alert. They start as something small:

  • a login that doesn't match the user's normal behavior
  • a weird spike in outbound traffic
  • a service account being used at the wrong time
  • a machine talking to a place it normally never talks to

Traffic work trained me to trust that feeling of "this isn't right" and then prove it.

Gang investigations taught me the most important thing: everything is connected

Gang work changes how you look at incidents.

You stop looking at events as isolated moments. You start looking at them as connected behavior.

A stop isn't just a stop. A person isn't just a person. A location isn't just a location.

There's a network behind it.

That mindset is pure cyber.

In cyber investigations, you're always asking:

  • What is this connected to?
  • Who else touched this system?
  • What happened before this?
  • What happens after this?
  • If this is the entry point, what's the target?

Attackers don't operate in single actions. They operate in chains.

So do gangs. So do threat actors. So does organized activity.

Different environment. Same structure.

Interdiction taught me timelines and intent

On the street, you learn to build the story from the order of events:

  • where someone came from
  • where they're going
  • what changed in their behavior
  • what doesn't match their explanation
  • what indicators show intent

In cyber investigations, the "where" becomes digital:

  • first access time
  • persistence methods
  • lateral movement
  • privilege escalation
  • exfiltration attempts

But the goal is the same:

Build the timeline. Identify intent. Explain impact.

The real bridge: reporting

Here's the part nobody talks about enough:

Cyber isn't just technical. It's communication.

Law enforcement forced me to get good at reporting because the report is the case.

You can do everything right in the field, and if you can't document it clearly, it didn't happen.

That lesson translated directly into cyber:

  • incidents don't matter if you can't explain them
  • technical findings don't matter if leadership can't understand them
  • "we think" doesn't matter unless you can back it up

Cyber reporting is basically the same muscle, just different evidence.

Instead of witness statements and physical evidence, it's:

  • logs
  • timestamps
  • alerts
  • artifacts
  • indicators of compromise
  • screenshots
  • system state

And the same rules apply: clear, factual, chronological, defensible.

What I carried from law enforcement into cyber (without realizing it)

When I first moved into cyber, I thought I'd be starting from scratch.

I wasn't.

I already had the core of the job:

  • Pattern recognition: seeing abnormal behavior and anomolies in a sea of normal
  • Threat awareness: understanding how bad actors move and adapt to their tone
  • Interview mindset: separating facts from noise, testing explanations and asking deeper questions
  • Case-building: connecting events into a timeline that makes sense
  • Reporting discipline: writing it clearly enough to stand on its own

Cyber tools can be learned. Investigation mindset takes time.

Law enforcement gives you that mindset early where college will not.

The difference now: the scene is digital

One thing I love about DevSecOps is that the evidence is often sitting there waiting to be found, and ctrl+f can save the day

You don't have to rely on memory. You don't have to rely on someone telling the truth. You don't have to relay on a 4 year debt and a single sheet of paper

You can pull the artifacts. You can trace the timeline. You can correlate what happened across systems. You can show it.

And the better you get at analysis, the more you realize cyber is closer to investigative work than most people admit, "finding the source."

Closing

If you're in law enforcement and looking at cyber thinking, "I'm not technical enough," here's what I'd tell you:

You might be more prepared than you think.

If you can:

  • notice patterns
  • stay calm under pressure
  • work a case methodically
  • write a report that holds up

…then you already have the foundation.

Cyber investigations is still investigations at the root.

The street taught me how to read people, behavior, and patterns.

Cyber taught me how to read systems, activity, and artifacts and push me to new bounds.

Same instincts. New terrain. Same mission: find the truth, document it, and protect what matters.