Just a bit of an open discussion really…
I did my CEH a few years ago and luckily work paid for it - if it was my own money, I’d be asking for a refund.
The course content included stuff from ~10 years earlier, inc. referring to tools that hadn’t been maintained (ie in github) for years and basically didn’t work any more… and topics like warchalking… ok, it’s interesting to know the history, but as the Wikipedia article mentions, I don’t think it really took off and no-one uses it anymore.
So, I let my certification slide and the EC Council have been continually trying to “remind” me to pay for my membership.
I just don’t have the feeling that they’re really trying to keep up and improve the industry.
I’m now managing a team of Cyber Security Engineers and this came up as a training topic recently, so I’m looking for others to help me reset my bias.
So… did you have the opposite experience?


Yep, partially we see the certs as just differentiators between us and “the others” for our customers.
In reality, we don’t even do half the things needed to get the certs (take CCNA for example… IPv6 still isn’t in use for our customers)