Practice Cyber Skills Like a Musician

Bianca Ionescu

BSidesSF 2026 · Day 1 · AMC Theatre 07

Overview

In a field often characterized by rapid evolution and overwhelming complexity, Bianca Ionescu's talk, "Practice Cyber Skills Like a Musician," offers a refreshing and profoundly practical framework for skill development in cybersecurity. Ionescu, a trained violist who transitioned into the cybersecurity domain, draws a compelling analogy between the rigorous discipline of musical training and the systematic acquisition of cybersecurity expertise. Her presentation challenges the common perception that cybersecurity aptitude is an innate talent, instead positing that structured, deliberate practice, akin to a musician's regimen, is the key to mastering an ever-changing landscape.

Watch on YouTube

Key moments

  1. 0:00 Introduction: Musician's mindset for cybersecurity skills
  2. 3:00 Structured practice and viola demonstration
  3. 4:00 Precision: Beethoven excerpt demo and analysis
  4. 8:00 Importance of ensemble training and feedback
  5. 10:00 Mastery is slow: Practice makes progress
  6. 11:00 Practical application: Break down cyber skills into 'measures'
  7. 12:00 Drill weak areas and practice under pressure

Practice Cyber Skills Like a Musician

Speakers: Bianca Ionescu

Conference: BSides SF

YouTube: https://www.youtube.com/watch?v=joM1K2jbVuU

Overview

In a field often characterized by rapid evolution and overwhelming complexity, Bianca Ionescu's talk, "Practice Cyber Skills Like a Musician," offers a refreshing and profoundly practical framework for skill development in cybersecurity. Ionescu, a trained violist who transitioned into the cybersecurity domain, draws a compelling analogy between the rigorous discipline of musical training and the systematic acquisition of cybersecurity expertise. Her presentation challenges the common perception that cybersecurity aptitude is an innate talent, instead positing that structured, deliberate practice, akin to a musician's regimen, is the key to mastering an ever-changing landscape.

The core of Ionescu's argument is that the principles of practice, precision, and patience—fundamental to a musician's journey—are equally vital for cybersecurity professionals. She highlights the often unstructured and isolating nature of self-study in cyber, which can lead to burnout and a sense of inadequacy, especially for newcomers or those making career transitions. By contrasting this with the feedback-rich, iterative, and communal learning environment of music, Ionescu provides actionable insights for individuals and organizations to foster more effective and resilient cybersecurity talent.

This talk is particularly relevant for anyone struggling with the breadth and depth of cybersecurity knowledge, those seeking a more effective learning methodology, or educators and team leaders looking to cultivate stronger, more adaptable security professionals. Ionescu's unique perspective, informed by her dual background, demystifies the path to mastery, making it accessible and sustainable through a disciplined, yet empowering, approach to skill development.

Background

▶ Watch: Introduction: Musician's mindset for cybersecurity skills (0:00)

The contemporary cybersecurity landscape presents a unique set of challenges for skill acquisition and professional development. The field is characterized by an incessant influx of new technologies, evolving threat vectors, and a vast array of tools and concepts to master. This rapid pace often pushes individuals towards self-study, which, while flexible, frequently lacks the structured guidance, consistent feedback, and deliberate practice routines essential for deep learning. As Ionescu points out, this environment can be incredibly overwhelming for those entering the field or transitioning from other careers, leading to sentiments like, "I'm just not cut out for cyber," or "I'm not technical enough." The underlying issue, she contends, is not a lack of innate ability but rather "the lack of structured skill development."

In stark contrast, musical training, as Ionescu explains, is inherently structured. From foundational drills like scales and exercises designed to build muscle memory and intonation, to the intricate process of breaking down complex pieces, musicians engage in constant, iterative refinement. They benefit from immediate feedback loops within practice rooms, ensemble rehearsals, and private lessons, allowing for continuous adjustment and noticeable improvement over time. This structured approach, which emphasizes deliberate practice, precision in execution, and ensemble learning, provides a robust model for skill development that is often absent in cybersecurity education and professional growth paths.

The problem, therefore, isn't a deficiency in the learners themselves, but rather in the prevalent methods of learning within cybersecurity. Without a clear roadmap, specific techniques for isolating weaknesses, or mechanisms for constructive criticism, aspiring and established professionals alike can find themselves adrift. Ionescu's talk seeks to bridge this gap by translating the time-tested pedagogical principles of music into a practical methodology for cybersecurity skill mastery, offering a much-needed antidote to the pervasive overwhelm and high expectations that define the industry.

Key Findings

▶ Watch: Precision: Beethoven excerpt demo and analysis (4:00)

Ionescu's key findings revolve around three pillars derived from musical training: practice, precision, and patience. These aren't merely abstract concepts but are presented as actionable principles directly transferable to cybersecurity skill development.

First, practice is not just about doing, but about deliberate practice. Simply "playing notes without a plan" is analogous to "just playing notes" in music—it doesn't lead to mastery. In cybersecurity, deliberate practice translates to creating home labs, actively participating in Capture The Flag (CTF) competitions (like those often found at conferences such as BSides), and even repeatedly executing a command until its underlying function is fully understood. This consistent, focused repetition builds confidence and internalizes complex processes, moving beyond mere memorization to genuine comprehension.

Second, precision is paramount. Ionescu illustrates this vividly with a musical excerpt, demonstrating how technically correct notes can still lack impact without the subtle nuances of dynamics, emotion, and tempo. In cybersecurity, this meticulousness is the difference between "simply looking and observing." A security operations center (SOC) analyst, for instance, must possess the precision to spot minute details that others might dismiss, as these often betray critical anomalies or attack indicators. Precision in cyber also involves a proactive, defensive mindset, akin to a musician breaking down a difficult passage to "fix it before the performance exposes it." This translates to conducting vulnerability assessments, scanning, testing, and patching systems before an attacker exploits weaknesses, rather than waiting for an incident to reveal them.

Third, patience is cultivated through ensemble learning and an acceptance of slow growth. Musicians rarely improve in isolation; they perform in groups, listening, adjusting, and syncing with others. This constant feedback accelerates improvement, highlighting areas where one might be "rushing or out of balance." Similarly, cybersecurity professionals should avoid isolated learning. Engaging in study groups, seeking peer reviews for projects or code, and finding mentors provide invaluable external perspectives and accelerate refinement. Ionescu emphasizes that mastery in any discipline, including music and cyber, is a slow process of "repetition and refinement and uncomfortable correction." Embracing this "slow growth" as "progress," rather than failure, fosters resilience and adaptability. When training emphasizes repetition and precision, individuals become adept at pattern recognition—a critical skill in cybersecurity. Rehearsing under constructive criticism builds comfort with being uncomfortable, preparing professionals to remain stable under pressure. Ultimately, this approach builds transferable skills, prioritizing adaptability over rote memorization.

Technical Deep Dive

▶ Watch: Importance of ensemble training and feedback (8:00)

While this talk does not delve into specific exploits or protocol analyses in a traditional sense, it offers a profound methodological deep dive into how one should approach technical skill acquisition in cybersecurity. Ionescu effectively translates the structured learning of music into a concrete framework for mastering complex cyber domains.

The first practical application is to break down cybersecurity into "measures". Rather than being overwhelmed by the entirety of the field, learners are encouraged to isolate difficult passages, much like musicians. For instance, if log analysis feels daunting, the advice is to "take one piece of the log, and then understand what is it really telling you?" This involves identifying patterns within a smaller context before expanding to the broader dataset. This micro-focus allows for incremental understanding and builds foundational knowledge.

Next, the methodology dictates to drill the weak areas. This moves beyond passively consuming content to actively engaging with challenging concepts. Ionescu advises identifying specific commands, workflows, or technical concepts that consistently cause confusion or slow down progress, and then rehearsing them deliberately. While specific examples aren't given for every domain, the principle applies broadly: if a particular Linux command for file permissions is unclear, create a mini-lab to practice it repeatedly. If a network protocol like DNS or HTTP is a blind spot, dedicate focused time to understanding its packets and behavior.

A critical component is to practice under pressure. This involves simulating real-world stress scenarios to test knowledge and build resilience. Ionescu strongly advocates for Capture The Flag (CTF) events, noting they reveal skill gaps that can then be addressed through targeted practice. Other suggestions include conducting mock interviews and participating in timed tabletop exercises. These activities are designed to expose weaknesses in a controlled environment, ensuring that "pressure should be introduced during practice, not discovered during a performance."

Finally, the talk emphasizes learning in ensembles. This is a direct counter to the isolated self-study common in cyber. Practical steps include:

  • Creating study groups: Collaborating with peers to discuss concepts, solve problems, and share knowledge.
  • Seeking peer review: Having others examine code, configurations, or project work to catch errors and offer alternative perspectives.
  • Finding a mentor: Leveraging experienced professionals for guidance, feedback, and career advice.

Ionescu provides concrete examples of tools and platforms that facilitate this structured practice. For web application security and penetration testing, she recommends the PortSwigger Web Security Academy, highlighting its interactive labs for learning Burp Suite and practicing web application exploitation. Other platforms mentioned include Hack The Box and Try Hack Me, which offer a wide range of CTF-style challenges across various cybersecurity domains. For project-based learning, she cites the CodePath program, which offered a honeypot project. This project involved developing an understanding of Google Cloud Platform, configuring firewalls, and analyzing how different attackers might target a honeypot, providing hands-on experience in cloud security and threat intelligence.

This "technical deep dive" is therefore a blueprint for how to learn technical skills effectively, rather than a list of skills themselves. It’s about adopting a disciplined, iterative, and collaborative approach to skill acquisition that mirrors the rigor of musical mastery, ensuring that cybersecurity professionals develop not just knowledge, but true competence and adaptability.

Demo / Proof of Concept

▶ Watch: Practical application: Break down cyber skills into 'measures' (11:00)

The talk included a unique and highly effective demonstration designed to illustrate the core principles of practice and precision. Bianca Ionescu, a trained violist, brought her instrument on stage and performed two short musical pieces.

The first part of the demo involved playing a simple C major scale on the viola. This served to illustrate the concept of warming up and the foundational aspect of practice—the repetitive drills that build muscle memory and ensure basic proficiency. It was a direct parallel to the initial stages of cybersecurity skill development, such as repeatedly executing a command or working through a basic lab to internalize a concept.

The second, and more impactful, part of the demo involved playing an excerpt from Beethoven's Fifth Symphony, second movement. Ionescu played this short passage twice. The first rendition was technically correct in terms of notes, but as she prompted the audience, something was "off." In the second rendition, she introduced vibrato, varied the dynamics, added more emotion, and adjusted the tempo, taking her time rather than rushing. The audience immediately recognized the significant difference, noting the added emphasis and slower pace.

This demonstration perfectly encapsulated the concept of precision. It showed that merely getting the "notes" (or, in cyber, the commands or configurations) technically correct isn't enough. The execution matters. The subtle nuances, the emotional depth, and the deliberate pacing transformed a technically accurate performance into a truly musical one. Ionescu directly linked this to cybersecurity, explaining that this level of meticulousness is what allows a security professional, particularly in a Security Operations Center (SOC), to "spot details that others might simply dismiss." It highlighted that precision is discipline under pressure, a discipline built through deliberate practice and an acute awareness of context and nuance that goes beyond surface-level correctness. The demo was a powerful, non-traditional proof of concept for the talk's central thesis, making the abstract concepts of practice and precision tangible and easily understandable.

Defensive Implications

▶ Watch: Drill weak areas and practice under pressure (12:00)

The defensive implications of Bianca Ionescu's framework are profound, focusing less on specific defensive technologies and more on cultivating a superior defensive mindset and enhancing the skill development of security teams. By adopting a musician's approach, defenders can significantly improve their effectiveness and resilience.

Firstly, the emphasis on deliberate practice directly translates to stronger defensive capabilities. Instead of passively reading threat reports or attending webinars, defenders should actively engage in structured exercises. This means setting up home labs to experiment with defensive tools like SIEMs, EDR solutions, or firewall rules. Regularly participating in CTFs or red team/blue team exercises provides a safe environment to practice incident response, threat hunting, and defensive maneuvers under simulated pressure. Identifying and drilling weak areas—whether it's understanding a specific malware analysis technique, mastering a forensic tool, or configuring complex network segmentation—ensures that critical skills are honed before they are needed in a real incident.

Secondly, precision is critical for effective defense. In a SOC environment, meticulousness in analyzing logs, alerts, and network traffic can be the difference between detecting a subtle intrusion and missing a critical breach. Defenders must develop the discipline to observe beyond the surface, looking for anomalies, unusual patterns, or deviations that signify malicious activity. This precision also extends to vulnerability management: proactively conducting vulnerability assessments, penetration testing, and implementing timely patch management to "fix it before the performance exposes it." This proactive, detail-oriented approach prevents attackers from exploiting known weaknesses.

Thirdly, the concept of ensemble learning fosters more robust and adaptable security teams. Defensive operations are rarely solitary endeavors. Encouraging study groups among team members, facilitating peer reviews of defensive playbooks, incident reports, or security architectures, and establishing mentorship programs creates a feedback-rich environment. This collaborative learning accelerates the refinement of individual skills and builds collective intelligence, ensuring that the team as a whole is greater than the sum of its parts. Teams that listen, adjust, and sync (like an orchestra) are better equipped to respond cohesively and effectively during a crisis.

Finally, embracing patience and viewing weaknesses as redirection, not failure, builds resilient defenders. The cybersecurity threat landscape is constantly evolving, meaning defenders must continuously adapt. By being comfortable with "uncomfortable correction" and practicing under pressure (e.g., tabletop exercises simulating major incidents), security professionals can develop the mental fortitude and adaptability to perform effectively when faced with novel attacks or high-stress situations. The ultimate goal is to build professionals who are not just technically proficient but also emotionally robust, capable of critical thinking and agile response, rather than being thrown off balance by the unexpected.

Key Takeaways

  • Structured Skill Development is Crucial: Cybersecurity skill development should adopt the structured, deliberate approach of musical training, moving beyond ad-hoc self-study to intentional practice, precision, and patience.
  • Deliberate Practice Builds Mastery: Focus on breaking down complex cybersecurity skills into manageable "measures," identifying and consistently drilling weak areas, and utilizing resources like home labs and CTFs for hands-on, repetitive learning.
  • Precision is Paramount in Security Operations: Meticulous attention to detail in observing logs, alerts, and system behavior is vital for identifying subtle anomalies that indicate threats, akin to a musician's precise execution of dynamics and tempo.
  • Proactive Vulnerability Management is Essential: Adopt a mindset of "fixing it before performance exposes it" by conducting regular vulnerability assessments, testing, and patching to mitigate weaknesses before attackers exploit them.
  • Collaborative Learning Accelerates Growth: Don't learn in isolation; engage in "ensemble training" through study groups, peer reviews, and mentorship to gain diverse feedback, accelerate skill refinement, and build stronger, more adaptable security teams.
  • Embrace Patience and Adaptability: Recognize that mastery is a slow process of continuous refinement. Practice under pressure (CTFs, tabletop exercises) to build resilience, view weaknesses as opportunities for redirection, and prioritize adaptability over rote memorization.

About the Speaker(s)

Bianca Ionescu is a cybersecurity professional with a unique background rooted in classical music. Having trained as a violist for many years, she made a deliberate switch to cybersecurity, a transition that initially seemed like a complete opposite but later revealed profound connections in learning methodology. Her journey into cybersecurity began with the GenCyber camp at the University of Nevada, Las Vegas (UNLV), where her interest was first sparked. Motivated by the growing demand for cybersecurity professionals and the constant threat of cyberattacks, she decided to pursue a career in the field, aspiring to be part of the solution.

Ionescu is an advocate for structured skill development and community engagement within cybersecurity. She is actively involved with organizations such as Women in Cybersecurity (WiCyS), which fosters a supportive community for women in the field. Her daily practices include staying updated on cyber news and engaging with practical labs, specifically mentioning her enjoyment of PortSwigger Web Security Academy and Burp Suite. She has also participated in programs like CodePath, which provided valuable project experience, including building a honeypot on Google Cloud Platform. Ionescu has a particular interest in OSINT (Open Source Intelligence), leveraging her skills in research and finding information. Despite her career transition, she continues to pursue her passion for music, playing as part of the Las Vegas Young Artist Orchestra, which regularly posts performances on YouTube.

Reviews

Dr. Zero (Offensive Security Researcher) — SOLID

A well-delivered career-development talk from a speaker with a genuinely interesting dual background. The music-to-cyber analogy is clean and the viola demo is memorable, but the content is fundamentally a repackaging of 'deliberate practice' frameworks that Anders Ericsson codified decades ago — applied to a domain where the same advice (do CTFs, build home labs, find mentors) has been repeated at every BSides since the format existed.

Heather Calloway (CISO) — WEAK

A well-delivered BSides talk with a genuine hook — musician turned security practitioner, viola on stage — but it operates entirely at the individual learner level. There is no governance angle, no institutional accountability, and no defender decision path that a security leader could act on.

→ Top-rated talks at BSidesSF 2026

All talks from BSidesSF 2026