I definitely feel like a fraud all the time. In meetings someone will introduce me as an information security expert and it makes my blood run cold. I keep thinking to myself, "This isn't rocket science, it's just common sense surely?" but bizarrely there are still developers out there who haven't heard of input validation, bounds checking or even how to do authorisation properly.

I worked out the other day that I've been doing this job for about 12 years. There's that whole 10,000 hours thing when it comes to being an expert, and I think I've put in several times that but I certainly don't feel like an expert in anything. If anything I keep expecting someone to turn up and point out blatant flaws in everything I say, but somehow it doesn't happen.

