Just a bit of an open discussion really…
I did my CEH a few years ago and luckily work paid for it - if it was my own money, I’d be asking for a refund.
The course content included stuff from ~10 years earlier, inc. referring to tools that hadn’t been maintained (ie in github) for years and basically didn’t work any more… and topics like warchalking… ok, it’s interesting to know the history, but as the Wikipedia article mentions, I don’t think it really took off and no-one uses it anymore.
So, I let my certification slide and the EC Council have been continually trying to “remind” me to pay for my membership.
I just don’t have the feeling that they’re really trying to keep up and improve the industry.
I’m now managing a team of Cyber Security Engineers and this came up as a training topic recently, so I’m looking for others to help me reset my bias.
So… did you have the opposite experience?


My experience with it wasn’t quite the same, but was similar. When I was looking at it, it was very much in that category of cert that was mostly about memorizing the study guides/books, and less about building/proving a skillset (which, as mentioned, is hardly uncommon with IT certs unfortunately).
Where it did have some “value” was that it was a well-known cert that was very useful for “proving” that your org was in compliance. A badge you could hang to auditors and costumers/clients that said you knew your stuff. Again, hardly uncommon with IT certs. :\
I don’t think it’s completely worthless. Depending on where you’re at in your career, it can be a useful experience. But it should, I think, be treated like a (relatively) beginner-tier cert. Something you might consider at an early point in your journey, but not one I’d necessarily build your resume around. I also think that it’s value may depend a lot on exactly what your role in an organization looks like. CEH for an entry-level pen tester or incident handler? Yeah, maybe. For something like an IAM developer or a privacy analyst… eh, less so.
Yep, partially we see the certs as just differentiators between us and “the others” for our customers.
In reality, we don’t even do half the things needed to get the certs (take CCNA for example… IPv6 still isn’t in use for our customers)