All blogs

"Today it's easier to hack a person than a system," says a service technician in an interview about technical support, infrastructure management and the behind-the-scenes of IT operations

2025-07-01 | 11 min Anasoft

Technologies move the world, but who is behind their operation? Who sets up the systems that we take for granted, and who solves incidents that happen outside of the users' attention?

In the series of interviews personal<IT>y, we will take a look behind the scenes of IT work through the eyes of experts from ANASOFT. They reveal not only their working world, but also their personal one, because behind the infrastructure, support and management of systems there is a specific person with his own way of thinking, approach to problems and daily commitment.

IT technician Marek Švirec moves on the border between hardware, software, user support and security. In the interview, he reveals how he became a specialist in enterprise technologies from a local admin, what IT support looks like when you can't rely on the manual, and why, in his opinion, the biggest weakness today is not the technician, but the user himself.

His approach is reminiscent of the philosophy of Emil Škoda (pictured), a Czech engineering visionary who, while not in the limelight, understood that system reliability and robust infrastructure were the foundation of every great advance. Just as Škoda built the foundations of industry in the 19th century, Marek maintains the technological environment on which the digital world runs.

So let’s start by painting a picture — what does the job of an IT service technician actually look like? Is it one of those typical “fix the washing machine or TV” kind of jobs?

Not quite. An IT service technician isn’t someone who repairs household appliances. I’d describe it more like being an “IT janitor” — someone who does a bit of everything. The role covers a really wide range of tasks, from user support and hardware/software installation to various interventions in infrastructure. We don’t have strictly defined categories like in large corporations.

Simply put: whatever comes up, we deal with it.

How did you get into this position?

I started with simpler tasks — installing workstations, helping with blocked accounts, providing support for users, both internal and external. The usual “level 1” stuff. Over time, as new opportunities came up, I gradually got access to more complex technologies.

So you basically learned everything on the job?

Exactly. I started out as a kind of local admin — a “go-to person” for everything. In the early days, you had to do a lot yourself, even if you didn’t know everything yet. And, back then, things weren’t as easy as they are today. There weren’t just two clicks for everything — you had to understand what you were doing. From assembling your first computers to configuring routers — step by step, I got into it.

What were your most common tasks as a service technician?

The classic IT support routine: “my computer doesn’t work, I can’t get online, or my printer isn’t printing.” I also prepared workstations for new and existing colleagues. But this job is always full of surprises — from small issues like a misplaced password in a “password manager,” all the way to diagnosing a “man-in-the-middle attack.”

What exactly is a “man-in-the-middle attack”?

We deployed a security tool that monitored network communication, and a certain portal identified it as a “man-in-the-middle attack,” a potential security threat — which then caused the monitored application to shut down. The client just reported that their app wasn’t working, and we had to perform a full diagnostic to find out what actually happened. That’s when we discovered it was a false positive — the security system had incorrectly flagged legitimate activity as a threat.

And what were some of the more complex tasks you eventually got to handle?

For example, working with enterprise technologies, centralized management, and security tools. One of my first major assignments was deploying two-factor authentication. That already fell under critical infrastructure management, where we had to prepare backup servers and develop a disaster recovery plan — a procedure for restoring operations in case of a failure.

Do you even have such a thing as a typical workday?

Not really. On the bus, I check my emails to see what’s waiting for me. Every day is different — some tasks are long-term, others require immediate attention. Most of the work is reactive: whatever comes in, I handle it. Among the longer-term projects I’m currently working on is improving cybersecurity levels. That includes securing email communication, endpoints, servers, and mobile devices, as well as implementing VPN-less access — which means you don’t have to manually start a VPN connection; remote access to the company infrastructure happens automatically.

What do you enjoy most about your work?

Probably working with systems more than with people. I really enjoy configuration, troubleshooting — basically when something doesn’t work, I love figuring out why. I don’t mind trying something eight times until it finally works on the ninth. For example, recently we were solving an email synchronization issue for one client. At first, they provided the wrong details and were using a different tool than they claimed.

So I started digging — from the firewall, through the web proxy, all the way to the mail server. I discovered they were using an old encryption protocol that hasn’t been secure for over ten years. We didn’t want to create security holes just to make it work, so I gave them all the necessary information, they updated their setup, and it finally started working.

Do you also work proactively, not just reactively?

Yes, for instance, we recently configured an advanced firewall for a client — mainly for their mobile access. We blocked everything except what was essential: web browsers and email clients on phones. All other ports and services were disabled — no torrents, no suspicious connections.

But a lot of proactive work actually hides within reactive work. For example, I once received an incident report from a cloud service. After handling the standard incident procedure, I noticed some new features in that cloud platform. I thought about which ones would be practical for that client — and then I implemented them.

What are the most common mistakes you have to deal with?

That’s hard to say — it could be anything from an application crash due to a faulty software library to incorrect tool usage by the user. Sometimes users try to use a tool in a way it was never intended for. Or we deal with things like users clicking “Allow notifications” on random websites — and then being bombarded by pop-ups and ads. Many of those are actually malicious sites running phishing campaigns designed to steal login credentials, deliver malware, or even trigger ransomware attacks.

So attackers can really exploit even the smallest vulnerabilities?

Absolutely. For example, if someone clicks on fake web notifications like “You’re at risk — click here,” it doesn’t lead to any real help. It just redirects you to shady content — sometimes even ransomware. Ransomware is a type of attack where hackers lock access to your data and demand a ransom. These attacks often use tools that analyze user behavior and are quite sophisticated — they can stay in your network for months, silently collecting credentials, even infecting your backups so you have nowhere to restore from once your system is encrypted.

Is there a way to defend against that?

Definitely — but it requires discipline. The most important thing is to have backups, ideally ones that aren’t always connected — offline backups. Some companies use tape drives stored in safes, others rotate external disks kept outside the regular environment. That protects you not just from ransomware, but also from fire, theft, or any kind of outage.

Are cyberattacks already linked to AI?

Yes — nowadays attacks are increasingly combined with AI engines that learn how to craft more convincing phishing messages or social engineering attempts. But the same applies in reverse: AI is also being used on the defensive side, of course.

What are the most common types of attacks on companies?

Definitely phishing. You get a text or an email saying, “Your account has been blocked, log in immediately,” often with a QR code. QR codes are tricky because you can’t see where they lead. You scan it with your phone, a website opens that looks exactly like your online banking page — and you’re already being lured to enter your login details.

Fraudsters are clever — they can perfectly imitate a bank’s design, add a fake email header, and even send their message in the same email thread as real communication from the bank.

So a lot of people become victims simply because they were inattentive at the wrong moment?

Exactly. It only takes stress or a brief lapse of focus. And when you voluntarily submit your data, the bank no longer considers it their responsibility. The systems weren’t hacked — you were hacked as a person.

Do you also do preventive work?

For clients, we set up protective rules, monitoring, and proper configuration. Some companies also run their own internal trainings on safe behavior, but we don’t do user awareness sessions directly — at least not yet. However, I regularly take part in internal education for colleagues, where we cover the latest forms of cybersecurity threats.

But people still tend to think, “It won’t happen to me,” right?

That’s the biggest myth. Attackers today work automatically — they shoot in all directions, and eventually someone takes the bait. And if you’re targeted specifically, through what’s called spear phishing, it becomes much harder to detect — often nearly impossible.

Does this happen only in companies?

No — anywhere. It could be a factory, a café, a hotel. I once stayed at a hotel for work and found their router still had the default credentials: admin/admin. I could access the entire system. People often don’t change default passwords — and that’s a huge problem. If an attacker connects with a strong antenna, they can intercept passwords or attempt a brute-force attack (a method where an attacker repeatedly tries different password combinations until they find the correct one). Nowadays, it really doesn’t take much.

So are you a bit paranoid in your personal life too?

A little, yes. I operate under the assumption that everyone and everything is trying to trick me. So I disable everything by default, trust nothing, and configure everything myself — even at home.

What about social media?

I’m always nagging my friends: “Stop posting every little thing!” Like when someone posts they’re on vacation — why share that right away? Wait until you’re back. Personally, my LinkedIn profile is nearly empty — just enough to have access. I don’t see the point in putting personal stuff online. People don’t realize that even a photo of an ice cream on Instagram can be used to create a targeted phishing campaign. That’s not science fiction anymore.

What do you think are the biggest myths about security or IT infrastructure?

Definitely the idea that “it doesn’t concern me.” People think they’re not interesting targets. But attacks today aren’t personal — automated systems target everyone. Once, we had an incident where a colleague received one of those classic scam emails — something like “A Nigerian prince wants to send you a million dollars.” The attachment looked like an image, but it was actually a disk image — an .ISO file that, when opened, mounted itself as a virtual CD drive. Inside was an autorun.bat script trying to execute code. Fortunately, we had a strong endpoint protection system, and it caught it immediately.

And did you have a similar experience at home?

Of course. At home I noticed my computer suddenly humming. I checked and six cores were at 100% — the CPU was fully loaded. I found out someone had started a crypto miner on my machine. It turned out it probably ran after visiting some website where a malicious script was executing. Nowadays there are trackers, ads, scripts everywhere, so if you temporarily allow something, something can slip in. That was exactly the case — something was saved into System32, ran as a driver, and mined Monero on my machine. They probably earned two dollars or so before I noticed.

So everyone knows about firewalls, but what other prevention tools are there?

Those professional tools aren’t cheap and they’re complex. It’s not enough to buy them and switch them on. You have to configure them correctly, manage them, update them — and monitor them. Companies think they can buy some product for thousands and be safe. But new threats appear every day. We’ve had cases where a vulnerability was found in a VPN and we had to react immediately, restrict access until a patch arrived. A regular person can’t handle this. Ideally, every company should have a dedicated team that deals only with security.

If you had to summarize — where is cybersecurity today?

Cybersecurity today is like a constant cat-and-mouse game. Attackers aren’t limited by budget or regulation. They move faster than defenders. There’s even “ransomware-as-a-service” now: you pay someone and they build a tailored attack for you. It’s a business.

Do you enjoy this work?

Absolutely. Since childhood I’ve taken things apart and tried to understand how they work. I’m most interested in security: how processes are set up, what communication paths exist, where weaknesses are, and how to fix them. Today it’s often not about breaking a system so much as manipulating people — human error is the biggest weakness.

Do you remember your first contact with IT security?

My first contact? That was back at home, in elementary school. There are freely available tools and guides online to play with. I remember experimenting with hacking games, reading their memory with Cheat Engine, modifying parameters, getting virtual money.

What do you think is the most important skill for an IT technician?

Definitely analytical thinking. Being able to connect the dots — what relates to what, where things happen, and what should happen where. For example, when you see something in the logs happened at a certain time, you expect a response elsewhere. If you don’t see it, you know there’s a problem.

Related articles