Which field has better career prospects in the next 20-30 years: SAP or cyber security?

My usual response to questions like this is to ask "What do you think would make you happiest? For which do you feel you're best suited?" and "If your interests lie in both, is there a field that embodies aspects of both?"

Thank you for the A2A.

20 to 30 years is a long window, and a lot can happen in any industry or market in that span of time, particularly in one that tends to evolve as quickly (in some ways, in other's we're virtually stagnant) as information technology.

My usual response to questions like this is to ask "What do you think would make you happiest? For which do you feel you're best suited?" and "If your interests lie in both, is there a field that embodies aspects of both?"

ERP systems are certainly a key underpinning to almost every aspect of large-scale commerce these days, and SAP is arguably the dominant vendor in that space at present. That company has also developed some foundation technologies that are seeing use in a wide variety of areas that have nothing to do with ERP. The HANA in-memory database technology is an example of that.

The fact is that SAP is but one of many vendors, of a large number who will be competing over a multi-decade timespan, and you have no idea when the "fashion" will change, or if a disruptive new entrant will enter the space, and result in a waning of SAP's particular prevalence in the market. I think anyone specializing in their platforms is likely to have a lot of work for the foreseeable future. It is simply a fact that the foreseeable future isn't very far into the future.

If you're actually really interested in both of these spaces or have some aptitude for them, then focusing on the security of SAP implementations is certainly not a bad idea.

Cybersecurity shares many of these aspects. For all I know in 30 years we'll be using some completely different processing paradigm like photonic computers, and doing quantum cryptography (or at least quantum cryptanalysis). My point is that we can't predict much there either. However, information security and cybersecurity more generally are likely to be fields where there will always be some demand for people. Cultural shifts may affect what the policies look like, but the desire to set controls on information systems and connected devices to only disclose what we wish to disclose, the challenges of building those controls, and the processes of measuring whether they actually work are likely to be timeless.

In general, I tell anyone interested in getting into security to learn as much as they can about how the systems they're going to be securing actually work. If you want to do network security, I urge you to understand how the protocol stacks work, how the applications are built, and how they run on the platform you're examining. This task never ends, by the way. A good security practitioner is always learning about new foundation technologies and new platforms, and thinking about the second-order ramifications of deploying them, in the context of security.