- Reading time: 3 minutes
- Price: Free download
- Published: 4th October 2026
- Word count: 628 words
- File format: Text
Personal statement example
Most mornings at the housing association where I work as a junior web support analyst, the first thing I open is the password reset queue for our tenant portal. A year ago I noticed that a handful of accounts were being reset several times a week, always just after midnight. Nobody had been harmed, but the pattern bothered me enough that I spent an evening pulling the request logs into a spreadsheet. Most of the requests came from the same small range of addresses, cycling through email addresses that looked as though they had been taken from an old leaked list. I wrote up what I had found for my manager, and we added rate limiting and a clearer confirmation email. It was a modest fix, but it showed me how much of security happens in unglamorous places, and how much I want to understand it properly rather than by guesswork.
My undergraduate degree in Computer Science gave me a solid grounding in operating systems, networking and algorithms, and I chose every security-related option available. My final-year project grew out of curiosity about who actually tries to log into an exposed machine. I set up a Raspberry Pi running a low-interaction SSH honeypot on a home connection, with my landlord's permission, and collected around six weeks of connection attempts. I then built a simple anomaly detection pipeline in Python, comparing a threshold-based approach with an isolation forest to flag unusual bursts of activity. The isolation forest picked up slow, distributed attempts that the thresholds missed, but it also produced false positives whenever my own legitimate logins appeared at odd hours. Writing up that trade-off honestly, rather than presenting one method as the winner, was the part of the project I was proudest of, and my supervisor singled it out in her feedback.
Since graduating I have kept reading beyond my job. Ross Anderson's Security Engineering has been especially useful, because it treats security as a question of incentives and human behaviour as well as cryptography. His point that systems often fail because the people responsible for them do not bear the cost of failure matched what I see at work, where small budget decisions shape what is protected. I have also worked through capture-the-flag exercises on public training platforms, mostly web exploitation challenges, which have made me more careful about input validation in the small internal tools I write.
Outside work, I volunteer one evening a month at my local library, helping older residents with their smartphones. Much of this has nothing to do with security: setting up video calls with grandchildren, or making text larger. But the questions people ask about suspicious messages have taught me to explain risk plainly, without frightening anyone. I also play five-a-side football on Thursdays, which is mainly a reliable way to stop staring at screens.
I am applying for postgraduate study in cybersecurity because I have reached the limit of what I can learn informally. I want a rigorous grounding in applied cryptography, network defence and secure software design, and the chance to study intrusion detection in more depth than my undergraduate project allowed. In particular, I would like to understand how detection systems can be evaluated fairly when labelled attack data is scarce, a problem I ran into directly with my honeypot. In the longer term I hope to work in a security operations or application security role, ideally for organisations like the one I work for now, which hold sensitive personal data but rarely have specialist staff.
I bring a reliable technical foundation, practical experience of supporting real users, and the habit of noticing when something in a log does not look right. I would now like the training to turn that habit into expertise.