Cyber Security Roadmap | Resources by Shumbul Arifa

🛡️ Cyber Security Roadmap

Cyber security has a huge talent shortage and no single "right" degree to enter it. This roadmap is your highway: six stages from networking basics to landing your first security role, with hands-on labs at every stop.

🧭 6-stage journey 🧪 Hands-on labs 🆓 Free tools & labs

How this roadmap works

Each stage below is a stop on your journey. Read it, do the hands-on lab, then hit Mark stage done, the map at the top updates and the traveler moves along the road. The three phases are:

One honest note: security rewards curiosity and persistence more than raw talent. If you enjoy taking things apart to see how they work, you will do well here.

Phase 1 · Foundations

Stage 1: Networking & Linux basics

Everything in security sits on top of networks and Linux. You cannot secure or attack what you do not understand, so this is the non-negotiable first stop.

TCP/IP & OSIDNS, HTTP, HTTPSPorts & protocolsLinux command lineBash basicsNetworking tools
Hands-on lab: set up a Linux VM (or WSL), learn the core commands, and use ping, nmap, and Wireshark to see real traffic on your own network. Trace what happens when you load a website.
Phase 1 · Foundations

Stage 2: Security fundamentals

Now the core ideas that everything else builds on. Learn the language and mental models of security before touching tools.

CIA triadThreats vs vulnerabilities vs riskAuthentication & authorizationCryptography basicsHashing & encryptionCommon attack types
Hands-on lab: practice on TryHackMe's free "Pre Security" and "Intro to Cyber Security" paths. Set up a password manager and enable 2FA everywhere, security starts with your own hygiene.
Phase 2 · Core Security

Stage 3: Offensive security (red team)

Learn to think like an attacker, ethically. This is "ethical hacking": finding weaknesses before the bad guys do. It is the most famous side of security and a great way to learn deeply.

Web app security (OWASP Top 10)ReconnaissanceExploitation basicsBurp SuiteMetasploitPrivilege escalation
Hands-on lab: work through PortSwigger's Web Security Academy (free) and capture-the-flag rooms on Hack The Box. Always practice only on systems you are allowed to, that line matters.
Phase 2 · Core Security

Stage 4: Defensive security (blue team)

The other half, and where most jobs are. Defenders monitor, detect, and respond to attacks. Roles like SOC Analyst are the most common entry point into the whole field.

SOC & SIEMLog analysisThreat detectionIncident responseEndpoint securityThreat intelligence
Hands-on lab: try the LetsDefend or TryHackMe "SOC Level 1" paths. Analyze a sample phishing email and a set of logs, and write a short incident report, exactly what the job involves.
Phase 3 · Get Hired

Stage 5: Specialize & get certified

Security is wide. Once the basics click, pick a lane and back it with a respected, beginner-friendly certification. Certs matter more in security than in most tech fields, they are often a hiring filter.

Popular starting specializations: SOC Analyst, Penetration Tester, Cloud Security, Application Security, GRC (governance, risk, compliance).

CompTIA Security+CompTIA Network+TryHackMe / HTB pathseJPT (practical pentest)Cloud security basics
Action: pick one specialization that excites you, then target one entry cert (Security+ is the classic first choice). Study with free resources and the official objectives, and book the exam to give yourself a deadline.
Phase 3 · Get Hired

Stage 6: Build proof & land the role

The final stretch: turn skills into a job. In security, visible proof of work and a clear story beat a long resume.

CTF write-upsA security-focused GitHub/blogHome labNetworking & communityTailored resume
Action: document your TryHackMe/HTB rooms as write-ups, build a small home lab, and share what you learn publicly. Then apply for SOC Analyst, Security Analyst, or Junior Pentester roles. Polish your resume with the Resume & Portfolio guide and prep with the Interview Prep Kit.

Entry roles & where they lead

You do not start as an elite hacker. Most people enter through one of these and grow from there:

Entry roleWhat you doGrows into
SOC Analyst (Tier 1)Monitor alerts, triage incidents, analyze logsIncident Responder, Threat Hunter
Security AnalystAssess risks, harden systems, support auditsSecurity Engineer, GRC Analyst
Junior Penetration TesterTest apps and networks for weaknessesSenior Pentester, Red Teamer
IT / Helpdesk (pivot)Support and systems, then move into securityAny of the above

Free places to learn

What to do next

Security overlaps with the rest of your tech skills. These guides pair well with this roadmap:

6
stages to job-ready
3
phases on the road
🔥
very high demand
0₹
cost to start
🌱 New to security? Start calm

You do not need a special degree or to be a "genius hacker". Security is a craft you build stage by stage: understand how systems work, then how they break, then how to defend them. Follow the road below in order, mark each stage done as you go, and let the map track your progress. Stuck on a concept? Tap ✦ Ask AI for a plain-English explanation.