Cybersecurity Roadmap for Beginners (2026): What to Learn, in What Order
Five stages, from “what is an IP address?” to job-ready projects — with the exact topics, free labs and a checkpoint for each stage so you always know when to move on.
Learn cybersecurity in five stages: 1) IT and operating system basics, 2) networking, 3) security fundamentals, 4) one specialisation track (SOC, ethical hacking, network security, application security or cloud), and 5) projects and job preparation. Practise in labs every week and don’t move to the next stage until you pass its checkpoint. At one to two hours a day, most beginners finish in about six months.
The cybersecurity roadmap at a glance
Five stages, about six months. Each stage builds on the one before it — that’s why the order matters.
IT & OS basics
Networking
Security fundamentals
Your track
Projects & job prep
⏳ Weeks assume one to two hours of study a day. Going slower is fine — skipping a stage is not.
Stage 1: IT and operating system basics
Everything in security sits on top of computers and operating systems. Skip this and every later topic feels confusing.
• Install VirtualBox and set up Ubuntu and Kali Linux virtual machines
• Play OverTheWire Bandit, a free Linux wargame
• Use the Linux terminal for 20 minutes every day
✅ Checkpoint: you can move around Linux from the terminal, change file permissions, and find and stop a running process.
Stage 2: Networking fundamentals
Attacks travel over networks. Once you can read network traffic, half of security starts to make sense.
• Capture your own browsing in Wireshark and find the DNS queries
• Practise subnetting until each question takes under a minute
• Build a small network in Cisco Packet Tracer
✅ Checkpoint: you can explain what happens when you open a website and spot a DNS lookup in a packet capture.
Stage 3: Security fundamentals
Now the security part begins. This is the shared language every security role uses — and the first block of every interview.
• Follow the beginner learning paths on TryHackMe
• Read one real breach story a week and map it to the attacks you learned
• Hash and encrypt files yourself with OpenSSL
✅ Checkpoint: you can explain five common attacks and the control that stops each one. Test yourself with our interview questions (Round 1).
🧭 Halfway there? Our trainers teach this exact order with live labs and feedback — sit in on a class for free.
Book a free demoStage 4: Choose one track and go deep
Now specialise. Pick one track based on what you enjoy and the role you want — you can add a second one later, once you’re working.
SOC / Blue team
Learn: SIEM (Splunk, Microsoft Sentinel, Wazuh), log analysis, Windows event IDs, incident response, phishing analysis.
First role: SOC Analyst L1 SOC Analyst training →Ethical hacking & VAPT
Learn: reconnaissance, Nmap, Burp Suite, Metasploit, privilege escalation and report writing.
First role: VAPT Analyst / Junior Pentester Ethical Hacking course →Network security
Learn: firewall rules, VPNs, IDS/IPS, network segmentation and secure configurations.
First role: Junior Network Security Engineer Network Security course →Application security
Learn: OWASP Top 10, Burp Suite, API testing and secure coding basics.
First role: Application Security Tester Web Application Security course →Cloud security (later)
Learn: AWS or Azure identity and access, logging, and the common misconfigurations attackers look for.
Usually after one to two years in IT or securityCan’t decide? Quick guide
Like investigating and spotting patterns → SOC
Like breaking things to see how they work → VAPT
Like building and configuring networks → Network security
Coming from development or testing → AppSec
• SOC: build a small home SIEM lab with Wazuh (free) and investigate your own logs
• VAPT: solve beginner machines on Hack The Box or TryHackMe
• AppSec: work through PortSwigger’s free Web Security Academy labs
✅ Checkpoint: you’ve completed at least three end-to-end labs in your track and can explain each one in your own words.
Stage 5: Projects and job preparation
Skills you can’t show don’t count in an interview. This stage turns what you learned into proof.
• SOC: investigate a phishing email end to end and write the incident report
• VAPT: assess a deliberately vulnerable app such as DVWA or OWASP Juice Shop and write a findings report
• Network: design and document a segmented network with firewall rules
✅ Checkpoint: you can walk an interviewer through each project in about five minutes. Practise with our 40 interview questions.
For resume, LinkedIn and first-job tips, read our guide on how to start a career in cyber security.
Free resources to follow this roadmap
You don’t need to buy anything to start. These free tools and platforms cover every stage.
OverTheWire Bandit
A free wargame that teaches the Linux command line level by level.
Wireshark
Free tool to capture and read real network traffic.
Cisco Packet Tracer
Free network simulator through Cisco Networking Academy.
TryHackMe
Guided, browser-based labs for beginners, with many free rooms.
Hack The Box
Practice machines to build offensive skills once you have the basics.
PortSwigger Web Security Academy
Free web security labs from the makers of Burp Suite.
Wazuh
Free, open-source security monitoring platform for a home SOC lab.
MITRE ATT&CK & OWASP Top 10
Free reference frameworks used across the industry — and in interviews.
Platforms change their free plans from time to time, so check what’s currently included before you sign up.
How to study each week
A simple weekly rhythm beats occasional all-night sessions. Here’s what works for most of our learners.
Learn + lab
One to two hours a day: one topic, then one hands-on lab on that topic.
Write it up
Turn the week’s labs into short notes or a write-up on GitHub or LinkedIn.
Revise and rest
Review the week, test yourself against the stage checkpoint, then switch off.
Mistakes that slow beginners down
Almost everyone who gets stuck made one of these. Avoid them and you’ll move much faster.
✕ Jumping straight to Kali Linux hacking tools
✕ Skipping networking because it feels boring
✕ Collecting courses and never finishing one
✕ Only watching videos without doing labs
✕ Learning every track at the same time
✕ Never writing anything down — no notes, no reports, no proof
Prefer to follow this roadmap with a trainer?
Our cyber security course in Hyderabad follows this same order — fundamentals, networking, security, your track, then projects — in about three months with live labs and feedback. Compare costs first in our fee guide.
Frequently asked questions
What is the best cybersecurity roadmap for beginners?
Learn in five stages: IT and operating system basics, networking, security fundamentals, one specialisation track, and finally projects and job preparation. Practise in labs every week and only move on when you can pass each stage’s checkpoint.
How long does it take to complete the cybersecurity roadmap?
About six months at one to two hours a day. A structured course with guided labs can shorten it; going slower is fine as long as you don’t skip stages.
Should I learn Kali Linux first?
No. Learn Linux basics and networking first. Kali’s tools only make sense once you understand what they are doing on the network and the operating system.
Do I need programming to follow this roadmap?
Not to start. You’ll pick up basic Bash in stage 1. Python becomes useful in stages 4 and 5, especially for automation and application security.
Which track should I choose after the basics?
SOC is the most common first job and a safe default. Choose VAPT if you enjoy offensive work, network security if you like infrastructure, and application security if you come from development or testing.
Are free resources enough to learn cybersecurity?
Free resources can teach you the skills. What they usually lack is a clear order, feedback on your work and help with getting hired — that is what a structured course adds.
Built from the order we teach in our own batches. Last updated 9 October 2026. Spotted something outdated? Tell us on WhatsApp.
Follow this roadmap with a trainer by your side
Live classes in this exact order, hands-on labs every week and reviewed projects. Sit in on a class for free. Next batch starts Monday, 2 November 2026.
Keep reading