Blog › Careers
Learning roadmap · Updated October 2026

Cybersecurity Roadmap for Beginners (2026): What to Learn, in What Order

Five stages, from “what is an IP address?” to job-ready projects — with the exact topics, free labs and a checkpoint for each stage so you always know when to move on.

✍️ Cyber Security Academy trainers ⏱ 13 min read 📅 Updated 9 October 2026
⚡ Short answer

Learn cybersecurity in five stages: 1) IT and operating system basics, 2) networking, 3) security fundamentals, 4) one specialisation track (SOC, ethical hacking, network security, application security or cloud), and 5) projects and job preparation. Practise in labs every week and don’t move to the next stage until you pass its checkpoint. At one to two hours a day, most beginners finish in about six months.

The big picture

The cybersecurity roadmap at a glance

Five stages, about six months. Each stage builds on the one before it — that’s why the order matters.

Stage 1 Weeks 1–3

IT & OS basics

Stage 2 Weeks 4–6

Networking

Stage 3 Weeks 7–9

Security fundamentals

Stage 4 Weeks 10–17

Your track

Stage 5 Weeks 18–24

Projects & job prep

⏳ Weeks assume one to two hours of study a day. Going slower is fine — skipping a stage is not.

Stage 1 Weeks 1–3

Stage 1: IT and operating system basics

Everything in security sits on top of computers and operating systems. Skip this and every later topic feels confusing.

📘 Learn
How computers work Windows basics Users and permissions Processes and services Linux file system Bash commands Virtual machines
🧪 Practise

•  Install VirtualBox and set up Ubuntu and Kali Linux virtual machines

•  Play OverTheWire Bandit, a free Linux wargame

•  Use the Linux terminal for 20 minutes every day

✅ Checkpoint: you can move around Linux from the terminal, change file permissions, and find and stop a running process.

Stage 2 Weeks 4–6

Stage 2: Networking fundamentals

Attacks travel over networks. Once you can read network traffic, half of security starts to make sense.

📘 Learn
OSI and TCP/IP IP addressing and subnetting TCP vs UDP Ports and protocols DNS and HTTP/HTTPS Firewalls and VPNs Wireshark
🧪 Practise

•  Capture your own browsing in Wireshark and find the DNS queries

•  Practise subnetting until each question takes under a minute

•  Build a small network in Cisco Packet Tracer

✅ Checkpoint: you can explain what happens when you open a website and spot a DNS lookup in a packet capture.

Stage 3 Weeks 7–9

Stage 3: Security fundamentals

Now the security part begins. This is the shared language every security role uses — and the first block of every interview.

📘 Learn
CIA triad Threats, vulnerabilities & risk Encryption & hashing Authentication & MFA Common attacks Security controls MITRE ATT&CK & OWASP Top 10
🧪 Practise

•  Follow the beginner learning paths on TryHackMe

•  Read one real breach story a week and map it to the attacks you learned

•  Hash and encrypt files yourself with OpenSSL

✅ Checkpoint: you can explain five common attacks and the control that stops each one. Test yourself with our interview questions (Round 1).

🧭 Halfway there? Our trainers teach this exact order with live labs and feedback — sit in on a class for free.

Book a free demo
Stage 4 Weeks 10–17

Stage 4: Choose one track and go deep

Now specialise. Pick one track based on what you enjoy and the role you want — you can add a second one later, once you’re working.

🛡️

SOC / Blue team

Learn: SIEM (Splunk, Microsoft Sentinel, Wazuh), log analysis, Windows event IDs, incident response, phishing analysis.

First role: SOC Analyst L1 SOC Analyst training →
🔍

Ethical hacking & VAPT

Learn: reconnaissance, Nmap, Burp Suite, Metasploit, privilege escalation and report writing.

First role: VAPT Analyst / Junior Pentester Ethical Hacking course →
🌐

Network security

Learn: firewall rules, VPNs, IDS/IPS, network segmentation and secure configurations.

First role: Junior Network Security Engineer Network Security course →
🧩

Application security

Learn: OWASP Top 10, Burp Suite, API testing and secure coding basics.

First role: Application Security Tester Web Application Security course →
☁️

Cloud security (later)

Learn: AWS or Azure identity and access, logging, and the common misconfigurations attackers look for.

Usually after one to two years in IT or security
🤔

Can’t decide? Quick guide

Like investigating and spotting patterns → SOC

Like breaking things to see how they work → VAPT

Like building and configuring networks → Network security

Coming from development or testing → AppSec

🧪 Practise in your track

•  SOC: build a small home SIEM lab with Wazuh (free) and investigate your own logs

•  VAPT: solve beginner machines on Hack The Box or TryHackMe

•  AppSec: work through PortSwigger’s free Web Security Academy labs

✅ Checkpoint: you’ve completed at least three end-to-end labs in your track and can explain each one in your own words.

Stage 5 Weeks 18–24

Stage 5: Projects and job preparation

Skills you can’t show don’t count in an interview. This stage turns what you learned into proof.

📘 Focus on
3–5 documented projects Written reports GitHub & LinkedIn Project-first resume Interview practice One beginner certification (optional)
🧪 Project ideas

•  SOC: investigate a phishing email end to end and write the incident report

•  VAPT: assess a deliberately vulnerable app such as DVWA or OWASP Juice Shop and write a findings report

•  Network: design and document a segmented network with firewall rules

✅ Checkpoint: you can walk an interviewer through each project in about five minutes. Practise with our 40 interview questions.

For resume, LinkedIn and first-job tips, read our guide on how to start a career in cyber security.

Free to use

Free resources to follow this roadmap

You don’t need to buy anything to start. These free tools and platforms cover every stage.

Stage 1

OverTheWire Bandit

A free wargame that teaches the Linux command line level by level.

Stage 2

Wireshark

Free tool to capture and read real network traffic.

Stage 2

Cisco Packet Tracer

Free network simulator through Cisco Networking Academy.

Stages 3–4

TryHackMe

Guided, browser-based labs for beginners, with many free rooms.

Stage 4

Hack The Box

Practice machines to build offensive skills once you have the basics.

Stage 4

PortSwigger Web Security Academy

Free web security labs from the makers of Burp Suite.

Stage 4

Wazuh

Free, open-source security monitoring platform for a home SOC lab.

Stages 3–5

MITRE ATT&CK & OWASP Top 10

Free reference frameworks used across the industry — and in interviews.

Platforms change their free plans from time to time, so check what’s currently included before you sign up.

Make it stick

How to study each week

A simple weekly rhythm beats occasional all-night sessions. Here’s what works for most of our learners.

Mon – Fri

Learn + lab

One to two hours a day: one topic, then one hands-on lab on that topic.

Saturday

Write it up

Turn the week’s labs into short notes or a write-up on GitHub or LinkedIn.

Sunday

Revise and rest

Review the week, test yourself against the stage checkpoint, then switch off.

🧪 Lab every week ✍️ Write what you learn 🎯 One stage at a time
Save yourself months

Mistakes that slow beginners down

Almost everyone who gets stuck made one of these. Avoid them and you’ll move much faster.

✕  Jumping straight to Kali Linux hacking tools

✕  Skipping networking because it feels boring

✕  Collecting courses and never finishing one

✕  Only watching videos without doing labs

✕  Learning every track at the same time

✕  Never writing anything down — no notes, no reports, no proof

Prefer to follow this roadmap with a trainer?

Our cyber security course in Hyderabad follows this same order — fundamentals, networking, security, your track, then projects — in about three months with live labs and feedback. Compare costs first in our fee guide.

Still wondering?

Frequently asked questions

What is the best cybersecurity roadmap for beginners?

Learn in five stages: IT and operating system basics, networking, security fundamentals, one specialisation track, and finally projects and job preparation. Practise in labs every week and only move on when you can pass each stage’s checkpoint.

How long does it take to complete the cybersecurity roadmap?

About six months at one to two hours a day. A structured course with guided labs can shorten it; going slower is fine as long as you don’t skip stages.

Should I learn Kali Linux first?

No. Learn Linux basics and networking first. Kali’s tools only make sense once you understand what they are doing on the network and the operating system.

Do I need programming to follow this roadmap?

Not to start. You’ll pick up basic Bash in stage 1. Python becomes useful in stages 4 and 5, especially for automation and application security.

Which track should I choose after the basics?

SOC is the most common first job and a safe default. Choose VAPT if you enjoy offensive work, network security if you like infrastructure, and application security if you come from development or testing.

Are free resources enough to learn cybersecurity?

Free resources can teach you the skills. What they usually lack is a clear order, feedback on your work and help with getting hired — that is what a structured course adds.

🛡️
Written by the Cyber Security Academy training team

Built from the order we teach in our own batches. Last updated 9 October 2026. Spotted something outdated? Tell us on WhatsApp.

Start stage 1 today

Follow this roadmap with a trainer by your side

Live classes in this exact order, hands-on labs every week and reviewed projects. Sit in on a class for free. Next batch starts Monday, 2 November 2026.

Keep reading
Free demo class

Book a free Cyber Security demo

Leave your details and a course counsellor will call you to fix a demo slot.

Thank you! A counsellor will call you shortly to confirm your demo slot.

Or call +91 70367 44555