A practical entry roadmap for cyber security covering foundations, role selection, labs, evidence, applications and continuous learning.
What the work actually involves
Cyber security is not one job. The popular image — a penetration tester breaking into systems — describes maybe a tenth of the roles that actually exist and hire. Most cyber security work is monitoring, investigating, documenting, advising and configuring.
Choosing a specific target role early is the single biggest accelerator, because it tells you what to learn and what to build.
| Entry role | What you actually do all day | Good fit if you | Typical entry route |
|---|---|---|---|
| SOC / security analyst | Triage alerts, investigate suspicious activity, escalate and document incidents | Like methodical investigation and can handle shift patterns | Most common first job; IT support background transfers well |
| GRC analyst | Map controls to standards, chase evidence, support audits, assess suppliers | Write clearly, are organised, comfortable in meetings | Business, audit, legal or project backgrounds transfer well |
| Cloud security engineer | Review and fix identity, network and workload configuration | Already know cloud or infrastructure | Usually a second role, from cloud/sysadmin work |
| Penetration tester | Scoped testing of applications or infrastructure, then write it up | Persistent, enjoy deep technical rabbit holes | Hardest direct entry; usually needs demonstrable lab work |
| Security engineer | Build and maintain security tooling and automation | Can code and like building | Usually from software or platform engineering |
SOC analyst and GRC analyst are the two realistic direct-entry roles for most people. The others are typically second jobs.
The foundations you cannot skip
Nearly everyone who struggles to break in has skipped one of these. Security is applied knowledge — you cannot secure something you do not understand.
- Networking. TCP/IP, DNS, HTTP, routing, firewalls. If you cannot explain what happens when you type a URL and press enter, start here.
- Operating systems. Both Windows (including Active Directory) and Linux, at command-line comfort level. Most enterprise attacks involve Active Directory.
- Identity. Authentication, authorisation, MFA, SSO, privilege. This is where most real incidents actually begin.
- Cloud basics. At least one platform. Most environments you will defend are partly or fully cloud.
- A scripting language. Python or PowerShell, enough to parse a log file and automate something repetitive.
Budget three to six months on foundations if you are starting fresh. It is not wasted time — it is the difference between a candidate who can answer follow-up questions and one who cannot.
A realistic first-year plan
| Months | Focus | Output you should have |
|---|---|---|
| 1–3 | Networking, OS and identity fundamentals | Working home lab, notes you could teach from |
| 3–5 | Security+ or ISC2 CC, plus hands-on platforms | One certification, 20+ completed practical rooms/boxes |
| 5–8 | Pick a target role, go deeper in that direction | A written investigation or audit-style report |
| 8–12 | Apply, interview, iterate on feedback | Tailored CV per application, interview practice |
Where to learn — mostly free
- TryHackMe — the gentlest practical on-ramp, guided paths, low monthly cost
- Hack The Box — harder, less hand-holding, strong for offensive skills
- LetsDefend and Blue Team Labs Online — the defensive equivalent, closest to real SOC work
- Professor Messer — complete free Security+ video course
- Microsoft Learn security paths — free, and directly relevant since most enterprises are Microsoft shops
- ISC2 Certified in Cybersecurity — free entry certification
Building evidence that works
The single most effective portfolio item is a documented investigation. Set up a small lab, generate some suspicious activity, detect it, investigate it and write it up the way an analyst would: what triggered, what you checked, what you concluded, what you would recommend.
That one document demonstrates technical skill, investigative reasoning and written communication simultaneously — which is exactly what a hiring manager is trying to assess and rarely gets evidence of.
Realistic expectations on pay and entry
Entry-level SOC and GRC roles typically sit meaningfully below the headline "average cyber security salary" figures you see quoted, which are skewed by senior and specialist roles. Expect a first role to pay in line with other entry technical positions in your market, with faster-than-average progression afterwards.
Also expect the first role to be genuinely hard to get. The industry has a shortage of experienced people, not of beginners. Service desk, IT support or junior systems administration for a year is a legitimate and common route in — it builds exactly the foundations listed above while being paid.
Frequently asked questions
Do I need a cyber security degree?
No. It is one route, and a good one, but employers in this field are unusually open to demonstrated capability, career changers and non-traditional backgrounds.
Is the skills shortage real?
Yes, but it is a shortage of experienced practitioners. That is why the first role is the hard one and the third is comparatively easy.
Should I learn hacking first?
It is the most fun entry point and the least employable one on its own. Offensive skills are valuable, but the volume of hiring is in defence, operations and governance.

