Cyber Security Roadmap 2026: From Beginner to First Job
By Mehmood Ali (Mr. Professor), CEH, CEI, MCT · Cybersecurity trainer · Updated September 2026
Quick answer: The Cyber Security Roadmap 2026 I give my students has six phases:
- IT foundations: networking, Linux and Windows (months 1-2)
- Security fundamentals (month 3)
- Hands-on labs (months 3-6)
- Choosing a path: SOC, penetration testing, cloud or GRC (month 6)
- One or two certifications that match that path (months 6-9)
- A portfolio and job search (months 9-12)
With one to two hours of focused practice a day, most beginners are job-ready in about 12 months.

Why Most Beginners Get Stuck (and Why I Wrote This)
Every batch I teach starts with the same question: “Sir, where do I start?”
In over nine years of training, and more than 1,700 professionals later, I’ve watched two kinds of students. The first kind collects courses. They buy five video bundles, start three certifications and finish none. The second kind follows a simple order, practises every day and builds proof of their skills. The second group gets hired. The first group is usually still “preparing” a year later.
The problem is not a lack of resources. There are too many. What beginners really need is a sequence: what to learn first, what to ignore for now, and when to move on.
This Cyber Security Roadmap 2026 is the same order I give my own students. It’s built for three kinds of people:
- Complete beginners with no IT background
- IT professionals (help desk, network or system admins) who want to move into security
- Students who want a job-ready skill set by the time they graduate
The Cyber Security Roadmap 2026 at a Glance
| Phase | What you learn | Time | Proof you’re ready |
|---|---|---|---|
| 1. IT foundations | Networking, Linux, Windows | Months 1–2 | You can explain what happens when you open a website |
| 2. Security fundamentals | CIA triad, threats, attacks, basic crypto | Month 3 | You can explain phishing, malware and MFA to a non-IT friend |
| 3. Hands-on labs | TryHackMe / Hack The Box rooms | Months 3–6 | 50+ rooms completed with your own notes |
| 4. Choose a path | SOC, pentest, cloud or GRC | Month 6 | You know which job title you’re applying for |
| 5. Certifications | 1–2 certs that match your path | Months 6–9 | A certificate employers recognize |
| 6. Portfolio & job hunt | Writeups, GitHub, home lab, interviews | Months 9–12 | Interviews, then an offer |
Timelines assume one to two hours a day. If you already work in IT, you can move faster through Phase 1.
Phase 1: Build Your IT Foundations (Months 1–2)
You can’t protect what you don’t understand. Almost every security skill sits on top of three basics.
Networking. Learn IP addresses and subnets, TCP vs UDP, common ports (22, 53, 80, 443, 445, 3389), DNS, HTTP and how a router and firewall fit together. When you can read an Nmap scan and understand why a port is open, you’re ready to move on.
Linux. Most servers, security tools and CTF machines run Linux. Get comfortable with the terminal: moving around the file system, permissions, users, processes, package managers and basic Bash. Keep my Linux command cheat sheet open while you practise.
Windows. Most companies run on Windows and Active Directory, so learn users and groups, the registry, services, Event Viewer and PowerShell basics.
Free resources I recommend: TryHackMe’s Pre Security path, Linux Fundamentals 1–3, and Windows Fundamentals 1–3.
Phase 2: Learn Security Fundamentals (Month 3)
Now learn the language of security. This is the theory that shows up in every interview:
- The CIA triad (confidentiality, integrity, availability)
- Common attacks: phishing, malware, ransomware, password attacks, SQL injection, XSS
- Defences: firewalls, MFA, patching, least privilege, backups, logging
- Cryptography basics: hashing vs encryption, symmetric vs asymmetric keys, certificates
- Frameworks: know what the NIST Cybersecurity Framework and MITRE ATT&CK are, even if you don’t memorize them
These are the same topics CompTIA Security+ covers, so studying them now also prepares you for Phase 5.
Start here: my TryHackMe Starting Out in Cyber Sec walkthrough gives you a 30-minute overview of the career paths, and Introductory Research teaches the most underrated skill of all: finding answers yourself.
Phase 3: Get Hands-On With Labs (Months 3–6)
This is where the Cyber Security Roadmap 2026 turns from reading into doing, and where most of your real learning happens.
Employers don’t hire people who have watched hacking videos. They hire people who have done it. Platforms like TryHackMe and Hack The Box give you real machines to attack and defend, legally, from your browser.
How to do this phase well:
- Follow an order. I’ve put 350+ TryHackMe rooms in sequence in my TryHackMe roadmap. Start at the top and don’t skip ahead to hard CTFs.
- Try for 30 minutes before reading a writeup. Being stuck is where the learning happens.
- Take notes for every room: commands, mistakes and one lesson. These notes become your portfolio later.
- Join a seasonal event. TryHackMe’s Advent of Cyber is free and beginner-friendly. My Advent of Cyber 2025 walkthroughs cover all 24 days if you want to practise with it.
Target by the end of month 6: 50 or more rooms completed, with your own notes for each.
Phase 4: Choose Your Cyber Security Path (Month 6)
“Cyber security” isn’t one job, it’s a whole field. By month six you’ve tried enough to know what you enjoy. Pick one direction for your first job. You can always switch later.
| Path | What you do | Good fit if you… | Entry-level job titles |
|---|---|---|---|
| SOC / Blue team | Monitor alerts, investigate incidents, hunt threats | Like puzzles, logs and patterns | SOC Analyst L1, Security Analyst |
| Penetration testing / Red team | Legally hack systems and report weaknesses | Love breaking things and CTFs | Junior Pentester, VAPT Analyst |
| Cloud security | Secure Azure, AWS or Google Cloud setups | Already know (or like) cloud and admin work | Cloud Security Associate |
| GRC (Governance, Risk, Compliance) | Policies, audits, ISO 27001, risk assessments | Prefer writing, process and business | GRC Analyst, IT Auditor |
| Digital forensics | Recover evidence and investigate breaches | Are patient and detail-focused | Forensics Analyst, DFIR Associate |
My honest advice: for most beginners, the SOC analyst path is the fastest route to a first job. There are more openings, and the skills transfer to every other path later.
If you choose penetration testing, my OSINT and attack surface mapping lab shows what real reconnaissance looks like. If forensics interests you, start with my guide to data carving tools.
Phase 5: Earn the Right Certifications (Months 6–9)
Certifications don’t replace skills, but they get your CV past HR filters. The mistake I see most often is collecting random certificates. Pick one foundation certificate and one for your path, and stop there until you’re hired.
| Level | Certification | Best for |
|---|---|---|
| Foundation | CompTIA Security+ | Everyone: the most widely requested entry-level security cert |
| Foundation | Google Cybersecurity Certificate / ISC2 CC | Budget-friendly starting points |
| SOC / Blue | CompTIA CySA+, Microsoft SC-200, BTL1 | SOC analysts and threat detection |
| Pentest / Red | CEH, eJPT, PNPT, later OSCP | Penetration testers |
| Cloud | Microsoft AZ-500, AWS Security Specialty | Cloud security roles |
| GRC | ISO 27001 Lead Implementer / Auditor | GRC, audit and compliance |
| Forensics | CHFI | Digital forensics and incident response |
As a CEH and EC-Council Certified Instructor, and a Microsoft Certified Trainer, I teach several of these. Here’s the honest summary: Security+ plus hands-on labs beats three theory-only certificates. Interviewers will ask you to show what you know.
Phase 6: Build a Portfolio and Land the Job (Months 9–12)
A portfolio is what separates you from the hundreds of other applicants with the same certificate.
What to build:
- Writeups. Publish walkthroughs of rooms you’ve solved, on a blog, Medium or GitHub. It proves you can do the work and explain it, which is half of any security job.
- A GitHub profile with your notes, scripts and a simple project. For example, a Python port scanner or a log-parsing script.
- A home lab. Build it with VirtualBox: a Kali machine, a Windows machine and a small Active Directory. Add a free SIEM such as Wazuh or Splunk Free to practise SOC work.
- LinkedIn. Add a clear headline (“Aspiring SOC Analyst | Security+ | TryHackMe Top 5%”), post what you learn every week, and connect with security professionals in your city.
Job hunting tips that work:
- Apply for SOC L1, IT security support and VAPT internship roles. Don’t wait for the “perfect” job.
- In interviews, expect questions like: What happens when you type a URL? How would you investigate a phishing email? What’s the difference between hashing and encryption?
- Practise explaining one of your writeups out loud in five minutes. It’s the most impressive thing you can do in an interview.
- If you’re already in IT, look for an internal move into security. It’s often the easiest first step.
Your 12-Month Cyber Security Roadmap 2026 Timeline
| Month | Focus | Milestone |
|---|---|---|
| 1 | Networking basics | Can explain TCP/IP, DNS, HTTP |
| 2 | Linux + Windows | Comfortable in the terminal and PowerShell |
| 3 | Security fundamentals | Can explain common attacks and defences |
| 4–5 | TryHackMe labs (intro → tooling) | 30+ rooms with notes |
| 6 | Choose a path + more labs | 50+ rooms; path chosen |
| 7–8 | Certification study | Exam booked |
| 9 | Certification exam | Certified ✅ |
| 10 | Portfolio: writeups, GitHub, home lab | 5 published writeups |
| 11–12 | Job applications + interview practice | Interviews → first offer |
What I’ve Learned From Training 1,700+ Professionals
After years in the classroom, these are the patterns I see again and again:
- Consistency wins over intensity. One hour every day beats a ten-hour weekend binge. My most successful students were rarely the most talented. They were the ones who never stopped showing up.
- Skipping networking and Linux always backfires. Students who rush to “hacking” come back to the basics three months later, frustrated.
- Certificates without labs don’t get jobs. I’ve seen candidates with three certificates fail a simple practical test in an interview. I’ve seen candidates with one certificate and 100 TryHackMe rooms get hired.
- Writing is a superpower. Students who publish writeups get noticed. Reports, documentation and explaining risk to managers are a huge part of every security role.
- Community speeds everything up. Join Discord groups, local meetups and LinkedIn communities. Most first jobs come through people, not job portals.
Free vs Paid: Do You Need to Spend Money?
You can complete most of this Cyber Security Roadmap 2026 for free:
- Free:
- TryHackMe free rooms
- YouTube tutorials (including my channel, Mr. Professor, in Urdu and Hindi)
- Official vendor documentation
- Free SIEMs for your home lab
- Worth paying for later:
- One certification exam
- A TryHackMe or Hack The Box subscription once the free rooms feel easy
- Instructor-led training, if you learn better with structure and feedback
Spend money only when a free resource stops moving you forward.
Final Advice on Your Cyber Security Roadmap 2026
The 2026 cyber security job market rewards people who can prove skills, not just list them. Follow this Cyber Security Roadmap 2026 phase by phase, practise every day, choose one path, earn one or two relevant certifications, and build a portfolio that shows your work.
Start today with the TryHackMe roadmap: the first room takes ten minutes. Twelve months from now, you’ll be glad you started.
Happy learning! Mehmood Ali (Mr. Professor)
Related Guides
- TryHackMe Roadmap 2026: 350+ Rooms in Order
- Linux Command Cheat Sheet
- Advent of Cyber 2025 Walkthroughs
- Cybersecurity Threats & Technologies in 2026
- NIST Cybersecurity Framework (external)
Frequently Asked Questions
What is the best cyber security roadmap for beginners in 2026?
This Cyber Security Roadmap 2026 starts with IT foundations (networking, Linux and Windows), then security fundamentals, then hands-on labs on TryHackMe or Hack The Box. After about six months, choose a path (SOC, penetration testing, cloud or GRC), earn one or two matching certifications, and build a portfolio of writeups. Most beginners can be job-ready in around 12 months.
How long does it take to get a job in cyber security?
With one to two hours of daily practice, most complete beginners need about 9–12 months to become job-ready for entry-level roles like SOC Analyst. People already working in IT can often do it in 4–6 months.
Can I start cyber security with no IT background?
Yes. Many of my students started with no IT experience. You just need to spend more time on Phase 1 (networking, Linux and Windows) before moving to security topics and labs.
Which certification should I get first?
For most beginners, CompTIA Security+ is the best first certification because it covers the fundamentals and is widely recognized by employers. After that, choose a certification that matches your path, such as CySA+ or SC-200 for SOC work, or CEH and eJPT for penetration testing.
Do I need programming to learn cyber security?
You don’t need to be a programmer to start. Basic Python and Bash scripting become very useful after the first few months, for automating tasks and understanding exploits, but you can learn them along the way.
Is cyber security a good career in 2026?
Yes. Demand for skilled security professionals keeps growing as companies move to the cloud and face AI-driven attacks. Entry-level competition is real, though, so hands-on skills and a portfolio matter more than ever.



