🛡️ Cybersecurity Roadmap 2026 — Learn Cybersecurity From Zero to Hired
A free, structured cybersecurity roadmap for beginners, career switchers, and IT pros in 2026. Networking and OS fundamentals, hands-on labs, certifications (Security+, CySA+, OSCP+, CISSP, CCSP, and the new SecAI+), specialization tracks (SOC/blue team, pentesting, cloud, GRC, IAM), salary data, and a realistic month-by-month study plan — all with vetted, working links.
Welcome! 🎉 This guide helps you navigate a path into cybersecurity, from foundational knowledge to practical experience and career tips. Whether you're a complete beginner, a career switcher, or an IT professional pivoting into security, this roadmap gives you a clear, structured path. Let's build a secure world together. 🌐🔐
Keywords: cybersecurity roadmap, learn cybersecurity 2026, how to become a cybersecurity analyst, SOC analyst path, penetration testing roadmap, cloud security career, cybersecurity certifications, CompTIA Security+, OSCP, CISSP, SecAI+, AI security, free cybersecurity resources.
🆕 What's new in 2026: AI-driven attacks and defenses (including autonomous "agentic" AI), identity-first and Zero Trust architecture, non-human/machine identity, post-quantum cryptography readiness, deepfake-enabled social engineering, and cloud-native security are reshaping the field. This edition reflects those shifts — and the certification landscape that changed alongside them.
🗂️ Table of Contents
- 👤 Who This Roadmap Is For
- 🚀 Foundation
- 🔎 Fundamentals
- 💻 Programming & Scripting
- 🌐 Specialization Tracks
- 🤖 Emerging Areas (2026 Focus)
- 🧪 Practical Experience & Labs
- 📚 Continuous Learning
- 📺 YouTube Channels
- 💼 Job Roles & Salaries
- 🔐 Improving Your Skills
- 💼 Finding a Job
- 📜 Certifications
- 📅 6-Month Roadmap
- 📈 Tips for Success
- 📚 Recommended Books
- 🤝 Communities
- ❓ Frequently Asked Questions
- 🤗 Contributing
👤 Who This Roadmap Is For
This roadmap works for three kinds of people:
- Complete beginners with no IT background who want a realistic, no-hype path into security.
- Career switchers (help desk, sysadmin, developer, or non-tech) who already have transferable skills and want to specialize.
- Students and self-learners building a portfolio to break into their first SOC, GRC, or junior analyst role.
You don't need a degree. You do need consistency, hands-on practice, and a visible portfolio. Pick a track, follow the plan, and document everything publicly. Skills and a portfolio open more doors than credentials alone.
🚀 Foundation
Before you can defend systems, you need to understand how they work. These foundational skills — networking, operating systems, and core IT concepts — are non-negotiable. Hiring managers consistently cite weak fundamentals as the biggest gap in entry-level candidates.
-
Networking Basics 🌐 — how devices share data and connect through networks.
-
Operating System Fundamentals 🖥️ — how Windows and Linux internals work: process management, memory, permissions, the boot process.
-
Linux Essentials 🐧 — most security tools (and most servers) run on Linux. Command-line fluency is mandatory.
-
TCP/IP Networking 🌐 — the protocol stack the entire internet runs on.
-
Introduction to Cybersecurity 🔒 — start with the why and the big picture.
- ISC2 Certified in Cybersecurity (CC) — vendor-neutral entry cert. Note: the free "One Million Certified in Cybersecurity" program closed to new enrollments on May 20, 2026. The CC is now a standard paid exam (about $199 + $50 annual maintenance fee), and a new exam outline takes effect September 1, 2026.
- Introduction to Cyber Security Specialization — Coursera
-
CompTIA Network+ 📜 — the industry-recognized credential validating your networking knowledge.
-
Virtualization Basics 🌪️ — you'll spin up virtual labs constantly.
🔎 Fundamentals
With the basics in place, dive into core security concepts and the tools security teams use every day.
-
Security Fundamentals
- CompTIA Security+ — official — the current exam is SY0-701. A successor (SY0-801, adding AI/LLM security content) is expected to preview in late 2026; SY0-701 stays valid and fully recognized, so most people should still take it now.
- Professor Messer's free Security+ training (SY0-701)
- Google Cybersecurity Professional Certificate — Coursera
-
The CIA Triad & Core Principles — Confidentiality, Integrity, Availability: the bedrock of every security decision.
-
Common Vulnerabilities ⚠️
-
Threat Modeling & Attacker Mindset
- MITRE ATT&CK Framework — the standard map of how real attackers operate. Learn it cold.
- MITRE D3FEND — the defensive-countermeasures companion to ATT&CK.
- MITRE ATLAS — the ATT&CK-style knowledge base for attacks on AI/ML systems (increasingly essential in 2026).
-
Cybersecurity Frameworks 📏
-
Incident Response Fundamentals 🚨
- NIST SP 800-61 Rev. 3 (April 2025) — Incident Response for Cybersecurity Risk Management — fully rewritten to align with CSF 2.0's six Functions (Govern, Identify, Protect, Detect, Respond, Recover). This supersedes Rev. 2.
- SANS Reading Room — Incident Handling papers (free)
-
Introduction to Malware Analysis 🦠
-
Phishing & Social Engineering Awareness 📧
-
Cryptography Basics 🔐
-
Data Privacy & Compliance 🔒
💻 Programming & Scripting
You don't need to be a software engineer, but you do need to read and write code. Automation, tooling, and analysis all live here.
-
Python 🐍 — the lingua franca of security tooling.
-
Bash & Shell Scripting 🐚
-
PowerShell 💠 — essential for Windows / Active Directory work.
-
Understanding code you'll see in the wild
- JavaScript (web exploitation, XSS)
- SQL (injection attacks, database hardening)
- C / C++ (memory corruption, deeper malware analysis)
-
Regular Expressions — RegexOne (interactive)
🌐 Specialization Tracks
After fundamentals, pick a track. Specialists tend to out-earn generalists, and most 2026 roles expect depth, not just breadth. Below are the major tracks with the certifications that signal expertise in each.
1. Security Operations / SOC Analyst (Blue Team) 🛡️
You'll do: monitor SIEM alerts, investigate incidents, respond to threats.
2. Penetration Testing / Red Team 💻
You'll do: simulate attacks to find weaknesses before real adversaries do.
- CompTIA PenTest+
- INE eJPT (great entry-level practical)
- Certified Ethical Hacker (CEH)
- OffSec PEN-200 → OSCP / OSCP+ — the gold-standard hands-on cert. Since November 2024, passing awards both the lifetime OSCP and the 3-year OSCP+; the exam now includes a mandatory Active Directory "assumed compromise" set and no longer awards bonus points.
3. Incident Response & Digital Forensics 🔍
You'll do: investigate breaches, recover evidence, write up what happened.
4. Governance, Risk & Compliance (GRC) 📝
You'll do: map controls to frameworks, manage audits, translate security to business.
- ISACA CISA — Certified Information Systems Auditor
- ISACA CRISC — Risk and Information Systems Control
- ISO/IEC 27001 Lead Auditor (PECB)
5. Security Architecture & Leadership 🏛️
You'll do: design enterprise security, make build-vs-buy calls, run programs.
- ISC2 CISSP
- ISC2 CISSP-ISSAP (Architecture concentration)
- ISACA CISM — Information Security Manager
- CompTIA SecurityX (the successor to CASP+) — vendor-neutral advanced/architect-level cert. Existing CASP+ holders transition automatically, no retake required.
6. Cloud Security ☁️
The fastest-growing specialization. Almost every org runs hybrid/multi-cloud now.
- ISC2 CCSP
- AWS Certified Security – Specialty
- Microsoft SC-100: Cybersecurity Architect Expert
- Google Cloud Professional Cloud Security Engineer
7. Application Security (AppSec) / DevSecOps 📱
- GIAC Web Application Penetration Tester (GWAPT)
- OffSec WEB-200 → OSWA
- Certified DevSecOps Professional (CDP)
8. Identity & Access Management (IAM) 🪪
Identity is the new perimeter in 2026 — and non-human / machine identity (service accounts, API keys, and AI agents) is now one of the fastest-growing attack surfaces.
9. AI Security 🧠 (new track)
Securing AI systems — and using AI safely inside security operations — is now its own career path.
- CompTIA SecAI+ (CY0-001) — launched February 17, 2026, the first vendor-neutral certification focused on securing AI systems and leveraging AI in security operations. Recommended after Security+/CySA+/PenTest+.
- Free foundations: OWASP Top 10 for LLM Applications, MITRE ATLAS, and the NIST AI Risk Management Framework.
🤖 Emerging Areas (2026 Focus)
These aren't fringe topics anymore — they appear in mainstream job descriptions. Building familiarity here will set you apart.
-
AI Security & Adversarial ML 🧠 — how attackers exploit AI systems (prompt injection, training-data poisoning, model extraction, jailbroken LLMs) and how defenders use AI for detection. In 2026, agentic AI — autonomous agents that reason, plan, and act — is being used on both sides: to automate parts of the attack kill chain, and to accelerate SOC triage and investigation. "Autonomous agent hijacking" is now a recognized attack category.
-
Deepfakes & AI-Enabled Social Engineering 🎭 — voice- and video-cloning are now routinely used in fraud and business-email-compromise. The defensive shift is toward contextual verification (out-of-band callbacks, code words, verifying intent) rather than trying to spot fakes visually.
-
Non-Human Identity (NHI) & Machine Identity 🤖🪪 — service accounts, API keys, secrets, and AI-agent credentials now vastly outnumber human identities and are a top lateral-movement vector. Expect to see NHI governance in more job descriptions.
-
Zero Trust Architecture 🚧 — "never trust, always verify." The replacement for perimeter-based security, now extended to devices, workloads, APIs, and AI systems.
-
Post-Quantum Cryptography (PQC) 🔮 — NIST finalized its first three quantum-resistant standards in August 2024: ML-KEM (FIPS 203) for key exchange, ML-DSA (FIPS 204) and SLH-DSA (FIPS 205) for signatures. HQC was selected as a backup KEM in March 2025, and a FALCON-based signature standard (FIPS 206) is in progress. "Harvest now, decrypt later" attacks make migration urgent.
-
Supply Chain & Software Bill of Materials (SBOM)
-
Container & Kubernetes Security
-
OT / ICS Security ⚙️ — securing industrial control systems and critical infrastructure. A high-paying specialization with a large talent gap.
🧪 Practical Experience & Labs
Certifications open doors; hands-on skills get you hired. Hiring managers consistently say practical experience matters more than credentials alone.
- TryHackMe 🔐 — guided, beginner-friendly rooms — tryhackme.com
- Hack The Box 🕵️ — more advanced, CTF-style — hackthebox.com
- OverTheWire ⚔️ — classic wargames, great for Linux — overthewire.org/wargames
- VulnHub 🏴☠️ — downloadable vulnerable VMs — vulnhub.com
- PortSwigger Web Security Academy 🌐 — best free web-app security training, by the makers of Burp Suite — portswigger.net/web-security
- picoCTF 🚩 — free, beginner-friendly CTF platform — picoctf.org
- CTFtime 📅 — calendar of running CTF competitions worldwide — ctftime.org
- Blue Team Labs Online 🔵 — defender-focused challenges — blueteamlabs.online
- LetsDefend — SOC analyst simulation — letsdefend.io
- Proving Grounds (OffSec) — OSCP-like practice — offsec.com/labs
- RangeForce — interactive defense labs — rangeforce.com
Build a Home Lab
A home lab is one of the best portfolio builders. Common setups:
- Active Directory lab — a domain controller + a couple of Windows clients + a Kali attacker.
- Detection lab — the DetectionLab project ships a pre-built Splunk + Velociraptor + Sysmon environment. (Check the repo's current status/notes before relying on it.)
- SOC-in-a-box — Security Onion, the ELK/Elastic Stack, or Wazuh.
📚 Continuous Learning
Cybersecurity changes faster than any other IT discipline. Staying current is part of the job.
- The Hacker News 👨💻 — thehackernews.com
- BleepingComputer 💻 — bleepingcomputer.com
- Krebs on Security 🔍 — krebsonsecurity.com
- Dark Reading 📰 — darkreading.com
- CyberScoop 🌐 — cyberscoop.com
- Risky Business 🎙️ (podcast) — risky.biz
- TLDR Sec 📩 (newsletter) — tldrsec.com
- SANS Internet Storm Center 🌪️ — isc.sans.edu
- CISA Advisories 🚨 — cisa.gov/news-events/cybersecurity-advisories
- Schneier on Security 🔐 — schneier.com
Reddit Communities
r/cybersecurity · r/netsec · r/AskNetsec · r/blueteamsec · r/redteamsec
People to Follow
Brian Krebs · Bruce Schneier · SwiftOnSecurity · Marcus Hutchins (MalwareTech) · Katie Nickels (threat intel) · John Hammond.
📺 YouTube Channels
- John Hammond — CTFs, malware analysis, practical projects
- NetworkChuck — networking, Linux, cloud, fun and accessible
- Professor Messer — complete free CompTIA training
- The Cyber Mentor (TCM Security) — ethical hacking and pentesting
- IppSec — Hack The Box walkthroughs (gold standard)
- LiveOverflow — deep technical hacking content
- HackerSploit — penetration testing tutorials
- David Bombal — networking, security, career advice
- Hak5 — hacking gear and techniques
- STÖK — bug bounty hunting
- InsiderPhD — bug bounty and API security
- LowLevelLearning — low-level systems and security
💼 Job Roles & Salaries
The ranges below are 2025–2026 estimates and vary widely by experience, location, industry, and certifications. Always cross-check with current sources before making decisions.
| Job Role | Avg. Salary (PHP) | Avg. Salary (USD) | Avg. Salary (AUD) |
|---|---|---|---|
| SOC Analyst (Tier 1) | ₱600,000 | $55,000–$75,000 | AU$70,000 |
| Security Analyst | ₱850,000 | $75,000–$95,000 | AU$95,000 |
| Network Security Engineer | ₱1,200,000 | $95,000–$120,000 | AU$110,000 |
| Penetration Tester | ₱1,100,000 | $90,000–$130,000 | AU$115,000 |
| Incident Responder | ₱1,300,000 | $100,000–$140,000 | AU$125,000 |
| Forensic Analyst | ₱1,150,000 | $85,000–$115,000 | AU$105,000 |
| Malware Analyst | ₱1,400,000 | $100,000–$140,000 | AU$120,000 |
| Cloud Security Engineer | ₱1,500,000 | $120,000–$160,000 | AU$140,000 |
| AI Security Engineer | ₱1,600,000 | $130,000–$180,000 | AU$150,000 |
| Security Consultant | ₱1,600,000 | $110,000–$160,000 | AU$130,000 |
| GRC Analyst | ₱1,000,000 | $85,000–$115,000 | AU$105,000 |
| Security Architect | ₱2,200,000 | $140,000–$200,000 | AU$170,000 |
| CISO | ₱4,000,000+ | $200,000–$400,000+ | AU$250,000+ |
Verify current numbers here
- Philippines: JobStreet, PayScale Philippines, Kalibrr
- United States: BLS Occupational Outlook Handbook, Glassdoor, Levels.fyi
- Australia: SEEK Salary Guide, Hays Salary Guide
Market note (2026): the global cybersecurity workforce gap remains large (commonly cited around 4+ million unfilled roles), and AI-security roles are among the fastest-growing. Demand is strong, but entry-level competition has tightened — hands-on skills and a visible portfolio matter more than ever.
🔐 Improving Your Skills
-
Practice secure online behavior 🕵️
- Use unique passwords with a password manager (Bitwarden, 1Password).
- Enable multi-factor authentication everywhere — prefer hardware keys (YubiKey) or passkeys over SMS.
- Be cautious about oversharing personal info online.
-
Keep everything updated 🔄 — auto-update your OS, browser, and apps; subscribe to vendor security advisories for tools you rely on.
-
Secure your home network 🛡️ — use WPA3 where possible, change default router credentials, segment IoT devices onto a guest network, and consider pfSense/OPNsense for serious labs.
-
Educate yourself daily 📚 — 15 minutes of news plus one TryHackMe room a day adds up fast.
-
Use security tools 🔧 — a VPN on untrusted networks, reputable EDR/antivirus, a password manager (mandatory), and DNS filtering (NextDNS, Cloudflare 1.1.1.1 for Families).
-
Practice hands-on 💻 — CTFs, home labs, write-ups. Document everything on GitHub — your portfolio is your proof.
-
Join communities 🌐 — Discord servers, Reddit, local DEF CON groups, OWASP and ISC2 chapters.
-
Self-audit regularly 🔍 — review your digital footprint quarterly and run Have I Been Pwned checks.
💼 Finding a Job
1. Build your portfolio
A resume tells; a portfolio shows. At minimum: a clean GitHub with lab and CTF write-ups, a technical blog (Medium, Hashnode, or self-hosted), and documented home-lab projects.
2. Tailor your resume
Use keywords from the job description (ATS systems screen aggressively), quantify wins ("reduced false-positive alerts by 30%"), and put relevant certs up top.
3. Apply broadly — especially to adjacent roles
You won't land Senior Pentester first. Realistic entry points: SOC Analyst Tier 1, Junior Security Analyst, IT Support → Security pivot, Help Desk → SOC pivot, GRC Analyst (often an easier entry for non-tech backgrounds), and internships/apprenticeships.
4. Job boards
LinkedIn · Indeed · Glassdoor · CyberSecJobs · InfoSec Jobs · JobStreet (PH/SEA) · Kalibrr (PH) · Wellfound (startups)
5. Network intentionally
Attend conferences (DEF CON, BSides, RSA, ROOTCON in PH), local meetups, and OWASP chapter events. On LinkedIn, comment thoughtfully — don't just spam connections.
6. Prepare for interviews
Common technical topics: networking (OSI/TCP), the cyber kill chain, MITRE ATT&CK, common attacks (XSS, SQLi, phishing), and IR basics. Behavioral: "tell me about a time you handled a difficult problem." Practical: many companies use scenario-based interviews or take-home labs.
7. Stay persistent
Track applications in a spreadsheet, ask for feedback on rejections, and keep learning while you apply.
📜 Certifications
Certifications build credibility, validate knowledge, and unlock job filters — but they don't replace experience. Be strategic about which ones you pursue.
Entry-Level (start here)
- CompTIA Security+ (SY0-701) — comptia.org/certifications/security Appears in a large share of entry-level postings and satisfies the DoD 8140 baseline. The most universally useful first cert. (Successor SY0-801 with AI content is expected to preview in late 2026; a current Security+ stays valid for three years regardless of version.)
- Google Cybersecurity Professional Certificate — Coursera Great for career switchers; budget-friendly with hands-on labs.
- ISC2 Certified in Cybersecurity (CC) — isc2.org/certifications/cc Vendor-neutral and foundational. The free "One Million Certified" program closed to new enrollments on May 20, 2026; the CC is now a standard paid exam (~$199 + $50 AMF), with a new exam outline effective September 1, 2026.
- CompTIA Network+ — comptia.org/certifications/network Networking foundation. Recommended before Security+ if you lack a networking background.
Intermediate (after a year or two)
- CompTIA CySA+ — comptia.org/certifications/cybersecurity-analyst — best second cert for SOC/blue-team careers.
- CompTIA PenTest+ — comptia.org/certifications/pentest — bridge to offensive security before OSCP.
- CompTIA SecAI+ (CY0-001) — comptia.org/en-us/certifications/secai — launched Feb 17, 2026; the first vendor-neutral AI-security cert. Builds on Security+/CySA+/PenTest+ and covers securing AI systems, AI-assisted security operations, and AI governance/risk/compliance.
- Certified Ethical Hacker (CEH) — eccouncil.org — HR-friendly but criticized as theory-heavy; often required for government roles.
- INE eJPT — security.ine.com — affordable, practical entry to pentesting.
Advanced / Specialist
- OSCP / OSCP+ (OffSec) — offsec.com/courses/pen-200 — gold standard for hands-on pentesting. OSCP is lifetime; OSCP+ carries a 3-year validity (renewable via the OffSec CPE program, a recert exam, or another qualifying OffSec exam). Both are awarded on passing.
- CompTIA SecurityX (formerly CASP+) — comptia.org — advanced/architect-level; CASP+ holders transition automatically.
- GIAC GCIH / GSEC / GCFA / GPEN / GWAPT — giac.org/certifications — highly respected but expensive (typically paired with SANS training).
- ISC2 CISSP — isc2.org/certifications/cissp — the leadership/architecture gold standard. Requires 5 years' experience.
- ISC2 CCSP — isc2.org/certifications/ccsp — cloud security expert. Check ISC2 for the current exam outline before scheduling.
- ISACA CISA / CISM / CRISC — isaca.org — audit, management, and risk; the GRC gold standards.
- AWS Certified Security – Specialty — aws.amazon.com
- Microsoft SC-100 Cybersecurity Architect Expert — learn.microsoft.com
A practical path for most beginners: Google Cybersecurity Cert → Security+ → CySA+ (or PenTest+) → then a track cert (OSCP+ for offense, CCSP/SC-100 for cloud, CISA/CISM for GRC, SecAI+ for AI) → CISSP once you have the experience.
📅 6-Month Roadmap
A realistic plan. Adjust the pace to your schedule — full-time learners can compress this; nights/weekends learners may stretch to 9–12 months.
| Month | Focus Area | Activities | Resources |
|---|---|---|---|
| Month 1 | Networking + Linux | Set up a home lab in VirtualBox; install Ubuntu and Kali; complete networking basics; practice on the Linux CLI | Cisco NetAcad, Linux Journey, OverTheWire Bandit |
| Month 2 | Security fundamentals + CIA triad | Begin Security+ study; learn the CIA triad, AAA, common threats; skim NIST CSF 2.0 | Professor Messer Security+, NIST CSF |
| Month 3 | Threats, vulns & MITRE | Study OWASP Top 10 and MITRE ATT&CK; read recent breach case studies; learn ransomware, phishing, supply-chain, AI threats | OWASP Top 10, MITRE ATT&CK, Krebs on Security |
| Month 4 | Hands-on tools | Wireshark, Nmap, Burp Suite, Metasploit, basic Splunk/ELK; start the TryHackMe beginner path | TryHackMe, Wireshark, PortSwigger Academy |
| Month 5 | Practical skills + projects | Take the Security+ exam; build out your home lab (AD or SOC); complete your first CTFs; document everything on GitHub | Security+, DetectionLab, picoCTF, CTFtime |
| Month 6 | Specialize + network | Pick a track (SOC, pentest, cloud, GRC, AI security); attend a virtual conference or local meetup; polish LinkedIn; start applying | BSides, LinkedIn, r/cybersecurity |
📈 Tips for Success
- Build a portfolio — a GitHub repo with documented labs, CTF write-ups, and tools you've written often beats certifications in technical interviews.
- Stay updated 🔄 — subscribe to 2–3 newsletters max (avoid overload). Risky Business, TLDR Sec, and BleepingComputer are great starts.
- Master core tools 🔧 — Wireshark, Nmap, Burp Suite, Metasploit, Splunk, the Linux CLI, and basic SIEM querying appear in nearly every job description.
- Develop soft skills — communication separates senior people from technicians. Practice writing clear reports and explaining technical concepts to non-technical stakeholders.
- Find a mentor — ISC2 chapters, meetups, and thoughtful LinkedIn outreach. Most professionals will give 30 minutes to someone making genuine effort.
- Do CTFs 🚩 — pick one per month from CTFtime. Even failing teaches a lot.
- Ethics first — never use your skills on systems you don't have written permission to test. One unethical act can end a security career.
- Contribute to open source 🛠️ — bug reports, docs, and small fixes are great resume material.
- Embrace "Try Harder" — persistence beats genius. Most senior pros got there by being stubborn, not brilliant.
📚 Recommended Books
- The Web Application Hacker's Handbook — Dafydd Stuttard & Marcus Pinto
- Hacking: The Art of Exploitation — Jon Erickson
- The Tangled Web — Michał Zalewski
- Practical Malware Analysis — Sikorski & Honig
- Cybersecurity Essentials — Charles J. Brooks et al. (great intro)
- Sandworm — Andy Greenberg (nation-state threats)
- Countdown to Zero Day — Kim Zetter (the Stuxnet story)
- The Cuckoo's Egg — Cliff Stoll (a classic)
- Permanent Record — Edward Snowden
- Click Here to Kill Everybody — Bruce Schneier
- Blue Team Handbook — Don Murdoch
- RTFM / BTFM (Red/Blue Team Field Manuals) — Ben Clark / Alan White (cheat-sheet style)
🤝 Communities
- OWASP — open web application security; local chapters worldwide
- DEF CON Groups — local hacker meetups
- BSides — community-driven conferences globally
- ISC2 Chapters
- ISACA Chapters
- Philippines: ROOTCON — the premier PH hacking conference
- Discord: TCM Security, John Hammond, NetworkChuck, and the official Hack The Box community servers
❓ Frequently Asked Questions
How do I start cybersecurity with no experience?
Start with networking and Linux fundamentals, then Security+ concepts. Do one hands-on lab (TryHackMe) per day and document what you learn publicly on GitHub. Aim for a first role like SOC Analyst Tier 1, junior analyst, or a help-desk → security pivot.
Which certification should I get first?
For most people, CompTIA Security+ is the best first cert — it's widely required and satisfies DoD 8140. If budget is tight, the Google Cybersecurity Certificate is a strong, affordable starting point. Network+ first if you lack networking background.
Is the ISC2 CC still free in 2026?
No. The free "One Million Certified in Cybersecurity" program closed to new enrollments on May 20, 2026. The CC is now a standard paid exam (~$199 + $50 annual maintenance fee), and a refreshed exam outline takes effect September 1, 2026.
Should I take Security+ SY0-701 now or wait for SY0-801?
Take SY0-701 now if you're ready. It's proven, well-supported, and stays valid for three years regardless of version. Only wait for SY0-801 (expected to preview around late 2026, with new AI/LLM content) if you genuinely won't be ready until then or are targeting an AI-centric role.
Do I need to know how to code?
You don't need to be a software engineer, but you should be able to read and write scripts. Learn Python first, then Bash, and PowerShell if you'll work with Windows/Active Directory.
Is a degree required for cybersecurity?
No. A degree helps with some employers, but hands-on skills, a portfolio, and relevant certs are what most hiring managers actually screen for.
What are the fastest-growing cybersecurity areas in 2026?
Cloud security, AI security (securing AI systems and defending against AI-enabled attacks), identity/IAM (including non-human/machine identity), and OT/ICS security — all with significant talent gaps.
How long does it take to get a cybersecurity job?
With consistent effort, many people go from zero to a first entry-level role in roughly 6–12 months — faster with prior IT experience, slower if studying part-time. The 6-month roadmap above is a realistic backbone.
🤗 Contributing
Contributions are welcome! If you spot a broken link, an outdated fact, or have a resource to add, please open an issue or a pull request. Please keep resources free or clearly labeled, and prefer official/canonical sources.
Connect with Me
- GitHub: carlcastanas
- LinkedIn: Carl Andrew Castañas
- Email: cacastanas@gmail.com
🕒 Last Updated
- Timezone: Philippine Standard Time (PHT) — UTC+8
- Last Updated: July 6, 2026
- Version: 2.1 — 2026 Edition
If this roadmap helped you, please ⭐ the repo — it helps others find it. Happy learning, and stay safe online! 🎉🔐