Cyber Security — Where to Go Next¶
If today sparked something, this is where to go next.
Most of this is free. You don't need a degree, expensive hardware or permission to start learning — you just need curiosity.
This page is intended to work for anyone from a student who's just discovered cyber security through work experience to someone at work who's thinking "hang on, this stuff is actually pretty interesting."
You don't need to know what part of cyber you want to do yet. That's what exploring is for.
If You Only Do Five Things¶
Don't try to do everything on this page. Pick something and have a go.
1. Do the Security Blue Team Junior Analyst Pathway¶
Security Blue Team — Junior Analyst Pathway
Start here. Six introductory courses covering phishing analysis, digital forensics, threat intelligence, SIEM and incident response. Finish the pathway and you get a certificate.
It's particularly useful because it starts to show you what defensive cyber security actually looks like.
2. Try TryHackMe¶
Guided, gamified labs covering networking, Linux, security, offensive security and defensive security.
You don't need to know what you're doing before you start. That's rather the point.
3. Have a go at picoCTF¶
Free capture-the-flag challenges designed around learning by solving problems.
If you like puzzles, this is probably going to be your thing.
4. Learn some networking¶
Understand what an IP address, DNS, port, TCP, UDP, HTTP and HTTPS actually are.
You don't need to become a network engineer. But understanding how computers communicate is one of the foundations of cyber security.
5. Build something¶
Don't just collect certificates.
Set up a VM. Write a script. Analyse a phishing email. Investigate a log file. Build a tiny network. Solve a CTF and write up how you solved it.
Doing something and being able to explain it is worth far more than clicking "Complete Course" another 20 times.