Cybersecurity Roadmap
Foundations first, then attack and defend: a path from networking basics to hands-on practice.
10 milestones · ~149 hours total
- 1
Networking and Linux fundamentals
~25hTCP/IP, DNS, HTTP, common ports, and comfort in a Linux terminal.
Practice this → - 2
Security principles
~8hThe CIA triad, threat modelling, risk, least privilege and defence in depth.
Practice this → - 3
Cryptography basics
~12hHashing, symmetric vs asymmetric encryption, TLS and digital signatures.
Practice this → - 4
Web application security (OWASP Top 10)
~20hInjection, XSS, CSRF, broken access control and how to prevent each.
Practice this → - 5
Authentication and access control
~10hPassword storage, MFA, sessions/tokens, OAuth and role-based access.
Practice this → - 6
- 7
Vulnerability assessment
~10hScanning, reading CVEs, prioritising by risk, and responsible disclosure.
Practice this → - 8
Logging, detection and incident response
~12hWhat to log, spotting suspicious patterns, and the steps of handling an incident.
Practice this → - 9
Secure coding
~10hValidate input, handle secrets, update dependencies, and review code for common flaws.
Practice this → - 10
Hands-on practice
~30hLegal practice labs and capture-the-flag events; write up what you learn.
Practice this →