Cybersecurity Roadmap

Foundations first, then attack and defend: a path from networking basics to hands-on practice.

10 milestones · ~149 hours total

  1. 1

    Networking and Linux fundamentals

    ~25h

    TCP/IP, DNS, HTTP, common ports, and comfort in a Linux terminal.

    Practice this →
  2. 2

    Security principles

    ~8h

    The CIA triad, threat modelling, risk, least privilege and defence in depth.

    Practice this →
  3. 3

    Cryptography basics

    ~12h

    Hashing, symmetric vs asymmetric encryption, TLS and digital signatures.

    Practice this →
  4. 4

    Web application security (OWASP Top 10)

    ~20h

    Injection, XSS, CSRF, broken access control and how to prevent each.

    Practice this →
  5. 5

    Authentication and access control

    ~10h

    Password storage, MFA, sessions/tokens, OAuth and role-based access.

    Practice this →
  6. 6

    Network security

    ~12h

    Firewalls, VPNs, IDS/IPS, segmentation and securing Wi-Fi.

    Practice this →
  7. 7

    Vulnerability assessment

    ~10h

    Scanning, reading CVEs, prioritising by risk, and responsible disclosure.

    Practice this →
  8. 8

    Logging, detection and incident response

    ~12h

    What to log, spotting suspicious patterns, and the steps of handling an incident.

    Practice this →
  9. 9

    Secure coding

    ~10h

    Validate input, handle secrets, update dependencies, and review code for common flaws.

    Practice this →
  10. 10

    Hands-on practice

    ~30h

    Legal practice labs and capture-the-flag events; write up what you learn.

    Practice this →