You want a job in cybersecurity. But where do you start? One video says learn Python. Another says to buy a certificate. A third says start hacking today. It gets confusing fast.
A cybersecurity roadmap fixes that. It’s a plan that shows what to learn first, what to learn next, and when to stop reading and start practicing. Students at LetsLearn in Kathmandu ask us about this all the time. So we wrote the plan in plain words.
A cybersecurity roadmap is a learning plan. It takes you from basic computer skills to a real cybersecurity job, step by step, using skills, labs, certificates, and projects.
- Who should follow it: Students, career switchers, and anyone starting from zero. You don’t need a degree or an IT job to begin.
- Career plan, not company plan: Some companies also write a cybersecurity roadmap to plan their security budget. That’s a different thing. This guide is about your career.
Cybersecurity Roadmap at a Glance
Here’s the whole cybersecurity roadmap on one page. Come back to it when you feel lost.
| Phase | What you learn | Time | Free place to practice |
| 1. Foundations | Computers, networks, Linux, Windows | Months 1-2 | Cisco Networking Academy |
| 2. Core ideas | CIA triad, threats, risk | Month 3 | roadmap.sh |
| 3. Hands-on skills | Nmap, Wireshark, Splunk, labs | Months 3-6 | TryHackMe, OverTheWire |
| 4. Certificates | Google certificate, Security+ | Months 4-8 | Official study guides |
| 5. Career path | Pick a track, build projects | Months 6-12 | Hack The Box, GitHub |
- Milestones to check yourself: After 3 months, you can explain how a web page reaches your phone. After 6 months, you can scan a practice network and read a log. After 12 months, you can show three projects to an employer.
Phase 1: Build Your IT and Networking Foundations
Every cybersecurity roadmap starts here, even if it feels boring. Attackers break into computers and networks. If you don’t know how those work, you can’t guard them. A good guard first learns where every door and window is.
- How computers, networks, and the internet work: A network joins computers together. The internet is many networks joined together. Try to explain how a web page travels to your phone.
- Networking words to know: An IP address is a home address for a device. A port is a door on that address. A router guides traffic. A firewall is the gate guard.
- TCP/IP, DNS, and common protocols: TCP/IP is the set of rules computers use to talk. DNS turns a name like google.com into an IP address, like a phone book.
- Linux and Windows basics: Learn how users, files, and permissions work. Linux matters a lot because many security tools run on it.
- Command-line skills: The command line means typing instead of clicking. Learn ten simple commands, like ls, cd, and ping.
Phase 2: Learn Core Cybersecurity Concepts
This part of the cybersecurity roadmap teaches the big ideas. Don’t rush it. These ideas show up in every job interview.
- The CIA triad: Confidentiality means only the right people see the data. Integrity means nobody changes it in secret. Availability means it works when you need it. Think of your bank app.
- Common threats: Phishing is a fake message that tricks you. Malware is bad software. Ransomware locks your files and asks for money.
- Controls, risk, and compliance: A control is a lock. Risk is the chance that something bad happens. Compliance means following the rules a company must follow.
- Authentication and access control: Authentication proves who you are. Authorization decides what you’re allowed to do.
- Incident response basics: When an attack happens, a team spots it, stops it, fixes it, and learns from it.
Phase 3: Develop Hands-On Cybersecurity Skills
Reading alone won’t make you good. It’s like swimming. You can’t learn it from a book. The hands-on part of any cybersecurity roadmap is where skills become real.
- Nmap, Wireshark, and Burp Suite: Nmap finds open doors on a computer. Wireshark shows messages moving on a network. Burp Suite tests websites for weak spots. Only use them on labs you have permission to test.
- SIEM tools like Splunk: A SIEM collects logs, which are diaries that computers write. It shows anything odd. Splunk has a free version for practice.
- A home lab: Install free VirtualBox on your laptop. Add Kali Linux and one practice machine that’s weak on purpose. A laptop with 8 GB of RAM is a fair start.
- Where to practice: TryHackMe has guided lessons. Hack The Box has harder puzzles. OverTheWire teaches the command line through games. Cisco Networking Academy has free networking courses.
Phase 4: Follow the Right Cybersecurity Certification Roadmap
Do you need certificates? Not to start. But they help when you have no job history yet. They fit into your cybersecurity roadmap like checkpoints.
| Step | Certificate | Level | Rough cost (check the official site) |
| 1 | Google Cybersecurity Certificate | Beginner | Monthly Coursera fee |
| 2 | CompTIA Security+ | Beginner | Around $400 for the exam |
| 3 | CompTIA CySA+ | Intermediate | Around $400 for the exam |
| 4 | CEH | Intermediate | Often over $1,000 with training |
| 5 | OSCP | Advanced | Over $1,000 |
| 6 | CISSP | Advanced | Around $750, plus years of work experience |
- How to read the table: Security+ is the best known entry certificate. CySA+ suits defenders. CEH and OSCP suit attackers. CISSP is for people with real work experience.
- Best order for 2026: Start with the Google certificate or Security+. Then pick your path. CISSP comes much later.
Phase 5: Choose Your Cybersecurity Career Path
You can’t learn everything. Pick one path on your cybersecurity roadmap and go deep. You can switch later.
- Cybersecurity analyst roadmap: Analysts watch alerts and check if they’re real. Learn logs and SIEM tools. It’s a common first job.
- Cybersecurity engineer roadmap: Engineers build and fix security tools, like firewalls. Learn deeper networking and some Python.
- Cybersecurity architect roadmap: Architects design a company’s whole security plan. It takes years of experience, so it’s a later step.
- Cybersecurity GRC roadmap: GRC means governance, risk, and compliance. There’s less hacking and more rules, audits, and writing.
- Cloud security path: You protect data stored on AWS, Azure, or Google Cloud. Learn one cloud first.
- AI security path: You protect AI tools and use AI to defend. It’s new, so learn the basics first.
A cybersecurity specialist roadmap is the same path. You just go deeper on one topic.
Red Team vs Blue Team: Which Cybersecurity Path Is Right for You?
Every cybersecurity roadmap splits into two sides. One side attacks, with permission. The other side defends.
| Red team | Blue team | |
| Job | Break in to find weak spots | Defend and catch attackers |
| Example roles | Penetration tester | SOC analyst |
| Key skills | Scripting, web hacking | Logs, SIEM, incident response |
| Certificates | CEH, OSCP | Security+, CySA+ |
| Feels like | Solving puzzles | Being a detective |
- Which has better long-term chances? Both have good futures. Blue team has more beginner jobs. Many people start there and move to red team later.
Cybersecurity Roadmap for Beginners With No Degree or IT Background
- Can you get in without a degree? Yes. Many employers care more about skills. Some big companies still ask for a degree, so projects and certificates matter even more for you.
- Cybersecurity roadmap after 12th: In Nepal, many students ask what to do after 12th. Start the basics now. Freshers and college students can follow the same plan beside classes.
- From a non-IT background: Bankers know risk. Teachers explain things well. Use what you already know. Help desk or GRC are friendly starting points.
- A self-taught plan: Study one or two hours on weekdays. Do labs on weekends. Keep notes of what you learn.
- Mistakes to avoid: Don’t jump into hacking tools before learning networks. Don’t collect certificates without labs. Don’t expect a job in three months.
How Long Does It Take to Learn Cybersecurity?
Every cybersecurity roadmap needs a clock. Here’s a simple one.
| Timeline | Goal | What you can do |
| 90 days | Fundamentals | Explain networks, use Linux, finish a beginner lab path |
| 6 months | Entry-level ready | Hold one certificate, finish many labs, apply for junior jobs |
| 12 months | Strong chances | Show three projects, one certificate, and interview skills |
- Can you learn cybersecurity in 90 days? You can learn the basics. You won’t be job-ready yet. Be careful with anyone who promises more.
- A realistic cybersecurity roadmap for 6 months: Months 1 and 2 are networks and Linux. Month 3 is security ideas. Months 4 and 5 are labs and certificate study. Month 6 is projects and applications.
- Weekly study time: Aim for 8 to 10 hours a week if you study part time.
How to Become Job-Ready in Cybersecurity
The last part of the cybersecurity roadmap is getting hired. This is where many people get stuck.


- A portfolio that gets interviews: Start a free blog or GitHub page. After each lab, write what you did and what you learned.
- Projects employers like: Build a home lab and draw it. Check a fake phishing email. Scan a practice network and write a report.
- Help desk to SOC analyst: Your first cybersecurity job may not say cybersecurity. Help desk teaches you users, tickets, and fixes. After a year or two, many people move to SOC analyst.
- Networking and community: Join Reddit groups, local tech meetups, and LinkedIn groups. Share what you build.
- Applying for jobs: Put your labs and certificates at the top of your resume. Apply to IT support, junior analyst, and internship roles.
AI in Cybersecurity: Will AI Replace Cybersecurity Jobs?
No. AI will take over boring, repeat tasks. People still make the hard calls. AI changes the cybersecurity roadmap a little, but it doesn’t erase it.
- How AI is changing roles: AI sorts alerts and scans code fast. Attackers also use AI to write better fake emails. So defenders need AI skills too.
- Jobs least likely to be automated: Incident responders, security architects, and GRC experts use judgment and talk to people. That’s hard for a machine.
- AI skills worth learning: Learn how AI tools work, how to keep data private, and basic Python.
Best Free Cybersecurity Resources in 2026
- roadmap.sh: A free visual map. Use it to check you haven’t skipped a topic. It shows topics, not weekly plans, so use it beside this one.
- GitHub roadmaps: Search GitHub for cybersecurity roadmaps. Pick ones updated in 2026. Old lists have old advice.
- Reddit: Try r/cybersecurity and r/netsec. People there are blunt. Search before you post.
- Free courses and platforms: TryHackMe free rooms, OverTheWire, Cisco Networking Academy, and freeCodeCamp videos on YouTube.
- A downloadable PDF: roadmap.sh offers a PDF of its cybersecurity map. You can also print this page and save it as a PDF in your browser.
Conclusion
You don’t need to learn everything at once. A good cybersecurity roadmap just needs you to take the next step. Then the next one.
- Key takeaways: Learn the basics first. Practice a lot. Earn certificates in order. Pick one path. Be patient, because real skill takes months.
- Your next steps: Choose a practice site this week. Set a weekly study time. Write down what you learn.
- First actions for beginners: Sign up for a free TryHackMe account. Learn five Linux commands today. Save this cybersecurity roadmap and tick off each phase.
If you want to build coding and IT basics first, LetsLearn teaches software and web development in Kathmandu. Those skills make security work easier later.
Most people mean the cyber kill chain. The stages are reconnaissance, weaponization, delivery, exploitation, installation, command and control, and actions on goals. It shows how an attack moves, so defenders can stop it early.
The layers are critical assets: data, endpoint, application, network, perimeter, and the human layer. Each layer protects the one inside it. If one fails, the next one helps.
Groups list them differently. A common list is network, cloud, endpoint, application, mobile, and IoT security, plus zero trust. Together, they cover where data lives.
One common version is to prepare, detect, analyze, contain, remove the threat, recover, and review. Some teams use six steps instead. The order stays the same.
These are support levels in a security team. L1 watches alerts and sorts them. L2 digs into real problems. L3 handles the hardest attacks.
Yes, but not at the start. Senior roles, such as architects and managers, can reach it, mostly in countries like the US. Entry-level jobs pay far less.
The CISO, or chief information security officer, is usually the highest-paid. Security architects also earn well. These jobs need years of experience.
Often, yes. It usually pays more than many other IT jobs. But pay changes by country, role, and experience. Check local job posts for real numbers.
No. Attacks keep growing, and companies keep hiring. Reports often say there are more jobs than trained people. Skilled people stay needed.
The best cybersecurity roadmap is simple. Learn networks and Linux. Learn security basics. Practice in labs. Earn one entry certificate. Then pick a path and build projects.






