📱

Get Our Mobile App

Take your business learning on the go!

Download on the App StoreGet it on Google Play

The Best and Worst Cyber Security Certificates 2025 (HUGE Update)

UnixGuy | Cyber Security39:46

Transcription

Cybersecurity certificates get a lot of attention, and for good reason. Earning the right certificate can lead to an interview, which can lead to a high-paying, long-term career in cybersecurity without needing an overpriced university degree.

So, I'll be covering the best and worst cybersecurity certificates based on whether they can actually get you hired. Now, the difference between recommendations on my channel and what you might see elsewhere is that the advice on this channel actually helps people land their first cybersecurity job. At this point, thousands have followed advice on this YouTube channel and managed to land their first cybersecurity job from across the world. In fact, I post success stories every single day.

Therefore, if you're serious about a career in cybersecurity, then you need to pay attention to this video. I'm going to rank cybersecurity certificates in a tier list from S for super to F for fail. At the end, I will crown one cybersecurity certificate as the best of the best and one as the worst of the worst. My criteria for ranking is simply whether a certificate can lead to a job or not. This can only happen if the certificate provides you with knowledge and skills that organizations are looking for.

We will also be listing the pros and cons of each certificate, but the true purpose of this video is that I want to teach you how to make informed decisions about cybersecurity training courses. However, I can't do that without taking you on a journey about the evolution of cybersecurity training courses and certificates. Therefore, I will divide the video into four parts.

Part one is old school. Those were the first certificates that were introduced in the field, like your CompTIA, CCNA, and CISSP. Part two is the second generation. This is when we started to see newer certificates like OSP. Part three is the new generation. These are certificates like the Google Cybersecurity Search, Let's Defend, Try Hack Me, Hack the Box, GC Mastery, Blue Team Level One, and others. Finally, part four is when I will reveal the best of the best and the worst of the worst of cybersecurity certificates, starting with the most popular and the oldest cybersecurity certificates, which is part one: old school.

We'll start with none other than your beloved CompTIA. I remember when I was starting my career 20 years ago and was interested in cybersecurity. People told me that I needed to learn Unix and networking, and I was learning from books and random online articles because that was the only thing available to me. Even back then, CompTIA was a thing, and I found out about CompTIA Security Plus, which was really exciting because it was kind of the only dedicated security training resource available to me at the time. We didn't have YouTube or online courses like we do today, so it was a different time.

Fast forward to today, Security Plus is definitely not the only beginner-friendly cybersecurity training; however, it still provides a good introduction to cybersecurity. Now, before we rank it, let's look at the pros and cons.

Now, the pros: the first one is that Security Plus is a good introduction to cybersecurity. Yes, it's not going to give you any practical skills that you will use on the job, but it will give you an important set of definitions and general information about cybersecurity. The second pro is that I've seen beginners land jobs using Security Plus. Now, please don't confuse that with me saying that Security Plus is what got them the job; that is not what I'm saying.

What I witness is that some individuals, when they start learning CompTIA Security Plus, get really into it, and they pass the exam. All of a sudden, they have the confidence to start applying to jobs, which naturally can lead to some interviews. Sometimes, all you need is just to show up to an interview and show that you're willing to learn. So, it's not the certificate that got them the job, but the fact that they had the confidence to study and apply to jobs.

Now, the third main pro is that if you're a U.S. citizen and you want to work in the Department of Defense or anything under the Department of Defense, then CompTIA Security Plus is a requirement by DOD. So, it's something that you need to pass if you want to work there. If you're not a U.S. citizen or you don't want to work in DOD, then this doesn't matter to you.

As for the cons, the first one is that the CompTIA Security Plus is a multiple-choice exam, which is not a great way to learn a subject. You'll end up needing to memorize a whole bunch of random things, and that doesn't really translate well to the day-to-day tasks of a cybersecurity professional. The second main con is the price. The CompTIA Security Plus exam alone will cost you $450 U.S. That is just an exam; you will probably need to pay the same for good quality training.

The final con, which is something I personally faced even 20 years ago, is that CompTIA materials are extremely boring in nature. When I started to study for CompTIA Security Plus, I was so excited to finally get to focus on security, but I got bored really quickly. I wanted to learn hacking; I wanted to learn practical things. Instead, I found myself memorizing the names of Ethernet cables. This is definitely not why most of us get into cybersecurity to begin with.

Now, other than that, honestly, CompTIA Security Plus is not a terrible starting point. You will get good knowledge once you pass the CompTIA Security Plus exam. Now, with all of that in mind and putting CompTIA Security Plus in context with all the new and better cybersecurity training that's available nowadays, I would rank Security Plus as a C.

Now, as far as other CompTIA certificates are concerned, they have certificates like A+, Network+, Security+, Linux+, Cloud+, and whatever plus. None of those certificates are good. Please don't waste time on them, and I say that as someone who's guilty of wasting time and money throughout the years on CompTIA certificates. In fact, I looked through my old email recently and found an email, I think in 2008, telling me that my CompTIA Storage Plus was about to expire. So trust me, this is coming from someone who has done a lot of CompTIA; they are not worth it.

Now, speaking of old training providers, the next one is one of the oldest training providers and one that I personally was obsessed with, which is Cisco. If you want to truly understand the cybersecurity industry, then you have to understand the impact that Cisco had on not only the industry but on certification programs in general.

You see, in the early 2000s, we did not have titles that were dedicated to cybersecurity. Instead, you either worked as a network engineer, where you were responsible for the network, or as a systems engineer or systems admin, which is basically managing the servers. That's what I used to do. Security was part of our job; that's how it evolved into what we refer to today as cybersecurity.

Now, if you were a network engineer, then Cisco was the king in terms of networking gear and certifications. It was simply not possible to be a network engineer without things like CCNA, CCNP, and to an extent, the legendary CCIE. However, fast forward to today, and I still see beginners confuse network engineering with cybersecurity. These are two separate disciplines.

Yes, a cybersecurity professional needs a certain level of understanding of networking for some specific disciplines, not all of cybersecurity. However, for some reason, to this day, people still recommend networking certificates for aspiring cybersecurity professionals. Unfortunately, some of those recommendations are coming from network engineers and company instructors who have never worked a day in their life in cybersecurity, yet they claim to know about the cybersecurity industry, which is absolutely ridiculous.

Now, with all that in mind, Cisco as an organization has evolved. They have cybersecurity products, not very good ones, and they have cybersecurity training and certifications. They have the Cisco Cyber Analyst certificate, and even recently, they have an ethical hacking course.

Looking at the pros of Cisco training and certifications, the main pro is that their new courses, like the Cisco Cybersecurity Analyst and their ethical hacking course, are completely free. So, you can do the training and learn as much as you like for free. If you're short on money, it could be a good start.

Now, as for the cons, those free training courses are actually low in quality. This, to me, is the major disadvantage of Cisco cybersecurity training. It's just long hours of low-quality training, unfortunately.

The second con of Cisco is that a lot of individuals are emotionally attached to Cisco. Therefore, if I criticize Cisco, so many people will simply attack me because they think with their feelings. I understand that. You see, Cisco is not just a company; it's someone's entire career. One of my close friends started his career in Cisco 15 years ago. He went and did his CCNA, CCNP, and CCIE, and he was one of the top architects in Cisco. Now he moved to another big company, but for him, Cisco was his entire career.

So, I understand that some individuals are irrationally emotionally attached to Cisco. Just be careful when you talk about Cisco because I've seen it happen in real time; people get offended, which is weird.

Now, as for the ranking of Cisco certificates, if you want to be a network engineer, then doing something like CCNA and CCNP are a no-brainer, and Cisco will be definitely S tier. However, if you want to work in cybersecurity, then those certificates aren't really necessary. But also, their cybersecurity training, as I alluded to earlier, is unfortunately low in quality. Yes, it's free, but you get what you pay for. Therefore, my rating for Cisco, when it comes to strictly cybersecurity, is a generous D.

Now, speaking of emotional attachment, the next training provider has a cult-like following, which is none other than (ISC)². CISSP used to be one of the most popular cybersecurity certificates. People who hold CISSP love to tell you all about it, and for a good reason, because they've spent so much time and effort to study and pass the CISSP exam.

Now, the CISSP started to get popular, I think, around 2006, maybe until 2012 it peaked. That's when it used to be the king of cybersecurity training. That's because, at the time, like I said, cybersecurity wasn't really a well-defined industry, if you will. So, (ISC)² as an organization tried to come up with a standard for what managing information security would look like, and the CISSP promised to be the training that would qualify you to be an information security manager.

They also had five years of requirements. So, if you want to become a CISSP, passing the exam alone wasn't enough; you also needed five years of experience. However, as I will explain later, those five years of experience are extremely questionable. The other reason for the popularity is that the CISSP exam used to be on paper, and it used to be long and hard. It's online now, and it's still challenging, but it used to be a lot harder when it first started. Therefore, it has managed to build a good reputation for that certificate.

Now, during that time, I think between 2008 and 2010, my career was taking off. I was a senior Unix security engineer, and I was traveling all over the world working on some serious Unix and security projects. But I was stuck in the mindset that if I had the skill, I needed a piece of paper to verify and validate that I had that skill. I was also young and insecure. Therefore, I stuck a piece of paper on my wall and wrote a list of certificates that I absolutely wanted to pass in order to prove myself.

I was extremely passionate about this field, and I wanted to learn everything. I also wanted people to love me. I ended up doing the majority of the certificates on that list; however, I didn't do CISSP. That's because, as I was getting promoted and I progressed to bigger roles, I noticed that the majority of senior leaders not only didn't have CISSP, but they also didn't care for it. Anytime I was bringing up certifications, I was either ignored or I got weird looks, so I decided not to pursue it any further.

Now, let's look at the pros of CISSP. The first one is that if you pass the CISSP exam, this proves that you're someone who studies really hard. It's not an easy exam to pass. Yes, I'm not a huge fan of the content of the exam, but it doesn't take away from your hard work and tenacity.

The second one is that the CISSP introduces you to a broad range of topics. Now, in the past, that was a novelty. It was one of the first certificates to talk about things like audit and risk management, so those topics were fairly new to technical individuals.

The third one is that companies used to love seeing CISSP on your resume. Now, this has changed a little bit in recent times, but generally speaking, people still have a positive outlook for the CISSP. The fourth one is not really related to CISSP, but (ISC)² has this beginner certificate called Certified in Cybersecurity, which we call (ISC)² CC. It's free to do, but I think you need to pay $50 to get the certificate. It's not great in terms of knowledge, but if you're short on money, then you can simply start there.

Now, as for the cons of the CISSP, the first one is that the CISSP was intended for the management of information security. As I said, the more senior I got in the past, and even in recent days, senior cybersecurity managers and senior leaders and CISO's simply don't have CISSP and don't care about it. In fact, the majority of them seem to have a negative view of the CISSP, even the ones who hold it. I'm just the messenger here, but what I'm trying to say is that it's not the ultimate cybersecurity management training that it was intended for.

This brings me to the second con, which is that the content of the CISSP and the CISSP exams don't really reflect the real world. I know they try, and I know they have committees. In fact, one of my friends is part of that committee, and they meet up and try to make the exam more real-world-like. Unfortunately, it's extremely difficult to mimic cybersecurity problems into a multiple-choice exam, especially the way they word their questions. They try to trick you with grammar, which, in my opinion, is a bit silly.

Now, again, this doesn't take away from you if you studied hard and passed the exam. I'm simply speaking about the exam for someone who's thinking about doing it. Now, the third con is that the CISSP is a multiple-choice exam, and this applies to CompTIA and the rest. People worldwide cheat to pass the exam. Unfortunately, the questions and answers are out there on the internet, and therefore organizations and professionals lost confidence in these exams because a lot of bad actors cheat and ruin it for everyone else.

Now, if you're someone who likes to challenge yourself and do certifications, by all means, go for it. Just be aware that the reputation of those certificates has gone backwards because of some bad actors. The other con is that the five years of experience is not really strict. I've seen people who faked that experience, and some individuals have put really strange things into that experience, and somehow they managed to qualify for that requirement. Therefore, that five years of experience is highly questionable.

The final con of the CISSP is that a lot of individuals who have it, especially beginners, become extremely arrogant. Trust me, individuals with the biggest egos in the cybersecurity industry are usually beginners who tell me they have a bachelor of cybersecurity, CompTIA Security Plus, and CISSP. Now, I have sympathy for them because once upon a time, I was young, naive, and had a big ego.

Now, if you take one thing from this video, based on my experience, I've never ever met an expert who had a big ego. Only idiots have big egos, and I know that because I was a massive idiot with a big ego. So please learn from my mistakes; a certificate alone will never make you an expert.

Now, with all that in mind, if we want to rank the CISSP, my honest ranking is an extremely generous B. Now, this is strictly for CISSP. If I look at other (ISC)² certificates like CC and their Cloud Security CSP and their other random nonsense architecture certificates, those are all tier F. They are absolutely terrible; they teach you nothing, and they are an absolute waste of time and money.

Speaking of certificates that overpromise and underdeliver, the next certificate takes that crown from the certificate that promised the most and delivered nothing, yet people still pay and do it. It's EC-Council Certified Ethical Hacker. You have no idea how excited I was when I heard the word Certified Ethical Hacker. I lost my mind. Are you telling me that you can be a qualified hacker and you can learn and get tested on hacking? This was an extremely novel idea back in the day.

This is like telling a kid that they can be a superhero, except I was the kid. I was in my 20s, and I really wanted to be a hero. But as you may have guessed, I was so, so disappointed looking at EC-Council. The pros are that somehow they got themselves to be a requirement for DOD through nothing but politics. So again, if you're American and you want to work in DOD, then you probably need to do it.

Now, as for the cons, the certificate itself doesn't teach you any hacking, so the name itself is a false promise. It's a multiple-choice exam that will get you memorizing a random bunch of things that have nothing to do with hacking. The second con is that the training and the certificate are way overpriced.

You know what's funny? On a weekly basis, someone will join my Discord server and tell me that they have a special discount from EC-Council and ask whether it's worth it to do. Well, spoiler alert: everyone gets that special discount. It's just a scammy way to trick you into buying this low-quality, useless training.

The final con is that EC-Council has other certificates like their forensic investigator and other pentesting certs. Unfortunately, they're all equally bad. Don't bother with them. With all that in mind, the rating is an obvious and solid F.

Speaking of theoretical certificates that teach you nothing, the next provider was, in fact, the first one to try to attempt to teach GRC, except we didn't really call it GRC; it was simply IT audits and risk. That provider is ISACA. They have three popular certificates, which are CISA, CRISC, and CISM. People who work in GRC in the real world, not on YouTube, will be more than familiar with them.

Looking at the pros, the main pros are that, like I said, they were the first ones targeted and specific to audit. So, CISA was traditionally listed for auditing jobs, and CRISC and CISM are still listed for risk management jobs and even information security management jobs. The second advantage is that, like I said, if you work in GRC and you've got the knowledge and you're bored, then you can entertain yourself by studying and doing ISACA exams.

I personally had to do CRISC and CISM as part of my job in PWC because we had a government contract, and they wanted consultants who had those certificates. I actually didn't even bother studying; I just walked in and did the exams, and I passed them. I don't recommend that because I found the exams to be really stupid, and again, they did not reflect the real world. However, there was some important knowledge in it that, if you have absolutely zero knowledge in audit or risk, then they can give you something. It's not the best, but it was something, especially back in the day.

This brings me to the cons. As you may have guessed, multiple-choice exams are not a great way to learn a subject, but especially with ISACA, a lot of the questions are worded in a very weird way that, frankly speaking, got me to question the person who wrote these questions. I know it's not one person; I know it's a committee, and I know they're trying their best. However, if you actually want to learn GRC, and contrary to what a legit GRC expert tells you online, you don't need to do all of these random GRC stuff. Instead, you need to learn GRC once, and then you need to work on your knowledge of regulations, business requirements, and yes, you need to have some technical understanding as well.

As for the second con, in my opinion, it's the price. ISACA has a requirement where you need to pay an annual fee to renew your status as a certified ISACA professional. I think CISSP has it, and a lot of certifications have it. I think this is a scam, and it's nothing but a money grab. In fact, I decided to stop paying for ISACA a few years ago, and lo and behold, they revoked my certificates. Guess what happened? I watched the knowledge leave my body as they revoked the certificates.

Now, with all that in mind, just like the CISSP, if you've worked hard to get your ISACA certificates, then I'm not taking away anything from your hard work. In fact, you have nothing but my respect and appreciation. However, if I was to be partial and rate ISACA certificates, then my honest rating is a very generous D.

Now, with all this talk about low-quality training, what if I told you that even back then, there was a legendary cybersecurity training provider that had extremely great quality cybersecurity training and rockstar cybersecurity instructors? They still do to this day. It's the SANS Institute and, by association, their GIAC certificates. SANS training is usually five days long, where you get lectures and books, and then you have, I think, four months to study and pass a GIAC exam.

Now, back then, when SANS started, they had rock stars in the information security community that were teaching these courses, and the quality was insanely high. In fact, they were the first ones to have proper blue teaming, incident response, and digital forensics training courses. They were setting the standards for so many things that we do today in the cybersecurity world. I still use the SANS methodology for incident response, for example.

The GIAC certificates that you get after passing the exam are also highly respected because the value was never the certificate, but the fact that in order to get the certificate, you needed to do high-quality SANS training. So, there was some sort of guarantee that you at least attended good quality training, which is a very smart idea.

Now, as for the pros, I've already mentioned them. The material is top-notch. They were the first ones to curate nice material that was really applicable to the world, so much so that, as I said, they became the standard for so many processes that we still use in cybersecurity today. Whether you're aware of it or not, a lot of the things that you do as a cybersecurity professional came from SANS and SANS instructors.

However, there are some major cons with the SANS Institute. The first one being the price. The training courses used to cost $5,000 for the five-day training course, but that was in the past. Today, I think they are $6,500 U.S., which is really overpriced and simply not affordable for so many people.

Now, for context, back in the day, we all had to save up and invest in SANS training because it was simply the only way available to us to learn things like incident response, digital forensics, and some niche penetration testing topics. But today, you guys are spoiled for choice.

Now, the second major con with SANS is that a lot of the great instructors have left, and their current process of hiring instructors is pretty bad. In fact, I personally have had bad experiences with them, but I'm not going to go through that because it's not really important for this video.

This brings me to the rating. Honestly, SANS has always been traditionally an S-tier cybersecurity provider, and it makes me sad to see them regress in recent years. I say that as someone who has four GIAC certificates. I'm going to put them on the screen, but unfortunately, as I said, there are equally good, if not better, cybersecurity courses nowadays that you can do for a fraction of the cost. Not only that, but the decline in the quality of SANS instructors is really concerning.

Therefore, with all of that in mind, SANS is not going to be S-tier; instead, they're going to be rated as tier A.

Now, as far as improvement, the cybersecurity industry was set to undergo massive improvements. We started to see this happen with the introduction of new cybersecurity training providers, which brings me to the second part of this video: part two, second generation.

But before we get to that, I want to thank the sponsor of this video, NordPass Business. Now, did you know that the average number of passwords used for business-related accounts is 87? This is absolutely insane and unmanageable. However, you can manage it with NordPass Business, which is an intuitive password manager for businesses and individuals.

Not only that, but a huge cybersecurity risk is usually offboarding users after they leave a business. Research has shown that one in four employees can still access their business accounts long after they left a company, which is a huge security risk. However, with NordPass Business, you can manage user access efficiently with a streamlined onboarding and offboarding process that can help you easily manage user credentials. This also gives you the chance to track your corporate data under a single pane of glass.

Research has also shown that, on average, it takes a business 121 days to identify a data breach, which is insane. However, with the data breach notification feature with NordPass, you can easily change passwords that were compromised before any damage is done. But best of all, you can get three months free to try NordPass, and they've given us an exclusive deal of a 20% discount, which is crazy. To access it, go to nordpass.com/UnixGuy and use the activation code UnixGuy. It's a limited-time offer only.

Now, back to the video, starting with the first provider of the next generation, which is Offensive Security with their famous OSCP. Offensive Security started as penetration testing with BackTrack Linux, which evolved to what you guys know today as Kali Linux and the OSCP.

Now, OSCP is not a generic cybersecurity certificate; it's focused training and certification for penetration testing, which is just one aspect of cybersecurity. However, what Offensive Security did is that they brought hands-on live exam environments where you get tested on your practical skills. This was not new to the IT world, but it was relatively new to the cybersecurity world. In the IT world, we had exams like Cisco CCIE, but we also had exams like Red Hat Certified Engineer, which I've passed a long time ago. Just saying the name brought back so many memories, but that's a topic for another video.

Now, as for the pros of the OSCP, like I said, it's practical hands-on training, which means you cannot pass without demonstrating efficiency in the practical skills that look a lot like what we do in the real world. This was a huge leap from things like CompTIA and CISSP. The second con is that the price is a lot cheaper than SANS training because SANS training was the only provider that had good quality penetration testing training. So, OSCP was definitely a game changer.

Now, I know there are cheaper options today; however, I still think the price of OSCP is relatively reasonable. As for the cons of OSCP, the biggest one, in my opinion, is that the training course is not properly structured. They have the mantra that says "try harder," which on the surface sounds reasonable. As hackers and cybersecurity professionals, we want to try harder. However, in this context of the training, I think it's just an excuse for their lazy training.

A training course should provide you with all the information that you need to learn a subject and pass an exam. You don't do a training course to spend hours upon hours Googling random nonsense; this defeats the purpose. The second con of OSCP is that Offensive Security, as an organization, was recently acquired by a private equity firm, so did your beloved CompTIA, by the way.

So, they started to introduce things like OSCP+, and they've raised their prices. They also introduced a whole bunch of random nonsense training that honestly doesn't make any sense. I think they should just stick to their OSCP because that's what they're good at.

Now, with all that in mind, the OSCP, in my books, is still a solid S-tier certificate. It gives you exactly what's promised, and it does it in a really good way. However, as of today, there are much, much better high-quality penetration testing courses that do what the OSCP is promising, and they deliver it in a much better way. Therefore, I'm going to move the OSCP from S-tier to A-tier.

Now, as the cybersecurity industry continued to evolve, something really exciting happened. Another organization followed the footsteps of Offensive Security and started another practical hands-on training organization. It used to be called eLearnSecurity, but most of you will know them as INE. I remember when they first started; the name was Armando. He was from Italy and used to go to internet forums and talk about his certificates. I think I was among the first people to try so many of their courses. They were later acquired by another company, and now they are called INE. Their popular certificates are eJPT and eCPP on the penetration testing side, but they also have fantastic incident response and digital forensics courses alongside so many other specialized cybersecurity courses.

As for the pros, they are practical hands-on training that mimics the real world, and the training courses are well-structured. They give you everything you need to pass the exams, unlike Offensive Security. The other advantage is that they are reasonably priced.

As for the cons, honestly, I can't think of any. I think they are a solid, solid training provider. Therefore, as you may have guessed, my rating of INE is a solid S tier. You simply can't go wrong with INE.

Now, before we continue and move on to the newer cybersecurity training and certificates, there are two extremely important training providers that you simply cannot escape if you want to work in cybersecurity, which are Microsoft Azure Cloud and Amazon AWS Cloud. They are literally everywhere. If someone tells you that AWS is better than Azure or Azure is better than AWS, just don't listen to any word that comes out of their mouth because they don't know what they're talking about.

Every environment will have some sort of a Microsoft and Amazon AWS presence. But not only that, once you learn one platform, the other one becomes so easy to learn because they're both extremely similar. Now, here I'm talking strictly about their cloud security certificates, which are Amazon AWS Security Specialty and Microsoft Azure Security Engineer Associate. This also includes their other cloud certifications because they're all relevant to you as a cybersecurity professional.

As for the pros, both AWS and Azure are extremely relevant to the market. Like I said, if you work in cybersecurity, you have to be familiar with these cloud platforms. The second pro is that there is so much training out there that can teach you Microsoft Azure and Amazon AWS. Yes, I'm aware some of it is not high quality, but still, it's available, and it gets the job done.

As for the cons, I find that their exams are again multiple choice, which I'm not a fan of. However, at least the things you are tested on are relevant to the day-to-day tasks of a cybersecurity professional. Therefore, my honest rating of Amazon AWS and Microsoft Azure, when it comes strictly to cybersecurity, is tier A. They are extremely important for you if you want to work in cybersecurity.

Now, before we jump to part three, which is the new generation of cybersecurity training, there is one final training provider that deserves an honorable mention because they've been around for a very long time, and that is Udemy. Now, I wish I had positive things to say about Udemy, but when it comes to cybersecurity, I'm just not a fan.

With Udemy, the only attraction is that they are extremely cheap, but as you may have guessed, you get what you pay for. In my 20 years of experience, I haven't met a single individual who spent their time learning from Udemy and got anywhere. What ends up happening is that people think they're saving money, and they spend it on all these cheap Udemy classes that are filled with fluff and long hours of nonsense. As a result, they never finish them, and they never learn anything.

So, as you can see, as for the pros for Udemy, they have one pro, which is that they're probably the cheapest training provider out there. However, the cons of Udemy are that you get what you pay for, which is extremely low-quality cybersecurity training. Therefore, my honest rating of Udemy is a well-deserved F tier when it comes to cybersecurity.

This brings me to the most exciting part of this video, which is part three: the new generation. If you're watching this video and you want to start a career in cybersecurity and you don't have a degree, then this is the single best time in history to embark on this journey. There is an abundance of high-quality training courses that are reasonably priced that can get you from zero all the way to landing your cybersecurity job, which is a huge novelty.

You cannot appreciate that unless you've been through what I've been through in the past. The hacker community was not really friendly; they used to make fun of you, they used to be really aggressive, and they just didn't like helping. However, today, the information is simply out there.

Now, the training providers that I want to rate, in no particular order for blue teaming or SOC, we have Let's Defend, Cyber Defenders, Try Hack Me, Hack the Box, and Blue Team Level One and Level Two. For offensive security, we have, again, Hack the Box and Try Hack Me, but we also have TCM Security and Zero Point Security. For GRC, we have GRC Mastery, and for a basic broad introduction to cybersecurity, we have the Google Cybersecurity SE.

Now, I know what some of you might be thinking, which is, "Which one is the best? Which one should I choose?" I'll get to that in a bit, but first, the pros of all these courses combined are, number one, they are all fully practical and hands-on training, which means they give you skills that we use on the job. This is crucial because this will give you the confidence to apply to cybersecurity jobs, and when you get to an interview, you'll actually be able to answer the questions that you'll be asked, which is what eventually leads you to a cybersecurity job.

The second pro is that they are all reasonably priced. I'm comparing them with your CompTIA, SANS, and CISSP. I think these courses are more than reasonably priced, something that, again, a lot of you don't appreciate because you haven't seen where we came from.

As for the cons, honestly, the main con is that individuals seem to get confused about which platform is the best. In my opinion, they are all great. Pick one platform and run with it to the end. The single biggest mistake that I see when it comes to this platform is that someone will pick something like Hack the Box, for example, and they will do all the free Capture the Flag challenges, and they never manage to do all of their intermediate and advanced level training and certifications.

This is where the real value is at; it's not on those Capture the Flag and free challenges. So, make sure that whatever you pick, do it to the end and get to their intermediate and advanced level certifications and courses. The second con is GRC-related. There is this myth online that to learn GRC, you need so many hours and hours of training. GRC itself is not rocket science.

Once you get the knowledge of GRC, which you can get in GRC Mastery, you need to move on and improve your technical knowledge. Even if you only want to work in GRC, having technical knowledge will make you a much better GRC professional. Chasing those random classes and random frameworks is not how you learn GRC. Once you do GRC Mastery, you're meant to move to hands-on practice tactical training like the ones I mentioned earlier.

Now, if you're looking for a deep dive into these individual courses, I talk about them in so many of my videos. I highly recommend you start with this one and work your way to the rest of the videos.

Now, as for the ranking, I'm not going to rank them individually; instead, I will rank them as a group as a solid S tier. These are simply how cybersecurity training is supposed to be. You simply can't go wrong with these courses.

This brings me to the big reveal: part four, the best and the worst cybersecurity certificates. Now, there is no shortage of bad cybersecurity training, and I could go on and on for hours about it. However, there is a certain group of cybersecurity training that more than deserves to be the worst of the worst. They are not new, unfortunately, and they are still thriving to this day, and these are collectively called cybersecurity boot camps.

I'm not going to name a boot camp individually because they are all absolute garbage. If you look at the pros of cybersecurity boot camps, then unfortunately, there is no advantage to paying thousands and thousands of dollars to learn watered-down, pointless CompTIA training that you can do by yourself for a couple of hundred.

As for the cons, there are so many. The first thing is they promise you that you will get a job at the end of it. This is simply not true. No one can promise you a job at the end of any training course; that's not how the process works. The second con is that they charge thousands and thousands of dollars. In fact, some of them charge upwards of $20,000, which is an absolute scam.

The third one is they use scammy techniques to get you to purchase their boot camp. They'll get you to go on a free webinar, and on that webinar, they'll have fake people signing up for that boot camp. At the end of it, they will pressure you and tell you that there is a special discount that you can only access if you purchase in the next five minutes. This is a scam. No reputable organization will ever do that.

They also have salespeople that call you and follow up with you to pressure you to buy. Again, none of the reputable organizations that I mentioned earlier in this video engage in this shady behavior. Another con is that they always seem to have some kind of a special discount going on. Again, this is just designed to make you feel that you're saving money when, in fact, you're just wasting money on a scam.

Finally, even universities now have their own boot camps, which are equally bad and equally overpriced. If a boot camp is run out of a university, it is still crap, and I never recommend them. Now, as for rating collectively, they will be crowned the worst of the worst.

Now, I'm not going to put names of boot camps; instead, I'm going to use this picture of me because people have a bad habit of screenshotting my tier list and posting it randomly on LinkedIn without any context. So, this will hopefully prevent them from doing so.

Now, as for the best of the best of cybersecurity certificates, if I was to pick one to be crowned the absolute best cybersecurity certificate, which one is it going to be? Are you ready? Well, unfortunately, I cannot pick one. There is no single best cybersecurity certificate. Instead, all of the certificates that I mentioned in the new generational certificates are collectively the best of the best.

The idea is for you to do one or more of these certificates so you can grow your skills, do well in interviews, and not only land your first cybersecurity job but progress later to more senior roles. Now, the single biggest mistake that I see with tier lists videos is that people treat it like a roadmap. This is not a roadmap video.

If you want a progressive roadmap where I create a list of courses that you can do progressively that will lead you to a cybersecurity job, then this is the video that I recommend you watch. But you need to watch it until the end and actually do what I recommend there. Check it out, and I'll see you there.