📱

Get Our Mobile App

Take your business learning on the go!

Download on the App StoreGet it on Google Play

The Only Cybersecurity Roadmap You Need for 2026

Tech with Jono7:48

Transcription

I've been seeing so many people asking about getting to cyber security lately. And the same questions keep coming up over and over again. Where do I even start? What certifications actually matter? And I get why people are confused because the advice online is kind of all over the place.

The good news is you don't really need a technical background like a computer science degree. But I'm also not going to sit here and tell you that you could do this all in 3 months with just one boot camp because that's not realistic either. So in this video I want to break things down properly. what cyber security actually is, what skills you really need, which certifications are worth your time, and some of the stereotypes that honestly stop people from even trying.

So, without further ado, if you're new here, my name is Jonno, and I work in cyber security. Let's start right at the beginning because this is where a lot of the confusions come from. When most people hear the word cyber security, they picture someone sitting in a dark room, typing really fast, and doing some stereotypical hacking stuff. And sure, that is kind of a thing. It's something called penetration testing, but realistically that's a pretty small part of the industry.

Cyber security is actually a huge umbrella. You've got people who spend a day looking at logs and alerts, trying to spot suspicious activity, responding to incidents when something actually goes wrong. And you've got people designing secure systems and networks. Some are working on policies and compliance and regulations, and others whose main job is training employees not to click on fishing emails. So, it's way more diverse than people think, and that's actually a good thing. It means there's probably a role that lines up with what you're good at, whether you're technical, analytical, good at communications, or somewhere in between.

Now, let's talk about the job market for a second. Yes, there are tons of open roles, but here's the annoying part that no one really likes to talk about. A lot of them still ask for experience. You see things like entry-level role with 3 to 5 years of experience required, which makes no sense at all. But nowadays, companies are slowly being forced to get more realistic. They need more people and more and more organizations are willing to train someone who has a clear, strong fundamentals and shows effort and clearly takes it seriously. Your goal is to show that you're that person.

All right, let's talk about the skills and I'm going to be straight with you here. First up, networking. You cannot skip this. There's no way around it. That means learning things like TCP, UDP, IP addresses, the OSI model, common ports and protocols, DNS, firewalls, routers, switches, all that foundational stuff. Is it the most exciting thing in the world? Not always, but you really need to understand the basics.

And then there's the operating systems. You need to be comfortable with both the Windows and Linux. Most corporate environments run on Windows, but Linux is everywhere in the security tools. You don't need to be an expert at command line, but you should be comfortable navigating, checking logs, managing users, and understanding what processes are doing. It's also really beneficial for you to pick up some scripting or programming as well. Python is usually the best place to start as I always recommend it. You don't need to build apps or become a software engineer. You just need to understand code well enough to read it, write some small scripts, automate some tasks, and understand what an exploit or malicious script is doing.

Now onto the security specific side of things. This is where it starts to get a bit more interesting. You'll learn how attackers actually operate. Things like fishing, malware, common vulnerabilities, social engineering, and a lot of these comes down to mindset. You start getting into the habit of asking, okay, how could this be abused? What could go wrong here? And that's what people mean when they talk about a security mindset. And one more thing that doesn't get talked about enough, communication. Being able to explain a technical issue to a non-technical person is huge. writing clear incident reports, presenting findings, talking to management. These skills matter a lot more than people realize.

All right, let's talk about certifications because this is where a lot of people get overwhelmed. There are a lot of SS out there and it's hard to know what's actually worth doing. At the entry level, contest security plus is kind of the standard here. It covers a broad range of topics and a lot of employers recognize it, especially in government and larger organizations. It's not really trivial, but it's very achievable if you study consistently. If you're completely new to IT, doing comt A+ then network plus before security plus isn't a bad idea either. It really helps with those fundamentals that you really need. There's also the ISC2 certified in cyber security which is newer and free. It's a good way to dip your toes in and see if this field is actually right for you.

Now, you hear a lot of people say things like certifications don't matter. Experience is everything when you're trying to break into this industry. Certifications does help. They show commitment. They show baseline knowledge and they help you get your resume past those automated filters. But are they enough just on their own? No. But they're useful. Once you have some direction, then you can look at more specialized certificates like offensive, defensive, cloud security, whatever path you choose. Just don't rush into those too early.

Once you've got the certifications down, you really need to complement those with some practical hands-on exercises. This can be as simple as coming up with your own scenarios like how to handle fishing emails, how to handle unauthorized login, or how to handle a computer that has a virus on it. The key is to be able to explain your thought process like what happened, what steps you took, and how you would prevent it from happening again.

All right, let's clear out some stereotypes because these stop a lot of people before they even start. You don't need to be good at math. Most cyber security work is practical, not theoretical. And you also don't need to be young. People break into cyber security in their 30s, 40s, or even later. If you're changing from another career, often times you will also bring valuable indirect skills over like effective communication, for example. You don't need to know your way around everything on day one or even the first month. Nobody really does anyway. The people who succeed are the ones who keep going when things don't make sense immediately.

I also want to bring up Googling skills. Believe it or not, being able to do your own research and find your own answer is very valuable in this industry. You're not expected to know everything, but at the very least, you need to be good at finding out the answer. If you don't know what a particular logan means, Google it. Heck, you can even chat GPT it. We do it all the time as well. Just don't be that guy that keeps asking someone on every single thing that can be easily found on Google.

Now, let's talk about your realistic timeline. First, you'll spend a couple of months building foundations, networking, operating systems, basic security concepts. This part is going to feel slow, but it's unavoidable. At the same time, you should be getting hands-on. Capture the flags, labs, home projects. This is where things start to click. Then, you're going to naturally gravitate towards a path, defensive, offensive, cloud security, GRC, and you go deeper from there.

When you're job hunting, it takes time. You should be expecting to get rejected a lot. That's normal for everyone. on when they first start anyway. So, just keep applying. Focus on entry- level roles if you can and just keep improving bit by bit. I think if you're starting from zero, best to give yourself 6 to 12 months of consistent effort. Lending a job might take a bit longer, but that's okay because cyber security is not a beginner role in the first place.

I'll finish with this because it's going to matter more than anything else. You're going to feel lost sometimes. You're going to feel dumb. You're going to feel like you're stuck. And if you just got a job, you're also going to feel a bit of imposter syndrome. That's not a sign you're bad at this. It's a sign you're just learning. Just stay curious. Don't just study to pass exams. Try to understand why things work the way they do. And try not to do this alone. Join online groups. Ask questions. Help others when you can. It makes a huge difference. And this isn't a shortcut career. If you're willing to put in a se effort, cyber security is absolutely still a good job to have in this day and age and it'll earn you some good money.

So yeah, that's the road map. Is it going to be easy? Not really. Is it possible? Absolutely. If this video helped you, then feel free to drop a comment down below to show your support.