A cyber security learning roadmap from scratch for beginners starts with mastering networking and operating systems, moves into Linux and core security concepts, builds a legal home lab, practices blue team skills with log analysis and SIEM, earns the Security+ certificate, then assembles a portfolio. These seven stages take roughly nine to twelve months with regular practice and always rest on lawful defensive work.
- Networking and Linux come first, because security is built on understanding how systems work
- Each stage leaves one tangible result, from lab notes to writeups, as portfolio material
- All practice happens in your own environment or on official platforms, always within the law
- A laptop with at least 8 GB of RAM to run one or two virtual machines at once
- A stable internet connection to access materials, documentation, and online practice platforms
- A quiet study space with a fixed schedule, at least eight to ten hours spread across the week
- A notebook or digital document to record commands, findings, and concept summaries
Why Cyber Security Skills Are Worth Learning Right Now
Understand First What You Are Actually Learning
Many beginners imagine cyber security as a scene of breaking into systems on a dark screen. In reality, most work in this field revolves around defense: keeping data confidential, intact, and available. Those three properties are known as the CIA triad, meaning confidentiality, integrity, and availability, and they guide almost every security decision. Healthy cyber security always rests on permission and law. Practicing attack techniques is only lawful in an environment you own or on platforms built for learning. The roadmap below emphasizes the blue team path, the defensive side that detects, analyzes, and responds to threats. This path opens the most entry-level roles and builds a solid base before you decide on any other specialty. To begin, you need curiosity, care in reading detail, and the discipline to practice in a safe lab.
Seven Stages of Learning Cyber Security From Scratch
Follow them in order. Each stage builds on the one before it, and each leaves behind one tangible result that later fills your portfolio.
- 1
Stage 1: Master Computer Networking Basics
Security stands on understanding how data moves. Start with networking fundamentals: the TCP/IP model, IP addresses, subnets, ports, and common protocols such as HTTP, HTTPS, DNS, and SSH. Understand the journey of a packet from your device to the destination server, because nearly every attack and every defense touches that path. The most grounded exercise here is installing Wireshark and watching the traffic while you open a website. Seeing the DNS request and the TCP handshake directly turns theory into something real. Set aside about a month so the map of networking in your head is clear enough before moving on.
Tips- Draw your own diagram of a packet's journey, this activity forces you to close gaps in understanding
- Memorize common ports and their functions, this knowledge keeps returning in the detection stage
- 2
Stage 2: Build a Foundation in Linux and the Command Line
Most servers and security tools run on Linux, so fluency in the terminal becomes an essential skill. Install a distribution such as Ubuntu in a virtual machine, then get comfortable navigating files, setting permissions, installing packages, and reading system logs. Understand the directory structure, users and groups, and how file permissions work, because many incidents start with a wrong permission. Write simple bash scripts to automate repetitive tasks, for example filtering certain lines from a log. This skill of reading and processing logs later becomes the daily bread of a defensive analyst.
Tips- Practice grep, awk, and tail until fluent, all three become your mainstays when examining logs
- Do every exercise inside a virtual machine so mistakes stay isolated from your main computer
Skipping Linux and jumping straight to ready-made tools leaves you dependent on buttons, without understanding what actually happens behind the scenes. - 3
Stage 3: Understand Core Security Concepts
Once networking and Linux feel familiar, step into the security mindset. Learn the CIA triad as your compass, then get to know the concepts of authentication, authorization, and encryption. Understand the basics of cryptography conceptually: the difference between symmetric and asymmetric encryption, hash functions, and the role of digital certificates in securing HTTPS. Recognize common threats such as phishing, malware, and misconfiguration, along with the principle of defense in depth. At this stage the focus lies in building a concept map that gives meaning to every exercise ahead, with a lighter share of hands-on work. Reading like the NIST framework and the OWASP Top 10 helps you recognize the risk patterns that appear most often.
Tips- Summarize each concept in your own words, this tests whether your understanding is truly correct
- Tie each concept to a real example from incident news, so the theory comes alive
- 4
Stage 4: Set Up a Safe and Legal Home Lab
Theory turns into skill only through practice, and security practice must happen in an environment you fully control. Build a home lab using VirtualBox: one attacker machine such as Kali Linux, and one or two target machines set up specifically for practice. Lock everything into an internal network separated from the internet and from other devices at home, so there is no risk of touching systems owned by others. Here you practice scanning a network, reading the results, and understanding how a weakness works, with the goal of learning to defend. If you want guided practice, TryHackMe offers beginner paths in an official environment that is safe to explore.
Tips- Use host-only or internal network mode so the lab is truly isolated from the outside
- Take a snapshot of the virtual machine before each experiment, so returning to a clean state is easy
Testing techniques on systems, websites, or networks owned by others without written permission is against the law. All practice is only lawful in your own lab or on platforms built for that purpose. - 5
Stage 5: Practice Blue Team Skills
This is the heart of a defensive career. The blue team monitors, detects, and responds to suspicious activity. Install a lightweight SIEM such as Wazuh or Security Onion in your lab, then feed logs from your practice machines into it. Learn to read authentication logs, recognize odd login patterns, and write simple detection rules. Get to know the MITRE ATT&CK framework as a dictionary of attacker tactics and techniques, so you can map each event to known behavior. Also practice a concise incident response flow: identify, contain, recover, then learn. The skill of connecting log fragments into a complete incident story is the selling point of a security analyst.
Tips- Create suspicious activity in the lab yourself then trace it in the logs, this trains the analyst's eye
- Document each finding as if writing a report for a colleague, this habit is valued in the workplace
- 6
Stage 6: Pursue a Foundation Certification
A certificate gives an organized study framework along with a signal of credibility to recruiters. For beginners, CompTIA Security+ is a widely recognized starting point, covering security concepts, networking, and risk governance in one balanced package. Before it, Network+ helps if your networking foundation still wobbles. Study from the official syllabus, work through practice questions, and tie each topic to hands-on work in the lab so the material settles. For those drawn to the analyst path, blue-team-oriented certificates such as the defensive security series are also worth a look after Security+. Keep in mind that a certificate becomes strong evidence when it stands on real skill, so chase the paper together with the practice that supports it.
Tips- Schedule the exam date early, a clear deadline keeps your study rhythm consistent
- Tie each syllabus chapter to one lab exercise, practiced theory sticks far better
- 7
Stage 7: Build a Portfolio and a Public Track Record
The final stage turns that long process into evidence a recruiter can see. Write writeups from challenges you solved on TryHackMe or from experiments in your home lab: explain the problem, your analysis steps, and the lessons learned, while keeping a learning and ethical frame. Store your lab scripts and configurations on GitHub so they look tidy and traceable. Summarize your skills in a concise profile, then join security communities to share and ask questions. One deep writeup that shows how you think leaves a stronger impression than a pile of certificates without a story. This public track record is what makes a beginner's application start getting noticed.
Tips- Write the writeup right after finishing a challenge, while your memory of the steps is still fresh
- Keep the tone educational and ethical, avoid any impression of showing off how to break systems
Time Estimate for Each Phase for Beginners
Technical Foundation
Mastering networking basics, Linux, and the command line until fluent in the terminal. Roughly two to three months of regular practice.
Concepts & Home Lab
Understanding core security concepts then setting up an isolated lab for safe and legal practice. About three to four months.
Blue Team, Cert & Portfolio
Practicing detection with SIEM, pursuing Security+, then assembling writeups and a public track record. Roughly four to five months.
Three Cyber Security Career Paths and How They Differ
| Path | Work Focus | Suits Beginners Who Are |
|---|---|---|
| Blue Team (Defense) | Monitoring, detecting, and responding to threats through logs and SIEM | Careful, patient with detail, and enjoy piecing fragments into a story |
| GRC (Governance & Risk) | Drafting policy, compliance audits, and risk assessment | Strong in documentation, communication, and systematic thinking about rules |
| Red Team (Ethical Testing) | Testing system resilience under official permission to strengthen defenses | Already grounded in technical basics and committed to ethics and written permission |
Many beginners start with the blue team because it opens the most entry-level roles, then choose a specialty once the foundation is solid.
“The beginners who earn trust fastest are the ones who show ethical discipline from their very first lab. Technical skill can be sharpened, while respecting boundaries and permission is the foundation that opens a career.”
Checklist Before Calling Yourself Ready to Apply
- You understand a packet's journey and can read network traffic with Wireshark
- You work fluently in the Linux terminal and filter logs with grep, awk, and tail
- You have an isolated home lab and have practiced detection with a SIEM inside it
- You hold or are ready to pursue a foundation certificate such as CompTIA Security+
- You have written at least one deep writeup that tells how you analyzed a case
How Much Learning Cyber Security at EduPoint Costs
The guided learning path stays affordable. Cyber security tutoring at EduPoint starts from Rp 120,000 per session for online lessons, and from Rp 150,000 per session for in-person lessons. A small group of two to three students is also available starting from Rp 100,000 per student. The final price adjusts to your learning goal, location, and lesson format. For beginners who want to follow the roadmap above with guidance, a mentor helps you arrange the learning order, accompanies you while setting up the home lab, and reviews your analysis stage by stage. The emphasis adjusts to your starting point, so your study time goes toward what you need most on the way to your first role in security.
- The cyber security roadmap runs from networking, Linux, security concepts, a home lab, blue team, a certificate, then a portfolio
- Networking and Linux come first because security is built on understanding how systems work
- The blue team path opens the most entry-level roles and suits beginners as an entry point
- All practice is only lawful in your own home lab or on official platforms, always within law and ethics
- A portfolio of writeups that show how you think becomes the strongest asset when applying for a first role
