Skip to content

Blog

Notes on breaking into security

Plain-English guides, reviewed by Hackrowd Technology’s penetration testers.

Breaking into cybersecurity

Best cybersecurity certifications for beginners, and the order to take them

The best cybersecurity certifications for beginners, in the order to take them: Security+ first, a foundation if you need one, then a specialist exam.

· 8 min read

Certificate vs certification: what employers actually check

Certificate vs certification: one proves you finished a course, the other proves you passed an independent exam. Here's what employers actually check.

· 7 min read

Changing career to cyber security in the UK: routes for career switchers

A cyber security career change in the UK: the four realistic routes, how NCSC schemes and Council titles fit in, and a 90-day plan you can start this week.

· 9 min read

How to get into cybersecurity with no experience: a practical roadmap

How to get into cybersecurity with no experience: pick a target role, learn the foundations, pass one certification and build proof. A month-by-month plan.

· 9 min read

How to get into cybersecurity without a degree

How to get into cybersecurity without a degree: the roles that hire on skill, which certifications help at entry level, and how to build proof.

· 8 min read

How to learn cybersecurity for free (and when paying makes sense)

How to learn cybersecurity for free: verified free courses, labs and wargames, a 12-week plan, and an honest guide to when paying is worth it.

· 8 min read

How to start a cybersecurity career in Nigeria: training, paths and first roles

Cybersecurity training in Nigeria, done right: the realistic first roles (helpdesk, SOC, GRC, data protection), what to learn and how to build proof.

· 9 min read

How to write a cybersecurity CV with no experience (with a sample)

Writing a cybersecurity resume with no experience? Show lab work, transferable skills and study honestly. Includes a full sample CV for a career switcher.

· 8 min read

Is cybersecurity hard to learn? An honest answer for beginners

Is cybersecurity hard to learn? It's broad rather than brutally difficult. What's genuinely hard, what's easier than you think, and a 30-day test to try.

· 6 min read

SOC analyst roadmap: from zero to entry level

A SOC analyst roadmap from zero to entry level: the skills, logs, tools and certifications to learn in order, plus how to land a SOC internship.

· 9 min read

Switching to cybersecurity at 30, 40 or later: an honest plan

A career change to cyber security at 40 (or 30, or 50) is realistic if you aim at roles that use your experience. An honest 12-month plan for switchers.

· 8 min read

Pentesting and ethical hacking

Bug bounty for beginners: how it works and how to start legally

Bug bounty for beginners: how programmes work, reading scope, safe harbour, platform rules and a report format triagers accept. Start legally.

· 8 min read

Burp Suite tutorial for beginners: step by step in your own lab

A Burp Suite tutorial for beginners: set up the proxy and CA certificate, then use Repeater, Intruder and Decoder against OWASP Juice Shop in your own lab.

· 8 min read

Ethical hacking for beginners: what to learn first, and what to skip

Ethical hacking for beginners: learn networking, Linux and the web first, then Nmap and Burp. What to skip, a 16-week roadmap and safe lab exercises.

· 7 min read

How to become a penetration tester from scratch

How to become a penetration tester from scratch: the skills, lab practice, methodology, certifications and first jobs, in the order that works.

· 9 min read

How to build a cybersecurity home lab (free and low-cost options)

Cybersecurity home lab setup, step by step: VirtualBox or VMware, Kali, Metasploitable 2 and OWASP Juice Shop on an isolated host-only network, all free.

· 10 min read

How to write a penetration testing report (with a sample from a fictional company)

How to write a penetration testing report: structure, CVSS scoring, evidence and remediation, with a sample findings section for a fictional fintech.

· 9 min read

Nmap commands cheat sheet: 25 commands with real output

Nmap commands cheat sheet: 25 commands for discovery, port scans, version and OS detection, NSE scripts and output, each with real lab output.

· 11 min read

OWASP Top 10 explained with examples

The OWASP Top 10 2025 explained category by category, with a lab-only example for each, what changed from 2021, and how the API Top 10 differs.

· 9 min read

Penetration testing tools: a beginner's toolkit and what each one is for

Penetration testing tools for beginners, grouped by test phase: what each one is for, how defenders spot it, and the order to learn them in.

· 9 min read

The phases of a penetration test, walked through on a fictional company

Penetration testing phases on a fictional fintech: scoping, recon, scanning, exploitation, post-exploitation and reporting, mapped to NIST and PTES.

· 8 min read

What a penetration tester actually does: a typical week

What does a penetration tester do all week? Scoping calls, testing, note-taking, retests and report writing, walked through day by day for career starters.

· 7 min read

CompTIA Security+ and PenTest+

CompTIA PenTest+ PT0-003 study guide: objectives and how to prepare

A PenTest+ PT0-003 study guide: the five official domains and weights, what each covers, a 12-week plan weighted to the exam, and lab exercises.

· 8 min read

CompTIA Security+ SY0-701 study guide: objectives, plan and resources

Security+ SY0-701 study guide: all five domains and their objectives, a study plan, PBQ practice, honest resources, and whether to take SY0-701 or SY0-801.

· 9 min read

Exam dumps: why they can cost you your certification

Thinking of using a Security+ exam dump? CompTIA treats it as cheating: scores invalidated, certifications revoked, testing bans. What to use instead.

· 8 min read

How to book a CompTIA exam from Nigeria: online or test centre

How to book a CompTIA exam in Nigeria: buy a voucher, schedule with Pearson VUE, and choose OnVUE online or a test centre. Steps, ID rules, pitfalls.

· 8 min read

PenTest+ PT0-003 PBQs and practice: how to prepare properly

PenTest+ PT0-003 PBQ prep: what performance-based questions test, six original practice scenarios with answers, and a lab routine that builds the skill.

· 7 min read

Security+ study plan: a 6-week and a 12-week version

A Security+ study plan for SY0-701 in two versions, 6 weeks and 12 weeks, mapped to the exam domains, with weekly tasks, practice checkpoints and lab work.

· 9 min read

Security+ SY0-701 performance-based questions (PBQs): what to expect and how to practise

Security+ SY0-701 PBQ guide: how performance-based questions work, how they are scored, and four original practice scenarios with worked answers.

· 7 min read

Security+ vs CEH: which is better for a beginner?

Security+ vs CEH for beginners: what each exam tests, eligibility, format and which job it suits, with a fair verdict and where CCNA fits instead.

· 7 min read

Security+ vs CySA+, and where SecurityX fits

Security+ vs CySA+: Security+ is the broad foundation, CySA+ the analyst step, SecurityX the expert tier. What each covers and the order to take them.

· 5 min read

Security+ vs Network+: which should you take first?

Security+ vs Network+: what each exam covers, how hard each is, who should take Network+ first and who can go straight to Security+.

· 8 min read

GRC, ISO 27001 and SOC 2

GRC analyst vs SOC analyst: which suits you?

GRC vs SOC analyst compared: a day in each role, the skills, the stress, the certifications and a self-test to work out which one suits you.

· 8 min read

GRC certifications for beginners: which ones matter

Which GRC analyst certification should a beginner take first? Entry-level options, ISO 27001 and privacy credentials, and the ones to save for later.

· 7 min read

ISO 27001 explained for beginners: clauses, Annex A and the ISMS

What is ISO 27001? A beginner's guide to the 2022 standard: the ISMS, clauses 4 to 10, the 93 Annex A controls in four themes, and how certification works.

· 9 min read

ISO 27001 Lead Implementer vs Lead Auditor: which one, and when?

ISO 27001 lead implementer vs lead auditor: one builds the ISMS, the other checks it. What each covers, who it suits, and what the 'Lead' title needs.

· 6 min read

Moving into GRC from audit, legal, banking or admin

How to get into cybersecurity GRC from audit, legal, banking or admin: skills that transfer, gaps to close, and a 90-day plan with real work samples.

· 7 min read

Nigeria's Data Protection Act 2023 (NDPA), explained for career starters

NDPA 2023 explained for cybersecurity beginners: who it covers, lawful bases, data subject rights, the 72-hour breach rule, DPOs, GAID and penalties.

· 10 min read

NIST Cybersecurity Framework 2.0 explained for career starters

NIST CSF 2.0 explained for beginners: the six functions including Govern, how categories, profiles and tiers work, and a worked gap analysis you can copy.

· 8 min read

What is a GRC analyst? The role, the skills and how to become one

What is a GRC analyst? What the job involves day to day, the frameworks and skills it needs, sample work to practise, and how to land an entry-level role.

· 8 min read

What is SOC 2? A plain-English guide for career starters (it's a report, not a certificate)

What is SOC 2 certification? It isn't one: SOC 2 is a CPA firm's attestation report. Type I vs Type II, the Trust Services Criteria and the jobs around it.

· 9 min read

Security basics for everyone

Black Friday scams: how attackers build fake shops and how defenders catch them

Black Friday scams explained for cyber beginners: how attackers build fake shops with lookalike domains, clones and skimmers, and how defenders catch them.

· 8 min read

Fake bank alerts and POS scams: how fraudsters do it and how defenders catch them

How a fake bank alert and POS scams work, why the SMS can't be trusted, and how fraud analysts catch them. A practical guide for cybersecurity beginners.

· 10 min read

Festive-season scams: how attackers exploit Detty December and how defenders catch them

Detty December scams explained for cyber beginners: fake tickets, short-lets and flights, WhatsApp takeovers, and how defenders detect and shut them down.

· 8 min read

How to analyse a phishing link safely: a beginner analyst's workflow

How to check a phishing website link without clicking it: read the URL, defang it, then use urlscan.io, VirusTotal, WHOIS and crt.sh like a SOC analyst.

· 9 min read

Passwords, passkeys and MFA explained for cybersecurity beginners

Passkeys vs passwords explained for cybersecurity beginners: how FIDO2 and WebAuthn work, MFA types and their weaknesses, and how defenders spot attacks.

· 9 min read

Phishing email examples explained: what a SOC analyst looks for

Annotated phishing email examples, and what a SOC analyst checks in each: headers, SPF, DKIM and DMARC results, lookalike domains, URLs and attachments.

· 10 min read

Security fundamentals for cybersecurity beginners: how account takeovers work and how defenders stop them

Cybersecurity basics for beginners through one attack: how account takeovers work, what defenders see in the logs, how they respond, and what to practise.

· 9 min read

Social media account takeover: how Facebook and Instagram accounts get hacked, and the defender's checklist

How to protect my Facebook account from hackers: the four takeover paths, how defenders detect them, and a recovery checklist from Meta's help pages.

· 9 min read

WhatsApp account takeover explained: how attackers hijack accounts and how defenders stop them

How to protect your WhatsApp from hackers: how verification-code scams, voicemail abuse and linked-device tricks work, and how defenders respond.

· 8 min read