Blog
Notes on breaking into security
Plain-English guides, reviewed by Hackrowd Technology’s penetration testers.
Breaking into cybersecurity
Best cybersecurity certifications for beginners, and the order to take them
The best cybersecurity certifications for beginners, in the order to take them: Security+ first, a foundation if you need one, then a specialist exam.
· 8 min read
Certificate vs certification: what employers actually check
Certificate vs certification: one proves you finished a course, the other proves you passed an independent exam. Here's what employers actually check.
· 7 min read
Changing career to cyber security in the UK: routes for career switchers
A cyber security career change in the UK: the four realistic routes, how NCSC schemes and Council titles fit in, and a 90-day plan you can start this week.
· 9 min read
How to get into cybersecurity with no experience: a practical roadmap
How to get into cybersecurity with no experience: pick a target role, learn the foundations, pass one certification and build proof. A month-by-month plan.
· 9 min read
How to get into cybersecurity without a degree
How to get into cybersecurity without a degree: the roles that hire on skill, which certifications help at entry level, and how to build proof.
· 8 min read
How to learn cybersecurity for free (and when paying makes sense)
How to learn cybersecurity for free: verified free courses, labs and wargames, a 12-week plan, and an honest guide to when paying is worth it.
· 8 min read
How to start a cybersecurity career in Nigeria: training, paths and first roles
Cybersecurity training in Nigeria, done right: the realistic first roles (helpdesk, SOC, GRC, data protection), what to learn and how to build proof.
· 9 min read
How to write a cybersecurity CV with no experience (with a sample)
Writing a cybersecurity resume with no experience? Show lab work, transferable skills and study honestly. Includes a full sample CV for a career switcher.
· 8 min read
Is cybersecurity hard to learn? An honest answer for beginners
Is cybersecurity hard to learn? It's broad rather than brutally difficult. What's genuinely hard, what's easier than you think, and a 30-day test to try.
· 6 min read
SOC analyst roadmap: from zero to entry level
A SOC analyst roadmap from zero to entry level: the skills, logs, tools and certifications to learn in order, plus how to land a SOC internship.
· 9 min read
Switching to cybersecurity at 30, 40 or later: an honest plan
A career change to cyber security at 40 (or 30, or 50) is realistic if you aim at roles that use your experience. An honest 12-month plan for switchers.
· 8 min read
Pentesting and ethical hacking
Bug bounty for beginners: how it works and how to start legally
Bug bounty for beginners: how programmes work, reading scope, safe harbour, platform rules and a report format triagers accept. Start legally.
· 8 min read
Burp Suite tutorial for beginners: step by step in your own lab
A Burp Suite tutorial for beginners: set up the proxy and CA certificate, then use Repeater, Intruder and Decoder against OWASP Juice Shop in your own lab.
· 8 min read
Ethical hacking for beginners: what to learn first, and what to skip
Ethical hacking for beginners: learn networking, Linux and the web first, then Nmap and Burp. What to skip, a 16-week roadmap and safe lab exercises.
· 7 min read
How to become a penetration tester from scratch
How to become a penetration tester from scratch: the skills, lab practice, methodology, certifications and first jobs, in the order that works.
· 9 min read
How to build a cybersecurity home lab (free and low-cost options)
Cybersecurity home lab setup, step by step: VirtualBox or VMware, Kali, Metasploitable 2 and OWASP Juice Shop on an isolated host-only network, all free.
· 10 min read
How to write a penetration testing report (with a sample from a fictional company)
How to write a penetration testing report: structure, CVSS scoring, evidence and remediation, with a sample findings section for a fictional fintech.
· 9 min read
Nmap commands cheat sheet: 25 commands with real output
Nmap commands cheat sheet: 25 commands for discovery, port scans, version and OS detection, NSE scripts and output, each with real lab output.
· 11 min read
OWASP Top 10 explained with examples
The OWASP Top 10 2025 explained category by category, with a lab-only example for each, what changed from 2021, and how the API Top 10 differs.
· 9 min read
Penetration testing tools: a beginner's toolkit and what each one is for
Penetration testing tools for beginners, grouped by test phase: what each one is for, how defenders spot it, and the order to learn them in.
· 9 min read
The phases of a penetration test, walked through on a fictional company
Penetration testing phases on a fictional fintech: scoping, recon, scanning, exploitation, post-exploitation and reporting, mapped to NIST and PTES.
· 8 min read
What a penetration tester actually does: a typical week
What does a penetration tester do all week? Scoping calls, testing, note-taking, retests and report writing, walked through day by day for career starters.
· 7 min read
CompTIA Security+ and PenTest+
CompTIA PenTest+ PT0-003 study guide: objectives and how to prepare
A PenTest+ PT0-003 study guide: the five official domains and weights, what each covers, a 12-week plan weighted to the exam, and lab exercises.
· 8 min read
CompTIA Security+ SY0-701 study guide: objectives, plan and resources
Security+ SY0-701 study guide: all five domains and their objectives, a study plan, PBQ practice, honest resources, and whether to take SY0-701 or SY0-801.
· 9 min read
Exam dumps: why they can cost you your certification
Thinking of using a Security+ exam dump? CompTIA treats it as cheating: scores invalidated, certifications revoked, testing bans. What to use instead.
· 8 min read
How to book a CompTIA exam from Nigeria: online or test centre
How to book a CompTIA exam in Nigeria: buy a voucher, schedule with Pearson VUE, and choose OnVUE online or a test centre. Steps, ID rules, pitfalls.
· 8 min read
PenTest+ PT0-003 PBQs and practice: how to prepare properly
PenTest+ PT0-003 PBQ prep: what performance-based questions test, six original practice scenarios with answers, and a lab routine that builds the skill.
· 7 min read
Security+ study plan: a 6-week and a 12-week version
A Security+ study plan for SY0-701 in two versions, 6 weeks and 12 weeks, mapped to the exam domains, with weekly tasks, practice checkpoints and lab work.
· 9 min read
Security+ SY0-701 performance-based questions (PBQs): what to expect and how to practise
Security+ SY0-701 PBQ guide: how performance-based questions work, how they are scored, and four original practice scenarios with worked answers.
· 7 min read
Security+ vs CEH: which is better for a beginner?
Security+ vs CEH for beginners: what each exam tests, eligibility, format and which job it suits, with a fair verdict and where CCNA fits instead.
· 7 min read
Security+ vs CySA+, and where SecurityX fits
Security+ vs CySA+: Security+ is the broad foundation, CySA+ the analyst step, SecurityX the expert tier. What each covers and the order to take them.
· 5 min read
Security+ vs Network+: which should you take first?
Security+ vs Network+: what each exam covers, how hard each is, who should take Network+ first and who can go straight to Security+.
· 8 min read
GRC, ISO 27001 and SOC 2
GRC analyst vs SOC analyst: which suits you?
GRC vs SOC analyst compared: a day in each role, the skills, the stress, the certifications and a self-test to work out which one suits you.
· 8 min read
GRC certifications for beginners: which ones matter
Which GRC analyst certification should a beginner take first? Entry-level options, ISO 27001 and privacy credentials, and the ones to save for later.
· 7 min read
ISO 27001 explained for beginners: clauses, Annex A and the ISMS
What is ISO 27001? A beginner's guide to the 2022 standard: the ISMS, clauses 4 to 10, the 93 Annex A controls in four themes, and how certification works.
· 9 min read
ISO 27001 Lead Implementer vs Lead Auditor: which one, and when?
ISO 27001 lead implementer vs lead auditor: one builds the ISMS, the other checks it. What each covers, who it suits, and what the 'Lead' title needs.
· 6 min read
Moving into GRC from audit, legal, banking or admin
How to get into cybersecurity GRC from audit, legal, banking or admin: skills that transfer, gaps to close, and a 90-day plan with real work samples.
· 7 min read
Nigeria's Data Protection Act 2023 (NDPA), explained for career starters
NDPA 2023 explained for cybersecurity beginners: who it covers, lawful bases, data subject rights, the 72-hour breach rule, DPOs, GAID and penalties.
· 10 min read
NIST Cybersecurity Framework 2.0 explained for career starters
NIST CSF 2.0 explained for beginners: the six functions including Govern, how categories, profiles and tiers work, and a worked gap analysis you can copy.
· 8 min read
What is a GRC analyst? The role, the skills and how to become one
What is a GRC analyst? What the job involves day to day, the frameworks and skills it needs, sample work to practise, and how to land an entry-level role.
· 8 min read
What is SOC 2? A plain-English guide for career starters (it's a report, not a certificate)
What is SOC 2 certification? It isn't one: SOC 2 is a CPA firm's attestation report. Type I vs Type II, the Trust Services Criteria and the jobs around it.
· 9 min read
Security basics for everyone
Black Friday scams: how attackers build fake shops and how defenders catch them
Black Friday scams explained for cyber beginners: how attackers build fake shops with lookalike domains, clones and skimmers, and how defenders catch them.
· 8 min read
Fake bank alerts and POS scams: how fraudsters do it and how defenders catch them
How a fake bank alert and POS scams work, why the SMS can't be trusted, and how fraud analysts catch them. A practical guide for cybersecurity beginners.
· 10 min read
Festive-season scams: how attackers exploit Detty December and how defenders catch them
Detty December scams explained for cyber beginners: fake tickets, short-lets and flights, WhatsApp takeovers, and how defenders detect and shut them down.
· 8 min read
How to analyse a phishing link safely: a beginner analyst's workflow
How to check a phishing website link without clicking it: read the URL, defang it, then use urlscan.io, VirusTotal, WHOIS and crt.sh like a SOC analyst.
· 9 min read
Passwords, passkeys and MFA explained for cybersecurity beginners
Passkeys vs passwords explained for cybersecurity beginners: how FIDO2 and WebAuthn work, MFA types and their weaknesses, and how defenders spot attacks.
· 9 min read
Phishing email examples explained: what a SOC analyst looks for
Annotated phishing email examples, and what a SOC analyst checks in each: headers, SPF, DKIM and DMARC results, lookalike domains, URLs and attachments.
· 10 min read
Security fundamentals for cybersecurity beginners: how account takeovers work and how defenders stop them
Cybersecurity basics for beginners through one attack: how account takeovers work, what defenders see in the logs, how they respond, and what to practise.
· 9 min read
Social media account takeover: how Facebook and Instagram accounts get hacked, and the defender's checklist
How to protect my Facebook account from hackers: the four takeover paths, how defenders detect them, and a recovery checklist from Meta's help pages.
· 9 min read
WhatsApp account takeover explained: how attackers hijack accounts and how defenders stop them
How to protect your WhatsApp from hackers: how verification-code scams, voicemail abuse and linked-device tricks work, and how defenders respond.
· 8 min read