Skip to content
Breaking into cybersecurity

How to get into cybersecurity with no experience: a practical roadmap

How to get into cybersecurity with no experience: pick a target role, learn the foundations, pass one certification and build proof. A month-by-month plan.

LearnCyber editorial team, reviewed by Hackrowd Technology’s penetration testers · · 9 min read

You get into cybersecurity with no experience by choosing one entry-level role, learning the IT foundations that role sits on, passing one recognised certification, and then building visible proof that you can do the work. The proof is the part most beginners skip, and it is the part that turns “no experience” into “some experience” before anyone hires you.

This guide gives you the order to do things in, what to practise each month, and the traps that waste the most time. It assumes you are starting from zero: no IT job, no computer science degree, maybe a day job in something unrelated.

What does “no experience” actually mean to an employer?

When a hiring manager reads “no experience”, they are not asking whether you have held the job title before. They are asking three narrower questions:

  1. Do you understand how computers, networks and accounts work well enough not to need hand-holding?
  2. Can you follow a process, write clearly and explain what you found?
  3. Is there any evidence, anywhere, that you have done something like this before?

You can answer all three without a security job. The first comes from foundations, the second from how you document your learning, and the third from a portfolio of small, real pieces of work. That is the whole roadmap in one sentence.

Most people also have more relevant experience than they think. If you have done customer service, you have handled confused, stressed people on a deadline, which is half of incident response. If you have worked in banking, audit or admin, you already understand controls, approvals and evidence, which is the daily language of governance, risk and compliance. Write those down now; you will use them on your CV later.

Step 1: choose a direction before you choose a course

“Cybersecurity” is not one job. Beginners who try to learn all of it at once tend to stall, because every topic leads to three more. Pick a target for your first role. You can change direction later, and many people do.

If you enjoy... Look at this first role What the work looks like
Puzzles, patterns, watching for something odd SOC analyst (tier 1) Triaging alerts, reading logs, escalating real incidents
Breaking things to see how they work Junior penetration tester Testing systems with permission, then writing up findings
Structure, documents, policy, people GRC analyst Risk registers, control testing, audits, policies
Fixing things for people IT support with a security focus Accounts, devices, patching: the classic stepping stone

If you are drawn to monitoring and incident response, our SOC analyst roadmap goes deeper. If offensive work is the goal, read how to become a penetration tester from scratch. If documents and frameworks appeal more than terminals, start with what a GRC analyst does.

Not sure? Default to the SOC path. Its foundations overlap most with the other three, so very little of the effort is wasted if you switch.

Step 2: learn the foundations (roughly months 1 to 3)

Security is built on IT. You cannot spot a malicious connection if you do not know what a normal one looks like. Before any “hacking” content, spend time on four areas.

Networking

Learn the OSI and TCP/IP models well enough to explain them, then go practical: IP addressing and subnets, DNS, DHCP, TCP versus UDP, common ports, and what a firewall rule actually does. On any Linux machine or virtual machine, these commands show you your own network:

$ ip -brief address
lo               UNKNOWN        127.0.0.1/8 ::1/128
enp0s3           UP             192.168.56.20/24 fe80::a00:27ff:fe4e:66a1/64

$ ss -tulpn
Netid State  Recv-Q Send-Q Local Address:Port  Peer Address:Port Process
udp   UNCONN 0      0      127.0.0.53%lo:53         0.0.0.0:*
tcp   LISTEN 0      128          0.0.0.0:22         0.0.0.0:*

Being able to say “this machine is listening for SSH on port 22, on every interface” is the kind of sentence a SOC or pentest interviewer wants to hear.

Linux and Windows

Get comfortable on the Linux command line: moving around the file system, permissions, users and groups, processes, services and logs. Then learn the Windows side: Event Viewer, user accounts, PowerShell basics and, ideally, a little Active Directory, because most organisations still run their identities on it.

Basic scripting

You do not need to be a developer. You need to read a short Bash or Python script and understand what it does, and to write a ten-line script that saves you from repeating yourself.

Security concepts

Learn the vocabulary: the CIA triad (confidentiality, integrity, availability), authentication versus authorisation, least privilege, encryption versus hashing, vulnerability versus threat versus risk. The NCSC’s guidance and the NIST Cybersecurity Framework 2.0 are free, authoritative and written for people who are not specialists.

A realistic weekly rhythm while working full time is around an hour on weekdays and a longer session at the weekend. Consistency matters more than intensity. If you are worried you are not “technical enough”, read our honest take on whether cybersecurity is hard to learn.

Step 3: earn one certification that employers recognise (roughly months 3 to 6)

A certification will not get you a job on its own, but it gets your CV past the first filter, and preparing for it forces you to cover topics you would otherwise skip.

For most beginners the sensible first target is CompTIA Security+. It is vendor-neutral, widely listed in entry-level job adverts, and covers the breadth you need. The current exam is SY0-701: up to 90 questions in 90 minutes, a passing score of 750 on a 100–900 scale, and five domains (General Security Concepts, Threats, Vulnerabilities & Mitigations, Security Architecture, Security Operations, and Security Program Management & Oversight). CompTIA has also announced a new version, so check the official Security+ page for which version to book. Our Security+ SY0-701 study guide covers how to choose and how to prepare.

If your networking is weak, Network+ first is a reasonable choice. For a fuller comparison and a suggested order, see the best cybersecurity certifications for beginners.

Two warnings. First, a certificate (you finished a course) is not a certification (you passed an exam set by a certifying body). Employers know the difference. Second, never use exam dumps. Beyond being dishonest, they breach the certifying body’s candidate agreement and can cost you the credential.

Step 4: build proof you can do the work (start now, keep going)

This is what separates candidates who get interviews from candidates who do not. Run it alongside steps 2 and 3, not after them.

Set up a small home lab

You need one reasonably modern laptop, free virtualisation software such as VirtualBox, and a few free virtual machines: a Linux server, a Windows evaluation machine, and a deliberately vulnerable machine to practise on. Keep the lab on a host-only network so nothing is exposed to the internet.

Do one small project, then write it up

Here is a typical first project. Install SSH on your Linux server, try logging in from another VM with wrong passwords a few times, then investigate what the logs show:

$ sudo grep “Failed password” /var/log/auth.log | grep -oE “from [0-9.]+” | sort | uniq -c | sort -rn
    212 from 192.168.56.101
      3 from 192.168.56.20

(On systems that log to the journal instead of /var/log/auth.log, use journalctl -u ssh and pipe that into the same commands.)

Now write it up as a one-page note: what you did, what the logs showed, what an attacker brute-forcing SSH would look like, and what you would recommend (key-based authentication, disabling password login, a tool like fail2ban, alerting on a threshold). That page is evidence of networking knowledge, Linux skill, log analysis and clear writing, all at once.

Only practise on machines you own or have written permission to test. Scanning or attacking anyone else’s systems is illegal in most countries, including under Nigeria’s Cybercrimes Act and the UK’s Computer Misuse Act.

Good portfolio pieces for beginners

  • A write-up of a log investigation, like the one above.
  • A short “hardening checklist” you applied to a fresh Windows or Linux VM, with before-and-after screenshots.
  • Walkthroughs of practice labs, such as the free PortSwigger Web Security Academy labs, written in your own words (never publish answers to live, paid or exam content).
  • For GRC-leaning learners: a sample risk register and an access-control policy for a fictional company.

Put these on GitHub or a simple blog and link them from your CV and LinkedIn.

Step 5: target the first role, not the dream role (roughly months 6 to 12)

Your first job in security might not have “security” in the title. Good stepping stones include IT support or service desk, NOC (network operations) analyst, junior SOC analyst, IT audit assistant, and compliance or GRC assistant. Each one gives you real experience with systems, tickets, logs or controls, and internal moves into security teams are common.

When you apply:

  • Tailor the CV to the role you picked in step 1. One page, skills and projects near the top, links to your write-ups. Lead with transferable experience in plain terms (“handled daily customer escalations under time pressure” reads well if it is true).
  • Use the job advert’s language. If it says “SIEM”, “incident triage” or “ISO 27001”, show where you have touched those things, even in a lab.
  • Apply widely, then follow up. Entry-level hiring is slow and uneven; silence is normal and not a verdict on you.
  • Talk to people. Local security meetups, online communities and conference talks are where many first roles are found.

If you are in Nigeria, the market, training routes and first roles have their own shape; we cover that in how to start a cybersecurity career in Nigeria. If you do not have a degree, read how to get into cybersecurity without a degree; many security roles care more about demonstrable skill than about a particular qualification.

A 12-month roadmap at a glance

This is a planning aid, not a promise. Some people move faster, and many people with jobs and families take longer. Both are fine.

Months Focus Output you should have
1–2 Networking, Linux basics, security vocabulary Notes you can explain aloud; a working Linux VM
2–3 Windows, PowerShell, intro scripting Home lab with 2–3 VMs on an isolated network
3–6 Certification study (Security+ or Network+ first) Exam booked and passed; first lab write-up
4–8 Role-specific skills (SOC, pentest or GRC) 3–5 portfolio pieces published
6–12 CV, LinkedIn, applications, networking Applications sent; interviews practised

Mistakes that cost beginners the most time

  • Collecting courses instead of finishing one. Ten half-watched courses are worth less than one finished course and one write-up.
  • Skipping networking because it feels boring. It comes back in every interview.
  • Jumping straight to hacking tools. Running a tool you do not understand teaches you very little; knowing what the tool is doing underneath is the skill.
  • Buying expensive certifications too early. Advanced credentials often assume years of experience. Start with the foundations.
  • Studying in silence. Join a community, ask questions, share your write-ups. Feedback speeds everything up.

Structured, instructor-led training helps some people stay on track; LearnCyber by Hackrowd runs live online classes taught by working penetration testers, but everything in this roadmap can also be done with free resources and discipline.

Questions

How long does it take to get into cybersecurity with no experience?

It varies widely with your starting point and weekly hours. Many people plan for six to twelve months of steady study and portfolio work before landing a first IT or security role, but there is no fixed timeline, and nobody can honestly promise one.

Can I get into cybersecurity with no IT background at all?

Yes, but plan to spend your first months on IT foundations. Most people who struggle skipped networking and operating systems, not "hacking".

What is the best first certification?

For most beginners, CompTIA Security+, or Network+ first if networking is new to you. Check the [official exam page](https://www.comptia.org/en-us/certifications/security/) for the current version and price.

Do I need to know how to code?

Not to start. You need to read and adapt short scripts, and Python or PowerShell basics will help a lot as you progress.

Is cybersecurity a good career for beginners?

It can be, if you enjoy continual learning. The field changes constantly, so curiosity matters more than any single credential.