You get into cybersecurity with no experience by choosing one entry-level role, learning the IT foundations that role sits on, passing one recognised certification, and then building visible proof that you can do the work. The proof is the part most beginners skip, and it is the part that turns “no experience” into “some experience” before anyone hires you.
This guide gives you the order to do things in, what to practise each month, and the traps that waste the most time. It assumes you are starting from zero: no IT job, no computer science degree, maybe a day job in something unrelated.
What does “no experience” actually mean to an employer?
When a hiring manager reads “no experience”, they are not asking whether you have held the job title before. They are asking three narrower questions:
- Do you understand how computers, networks and accounts work well enough not to need hand-holding?
- Can you follow a process, write clearly and explain what you found?
- Is there any evidence, anywhere, that you have done something like this before?
You can answer all three without a security job. The first comes from foundations, the second from how you document your learning, and the third from a portfolio of small, real pieces of work. That is the whole roadmap in one sentence.
Most people also have more relevant experience than they think. If you have done customer service, you have handled confused, stressed people on a deadline, which is half of incident response. If you have worked in banking, audit or admin, you already understand controls, approvals and evidence, which is the daily language of governance, risk and compliance. Write those down now; you will use them on your CV later.
Step 1: choose a direction before you choose a course
“Cybersecurity” is not one job. Beginners who try to learn all of it at once tend to stall, because every topic leads to three more. Pick a target for your first role. You can change direction later, and many people do.
| If you enjoy... | Look at this first role | What the work looks like |
|---|---|---|
| Puzzles, patterns, watching for something odd | SOC analyst (tier 1) | Triaging alerts, reading logs, escalating real incidents |
| Breaking things to see how they work | Junior penetration tester | Testing systems with permission, then writing up findings |
| Structure, documents, policy, people | GRC analyst | Risk registers, control testing, audits, policies |
| Fixing things for people | IT support with a security focus | Accounts, devices, patching: the classic stepping stone |
If you are drawn to monitoring and incident response, our SOC analyst roadmap goes deeper. If offensive work is the goal, read how to become a penetration tester from scratch. If documents and frameworks appeal more than terminals, start with what a GRC analyst does.
Not sure? Default to the SOC path. Its foundations overlap most with the other three, so very little of the effort is wasted if you switch.
Step 2: learn the foundations (roughly months 1 to 3)
Security is built on IT. You cannot spot a malicious connection if you do not know what a normal one looks like. Before any “hacking” content, spend time on four areas.
Networking
Learn the OSI and TCP/IP models well enough to explain them, then go practical: IP addressing and subnets, DNS, DHCP, TCP versus UDP, common ports, and what a firewall rule actually does. On any Linux machine or virtual machine, these commands show you your own network:
$ ip -brief address
lo UNKNOWN 127.0.0.1/8 ::1/128
enp0s3 UP 192.168.56.20/24 fe80::a00:27ff:fe4e:66a1/64
$ ss -tulpn
Netid State Recv-Q Send-Q Local Address:Port Peer Address:Port Process
udp UNCONN 0 0 127.0.0.53%lo:53 0.0.0.0:*
tcp LISTEN 0 128 0.0.0.0:22 0.0.0.0:*
Being able to say “this machine is listening for SSH on port 22, on every interface” is the kind of sentence a SOC or pentest interviewer wants to hear.
Linux and Windows
Get comfortable on the Linux command line: moving around the file system, permissions, users and groups, processes, services and logs. Then learn the Windows side: Event Viewer, user accounts, PowerShell basics and, ideally, a little Active Directory, because most organisations still run their identities on it.
Basic scripting
You do not need to be a developer. You need to read a short Bash or Python script and understand what it does, and to write a ten-line script that saves you from repeating yourself.
Security concepts
Learn the vocabulary: the CIA triad (confidentiality, integrity, availability), authentication versus authorisation, least privilege, encryption versus hashing, vulnerability versus threat versus risk. The NCSC’s guidance and the NIST Cybersecurity Framework 2.0 are free, authoritative and written for people who are not specialists.
A realistic weekly rhythm while working full time is around an hour on weekdays and a longer session at the weekend. Consistency matters more than intensity. If you are worried you are not “technical enough”, read our honest take on whether cybersecurity is hard to learn.
Step 3: earn one certification that employers recognise (roughly months 3 to 6)
A certification will not get you a job on its own, but it gets your CV past the first filter, and preparing for it forces you to cover topics you would otherwise skip.
For most beginners the sensible first target is CompTIA Security+. It is vendor-neutral, widely listed in entry-level job adverts, and covers the breadth you need. The current exam is SY0-701: up to 90 questions in 90 minutes, a passing score of 750 on a 100–900 scale, and five domains (General Security Concepts, Threats, Vulnerabilities & Mitigations, Security Architecture, Security Operations, and Security Program Management & Oversight). CompTIA has also announced a new version, so check the official Security+ page for which version to book. Our Security+ SY0-701 study guide covers how to choose and how to prepare.
If your networking is weak, Network+ first is a reasonable choice. For a fuller comparison and a suggested order, see the best cybersecurity certifications for beginners.
Two warnings. First, a certificate (you finished a course) is not a certification (you passed an exam set by a certifying body). Employers know the difference. Second, never use exam dumps. Beyond being dishonest, they breach the certifying body’s candidate agreement and can cost you the credential.
Step 4: build proof you can do the work (start now, keep going)
This is what separates candidates who get interviews from candidates who do not. Run it alongside steps 2 and 3, not after them.
Set up a small home lab
You need one reasonably modern laptop, free virtualisation software such as VirtualBox, and a few free virtual machines: a Linux server, a Windows evaluation machine, and a deliberately vulnerable machine to practise on. Keep the lab on a host-only network so nothing is exposed to the internet.
Do one small project, then write it up
Here is a typical first project. Install SSH on your Linux server, try logging in from another VM with wrong passwords a few times, then investigate what the logs show:
$ sudo grep “Failed password” /var/log/auth.log | grep -oE “from [0-9.]+” | sort | uniq -c | sort -rn
212 from 192.168.56.101
3 from 192.168.56.20
(On systems that log to the journal instead of /var/log/auth.log, use journalctl -u ssh and pipe that into the same commands.)
Now write it up as a one-page note: what you did, what the logs showed, what an attacker brute-forcing SSH would look like, and what you would recommend (key-based authentication, disabling password login, a tool like fail2ban, alerting on a threshold). That page is evidence of networking knowledge, Linux skill, log analysis and clear writing, all at once.
Only practise on machines you own or have written permission to test. Scanning or attacking anyone else’s systems is illegal in most countries, including under Nigeria’s Cybercrimes Act and the UK’s Computer Misuse Act.
Good portfolio pieces for beginners
- A write-up of a log investigation, like the one above.
- A short “hardening checklist” you applied to a fresh Windows or Linux VM, with before-and-after screenshots.
- Walkthroughs of practice labs, such as the free PortSwigger Web Security Academy labs, written in your own words (never publish answers to live, paid or exam content).
- For GRC-leaning learners: a sample risk register and an access-control policy for a fictional company.
Put these on GitHub or a simple blog and link them from your CV and LinkedIn.
Step 5: target the first role, not the dream role (roughly months 6 to 12)
Your first job in security might not have “security” in the title. Good stepping stones include IT support or service desk, NOC (network operations) analyst, junior SOC analyst, IT audit assistant, and compliance or GRC assistant. Each one gives you real experience with systems, tickets, logs or controls, and internal moves into security teams are common.
When you apply:
- Tailor the CV to the role you picked in step 1. One page, skills and projects near the top, links to your write-ups. Lead with transferable experience in plain terms (“handled daily customer escalations under time pressure” reads well if it is true).
- Use the job advert’s language. If it says “SIEM”, “incident triage” or “ISO 27001”, show where you have touched those things, even in a lab.
- Apply widely, then follow up. Entry-level hiring is slow and uneven; silence is normal and not a verdict on you.
- Talk to people. Local security meetups, online communities and conference talks are where many first roles are found.
If you are in Nigeria, the market, training routes and first roles have their own shape; we cover that in how to start a cybersecurity career in Nigeria. If you do not have a degree, read how to get into cybersecurity without a degree; many security roles care more about demonstrable skill than about a particular qualification.
A 12-month roadmap at a glance
This is a planning aid, not a promise. Some people move faster, and many people with jobs and families take longer. Both are fine.
| Months | Focus | Output you should have |
|---|---|---|
| 1–2 | Networking, Linux basics, security vocabulary | Notes you can explain aloud; a working Linux VM |
| 2–3 | Windows, PowerShell, intro scripting | Home lab with 2–3 VMs on an isolated network |
| 3–6 | Certification study (Security+ or Network+ first) | Exam booked and passed; first lab write-up |
| 4–8 | Role-specific skills (SOC, pentest or GRC) | 3–5 portfolio pieces published |
| 6–12 | CV, LinkedIn, applications, networking | Applications sent; interviews practised |
Mistakes that cost beginners the most time
- Collecting courses instead of finishing one. Ten half-watched courses are worth less than one finished course and one write-up.
- Skipping networking because it feels boring. It comes back in every interview.
- Jumping straight to hacking tools. Running a tool you do not understand teaches you very little; knowing what the tool is doing underneath is the skill.
- Buying expensive certifications too early. Advanced credentials often assume years of experience. Start with the foundations.
- Studying in silence. Join a community, ask questions, share your write-ups. Feedback speeds everything up.
Structured, instructor-led training helps some people stay on track; LearnCyber by Hackrowd runs live online classes taught by working penetration testers, but everything in this roadmap can also be done with free resources and discipline.