Skip to content
Breaking into cybersecurity

How to learn cybersecurity for free (and when paying makes sense)

How to learn cybersecurity for free: verified free courses, labs and wargames, a 12-week plan, and an honest guide to when paying is worth it.

LearnCyber editorial team, reviewed by Hackrowd Technology’s penetration testers · · 8 min read

You can learn most of the technical foundations of cybersecurity for free: networking, Linux, web application security and basic defence are all covered by high-quality official resources that cost nothing. What free learning rarely gives you is structure, feedback on your work, and an exam-based certification, and those are the three things worth paying for, at the right moment.

This guide lists free resources we checked in October 2026, gives you a 12-week plan that uses only them, and then sets out honestly when spending money starts to make sense.

Can you really learn cybersecurity for free?

Yes, up to a point. The people who build the tools and standards publish a lot of their best material openly. OWASP’s documentation is free. PortSwigger’s Web Security Academy, which many working testers still use, states on its own page that the Academy is “100% free” (PortSwigger). NIST publishes its frameworks and testing guides at no cost.

Where “free” stops is usually in three places:

  1. Certification exams. Almost every exam-based certification charges an exam fee. Free courses can prepare you, but the credential itself generally costs money.
  2. Guided feedback. Nobody reviews your report, corrects your methodology or tells you why your answer was half right.
  3. Time-limited free tiers. Some platforms give you a free plan with limits. TryHackMe, for example, offers a free plan with access to free rooms and a daily time limit on its in-browser attack machine, with full learning paths on the paid plan (TryHackMe pricing).

None of these block you from starting today.

The free resources worth your time, by stage

We checked each of these on the provider’s own site in October 2026. Free offers change, so look again before you commit weeks to one.

Stage Resource What it teaches Free status (Oct 2026)
Foundations Cisco Networking Academy, Introduction to Cybersecurity Core concepts, threats, basic defence Listed as a free online course (NetAcad)
Linux and the command line OverTheWire Bandit wargame SSH, file permissions, searching, pipes Free to play (OverTheWire)
Web security PortSwigger Web Security Academy SQL injection, XSS, access control, authentication, with live labs Free
Web security reference OWASP Top 10 and Web Security Testing Guide The common web risk categories and how to test for them Free (OWASP)
Vulnerable practice app OWASP Juice Shop A deliberately insecure shop you run on your own machine Free, open source
Frameworks and GRC NIST Cybersecurity Framework 2.0 How organisations structure security Free (NIST)
Exam planning CompTIA exam objectives The exact topics an exam covers Objectives are a free download from CompTIA’s exam pages (CompTIA)
Guided labs TryHackMe free plan Beginner rooms in the browser Free tier with limits

A correction worth knowing about: ISC2 Certified in Cybersecurity

For several years, many blog posts (possibly including ones you’ve read) recommended ISC2’s Certified in Cybersecurity (CC) as a “free certification”. That was true under ISC2’s One Million Certified in Cybersecurity programme. ISC2’s own page now says the programme closed to new enrolments on 20 May 2026. People who already hold an exam code can still sit the exam free until 31 December 2026, and certified members pay an annual maintenance fee (ISC2). If you’re starting now, treat CC as a paid exam. It’s still a reasonable entry-level certification, but it’s no longer the free shortcut it was.

A 12-week plan using only free resources

This assumes around eight to ten hours a week. If you have less, stretch it; don’t skip stages.

Weeks 1–3: networking and Linux

Start Cisco’s Introduction to Cybersecurity for the vocabulary, and play Bandit for the hands-on habit. Bandit runs over SSH. Level 0 tells you the host, port, user and password (OverTheWire):

ssh bandit0@bandit.labs.overthewire.org -p 2220

Once you’re in, the early levels teach you commands you’ll use every working day:

bandit0@bandit:~$ ls -la
total 24
drwxr-xr-x  2 root    root    4096 Sep 19 07:08 .
drwxr-xr-x 70 root    root    4096 Sep 19 07:09 ..
-rw-r--r--  1 root    root     220 Mar 31  2024 .bash_logout
-rw-r--r--  1 root    root    3771 Mar 31  2024 .bashrc
-rw-r--r--  1 root    root     807 Mar 31  2024 .profile
-rw-r-----  1 bandit1 bandit0   33 Sep 19 07:08 readme
bandit0@bandit:~$ cat readme

Aim to clear levels 0 to 15 by the end of week 3. When you get stuck, read the man page for the command the level hints at before searching for a walkthrough. Reading a manual is a skill you’re practising, not a detour.

Weeks 4–5: build a small lab

You need somewhere safe to break things. Install Docker, then run OWASP Juice Shop bound to your own machine only:

docker run --rm -p 127.0.0.1:3000:3000 bkimminich/juice-shop
info: All dependencies in ./package.json are satisfied (OK)
info: Detected Node.js version v22.12.0 (OK)
info: Configuration default validated (OK)
info: Server listening on port 3000

That output is illustrative; the versions on your machine will differ. Open http://127.0.0.1:3000 in your browser. Binding to 127.0.0.1 keeps the vulnerable app off your home network. Our guide to building a cybersecurity home lab covers adding a Kali VM and a Windows target when you’re ready.

Weeks 6–9: web application security

Work through PortSwigger’s learning paths in this order: SQL injection, authentication, access control, then cross-site scripting. Do the “Apprentice” labs first. For each topic, write three lines in a notes file:

  • what the vulnerability is, in your own words
  • the request that proved it (copy it from Burp Suite’s Community Edition, which is free)
  • the fix a developer should make

Then find the same flaw in Juice Shop. Recognising a vulnerability in an app that wasn’t built as a lesson is the real test.

Only test systems you own or have written permission to test. Juice Shop on your own machine and PortSwigger’s labs are built for this.

Weeks 10–11: the defender’s side

Read the NIST CSF 2.0 core functions (Govern, Identify, Protect, Detect, Respond, Recover) and map each Juice Shop flaw you found to the function that would have prevented or caught it. Then watch your own attacks from the defender’s side. On a Linux host, capture the traffic to Juice Shop on the loopback interface while you repeat a login attack in another window:

sudo tcpdump -i lo -l -A ‘tcp port 3000’ | grep --line-buffered -A12 “POST /rest/user/login”
POST /rest/user/login HTTP/1.1
Host: 127.0.0.1:3000
Content-Type: application/json
...
{“email”:"' OR 1=1--“,”password“:”x"}

Seeing your own SQL injection attempt on the wire is the moment many people realise defence is as interesting as attack. Ask yourself what rule would have flagged it.

Week 12: pick a direction and a target certification

Download the exam objectives for the certification that fits your direction (Security+ SY0-701 for a general start, for example; CompTIA says a new Security+ version is expected on or around 17 November 2026, so check its Security+ page for which version to target) and mark each objective as confident, seen it or never heard of it. That list tells you exactly what to study next, and it cost you nothing.

What free learning can’t give you

Be honest with yourself about these gaps. They’re the reasons many self-taught learners stall.

  • Feedback on your reasoning. A lab tells you whether you got the flag, not whether your approach would hold up on a client’s network.
  • Professional writing practice. Employers in offensive and GRC roles care a great deal about reports. Free platforms rarely mark your writing.
  • Accountability. A cohort with a schedule finishes things. Solo learners with full-time jobs often don’t, and that’s not a character flaw.
  • A credential employers filter on. Many job adverts list certifications. Remember the difference: a certificate shows you completed a course; a certification is an exam-based credential from a certifying body. Free courses usually give you the first, not the second.

When paying makes sense

Spend money when it solves a specific problem you’ve already hit, not before. A decision table:

Your situation Is paying worth it? What to pay for
You haven’t finished a single free path yet Not yet Nothing. Finish the 12-week plan first
You’ve done the free material and keep stalling alone Often yes A structured programme with live sessions and deadlines
A job advert you want lists a specific certification Yes The exam itself, plus official practice material if your mock scores are weak
You want feedback on reports or real methodology Yes Instruction from working practitioners who mark your work
You’re paying for a “certificate” that isn’t exam-based Think twice Check whether employers in your target role recognise it
A seller offers “real exam questions” Never These are dumps; using them can get your certification revoked

Two rules protect your money. First, never pay for anything promising guaranteed jobs or guaranteed passes; nobody honest can promise either. Second, before paying for a course, look for its syllabus and compare it with the official exam objectives. If the provider won’t show you the syllabus, keep your money.

If you’re unsure whether you’re ready to spend at all, our honest take on whether cybersecurity is hard to learn may help you judge where you are.

How long does it take to learn cybersecurity for free?

It depends on your starting point and hours, so be wary of anyone who gives you a fixed number. A useful benchmark: if you can complete the 12-week plan above, explain each Juice Shop flaw you found to a non-technical friend, and score consistently well against the objectives list for an entry certification, you’ve built a real foundation. Moving from there to a first role is a separate project, covered in our roadmap for getting into cybersecurity with no experience.

Questions

Are there any free cybersecurity certifications for beginners?

Free *courses* with completion certificates are common. Free exam-based *certifications* are rare, and the best-known one, ISC2's CC offer, closed to new enrolments in May 2026. Check the issuer's own page before believing any "free certification" claim.

Do I need a degree to learn cybersecurity?

No degree is needed to learn. Some employers ask for one when hiring, but many roles weigh demonstrable skills and certifications heavily.

Is YouTube enough?

Videos are fine for understanding concepts. They don't replace hands-on labs, where you type the commands and make the mistakes yourself.

What should I learn first: networking, Linux or programming?

Networking and Linux first. Basic scripting (Bash or Python) comes naturally once you're repeating the same commands in Bandit and wish a script would do it for you.

Can I learn cybersecurity on a phone?

You can read and watch on a phone, but you need a laptop or desktop for labs. An older machine with 8 GB of RAM can run Juice Shop and a lightweight Linux VM.