Home
Courses
Sign In
New Cohort starts September 21st!✳New Cohort starts September 21st!✳New Cohort starts September 21st!✳New Cohort starts September 21st!✳New Cohort starts September 21st!✳New Cohort starts September 21st!✳New Cohort starts September 21st!✳New Cohort starts September 21st!✳New Cohort starts September 21st!✳New Cohort starts September 21st!✳New Cohort starts September 21st!✳New Cohort starts September 21st!✳New Cohort starts September 21st!✳New Cohort starts September 21st!✳New Cohort starts September 21st!✳New Cohort starts September 21st!✳New Cohort starts September 21st!✳New Cohort starts September 21st!✳New Cohort starts September 21st!✳New Cohort starts September 21st!✳
PalmTechnIQ
Cybersecurity

A cybersecurity roadmap for complete beginners

Most roadmaps list a hundred topics and leave you no wiser about where to start. This one is ordered, and each stage says what 'done' looks like.

Updated 2 October 2026

How to use this roadmap

Move on when you can pass the test at the end of a stage, not when a number of weeks has gone by. People start from very different places, so any calendar would be wrong for most readers. Someone who already works in IT support will clear the first two stages quickly. Someone starting fresh should give them time.

Stage 1 — Networking fundamentals

Everything in security happens over a network, so this comes first. You are learning how machines find and talk to each other, because attacks and defences are both built on those mechanics. If you want a guided version, our Ethical Hacking course opens with the OSI model, then subnetting and IP addressing.

You are done with this stage when you can:

  • Explain, step by step, what happens when you type a web address into a browser.
  • Describe the OSI model in your own words and say which layer a given problem sits in.
  • Work out the subnet for a given IP range and mask.

Common questions

Do I need to know programming to start in cybersecurity?

Not to begin. Networking, operating systems and security fundamentals come first and need no programming. Basic scripting becomes useful later, for automating repetitive checks, and you do not need to be a developer to benefit from it.

Which operating system should I learn first?

Linux. Most security tooling runs on it, and working at the command line teaches you how the system works. Pick up the Windows basics alongside it, since most organisations run Windows.

How do I know when I am ready to apply for jobs?

Judge by evidence, not by the calendar. When you can pass the test for the first four stages and have a few written-up exercises to show, start applying. Nobody ever feels fully ready, and applications teach you what the market actually asks for.

Learn this with a tutor

Ethical Hacking StarterBEGINNEREthical Hacking & Penetration Testing for Beginners and IntermediateINTERMEDIATE
All cybersecurity guides

Stay Updated

Get the latest courses, features, and learning tips delivered to your inbox

PalmTechnIQ

Changing education with AI-powered learning, expert mentorship, and cutting-edge technology. Your journey to success starts here.

support@palmtechniq.com
+234 (807) 956-8910
Lagos, NG

platform

  • Courses
  • Learn Cybersecurity
  • Become a Tutor
  • Mentor And Earn

features

  • AI Interview Coach
  • Verify Certificate
  • Live Mentorship
  • Bootcamps

company

  • About Us
  • Blog

support

  • Help Center
  • Contact Us
  • Privacy Policy
  • Terms of Service
©2026 PalmTechnIQ. Made withfor learners worldwide
Explain what a port is, and the difference between TCP and UDP.

Stage 2 — Operating systems and the command line

Most security tools run on Linux, and most targets run Windows or Linux, so you need to be comfortable in both. Start with Linux, because the command line teaches you how the system really works.

You are done with this stage when you can:

  • Move around the file system and create, copy and delete files from the terminal.
  • Read and change file permissions, and explain what they allow.
  • Manage users, processes and services.
  • Chain simple commands together to search through a large file.
  • Describe, at a basic level, how users, services and the registry work on Windows.

Stage 3 — Security fundamentals

Now the concepts: confidentiality, integrity and availability; authentication versus authorisation; encryption at rest and in transit; and the common attack types — phishing, malware, injection, credential theft — alongside the defences for each. The OWASP lists of common web vulnerabilities are a good map for the web side.

You are done with this stage when you can:

  • Explain confidentiality, integrity and availability with a real example for each.
  • Describe how a typical phishing attack unfolds and name three points where it could be stopped.
  • Say why hashing is not the same as encryption.
  • Name the main categories of web application vulnerability and give an example of each.

Stage 4 — Hands-on practice

Reading is not enough. Build a small lab, attack your own machines, and write down what you learn. Our Ethical Hacking Starter covers this stage's core skills: footprinting, network scanning, DNS and SNMP enumeration, and vulnerability assessment with Nikto and Nessus.

Only practise on systems you own or on purpose-built practice targets. Your write-ups become your portfolio.

You are done with this stage when you can:

  • Set up a lab with one virtual machine to attack from and one to attack.
  • Use a scanner such as Nmap against your own lab and explain every line of its output.
  • Take an unfamiliar practice machine, enumerate it methodically, and explain what you found and why it matters.
  • Show a few written-up exercises to someone else and have them follow your reasoning.

Stage 5 — Specialising

Only now choose a direction, because by this point you have seen enough to choose with some basis. The main branches are:

  • Defensive work: monitoring, detection and incident response.
  • Offensive work: penetration testing and application security.
  • Governance, risk and compliance: policy, audits and controls.
  • Cloud security: securing infrastructure on the major cloud platforms.

Choosing, and what 'done' looks like here

Try a little of each branch before committing, then deepen with the certification that matches the role. You are done with the roadmap when you can name the role you are aiming at and list the skills its postings ask for that you do not yet have. That list is your next study plan.