Most roadmaps list a hundred topics and leave you no wiser about where to start. This one is ordered, and each stage says what 'done' looks like.
Updated 2 October 2026
Move on when you can pass the test at the end of a stage, not when a number of weeks has gone by. People start from very different places, so any calendar would be wrong for most readers. Someone who already works in IT support will clear the first two stages quickly. Someone starting fresh should give them time.
Everything in security happens over a network, so this comes first. You are learning how machines find and talk to each other, because attacks and defences are both built on those mechanics. If you want a guided version, our Ethical Hacking course opens with the OSI model, then subnetting and IP addressing.
You are done with this stage when you can:
Not to begin. Networking, operating systems and security fundamentals come first and need no programming. Basic scripting becomes useful later, for automating repetitive checks, and you do not need to be a developer to benefit from it.
Linux. Most security tooling runs on it, and working at the command line teaches you how the system works. Pick up the Windows basics alongside it, since most organisations run Windows.
Judge by evidence, not by the calendar. When you can pass the test for the first four stages and have a few written-up exercises to show, start applying. Nobody ever feels fully ready, and applications teach you what the market actually asks for.
Most security tools run on Linux, and most targets run Windows or Linux, so you need to be comfortable in both. Start with Linux, because the command line teaches you how the system really works.
You are done with this stage when you can:
Now the concepts: confidentiality, integrity and availability; authentication versus authorisation; encryption at rest and in transit; and the common attack types — phishing, malware, injection, credential theft — alongside the defences for each. The OWASP lists of common web vulnerabilities are a good map for the web side.
You are done with this stage when you can:
Reading is not enough. Build a small lab, attack your own machines, and write down what you learn. Our Ethical Hacking Starter covers this stage's core skills: footprinting, network scanning, DNS and SNMP enumeration, and vulnerability assessment with Nikto and Nessus.
Only practise on systems you own or on purpose-built practice targets. Your write-ups become your portfolio.
You are done with this stage when you can:
Only now choose a direction, because by this point you have seen enough to choose with some basis. The main branches are:
Try a little of each branch before committing, then deepen with the certification that matches the role. You are done with the roadmap when you can name the role you are aiming at and list the skills its postings ask for that you do not yet have. That list is your next study plan.