Cyber Security Roadmap: 14 Weeks From Networking Basics to Blue Team Skills

14 weeks at 8-10 hours per week · Beginner to SOC-analyst entry level

Cyber security fails as a self-study subject when people start with tools instead of fundamentals. This roadmap fixes the order: networking and Linux first, attacker techniques second, defensive workflows last. Each week ends in a lab you can rerun and describe in an interview.

What you will be able to do

  • Read and reason about network traffic at the packet level
  • Operate Linux confidently from the command line
  • Identify and explain the OWASP Top 10 with working demonstrations
  • Apply cryptography correctly for data at rest and in transit
  • Triage alerts and write clear incident notes like a SOC analyst

Before you start

  • Comfort installing software and using a virtual machine
  • Basic scripting helps but is taught in week 6

The week-by-week plan

Already know an early week? Start at your first real gap instead of week one — the projects still build on each other from wherever you join.

Week 1: How networks work

  • OSI and TCP/IP models
  • IP addressing and subnets
  • DNS
  • Ports and protocols

Project: Map your home network and document every device and open port

Week 2: Packets in practice

  • Wireshark
  • TCP handshakes
  • HTTP vs HTTPS traffic
  • ARP and spoofing

Project: Capture and annotate a full login flow

Week 3: Linux essentials

  • Filesystem and permissions
  • Users and groups
  • Processes and services
  • Logs

Project: Harden a fresh Linux VM and write the checklist

Week 4: Windows and Active Directory basics

  • Event logs
  • Users and policies
  • PowerShell basics
  • Common misconfigurations

Project: Audit a Windows VM's local policy

Week 5: Threats and attacker mindset

  • MITRE ATT&CK
  • Phishing and social engineering
  • Malware categories
  • Kill chain

Project: Write an attack narrative for a simulated breach

Week 6: Scripting for security

  • Python basics
  • Parsing logs
  • Automating scans
  • Regular expressions

Project: Script that flags suspicious lines in an auth log

Week 7: Web application security

  • HTTP fundamentals
  • Injection
  • Broken authentication
  • XSS and CSRF

Project: Exploit and then patch a deliberately vulnerable app

Week 8: OWASP Top 10 deep dive

  • Access control failures
  • Security misconfiguration
  • Vulnerable dependencies
  • SSRF

Project: Full write-up of five findings with severity ratings

Week 9: Cryptography applied

  • Hashing vs encryption
  • Symmetric and asymmetric keys
  • TLS certificates
  • Password storage

Project: Build a small encrypted note store and justify each choice

Week 10: Vulnerability management

  • Scanning
  • CVSS scoring
  • Patch prioritisation
  • Reporting

Project: Scan a lab network and produce a prioritised remediation plan

Week 11: Cloud and identity security

  • Shared responsibility
  • IAM policies
  • Storage exposure
  • Logging in the cloud

Project: Find and fix three misconfigurations in a sandbox cloud account

Week 12: SOC workflows

  • SIEM basics
  • Alert triage
  • False positives
  • Escalation

Project: Triage a day of simulated alerts with written verdicts

Week 13: Incident response

  • Preparation and detection
  • Containment
  • Eradication and recovery
  • Post-incident review

Project: Run a tabletop incident and publish the report

Week 14: Career preparation

  • Certification landscape
  • Home lab presentation
  • Interview scenarios
  • Reporting writing practice

Project: Portfolio of three labs plus one full incident report

Tools you will use

WiresharkLinuxPythonBurp SuiteNmapSplunk or ElasticVirtual machines

Where this roadmap leads

SOC Analyst (Tier 1)

The most common entry point — weeks 12-13 map directly to the day job.

Application Security Associate

Weeks 7-9 plus coding experience make this reachable.

IT Security Administrator

Weeks 3-4 and 10-11 are the core skills hiring managers test.

Frequently asked questions

Can I learn cyber security without an IT background?

Yes, provided you do weeks 1-4 properly. Networking and operating system fundamentals are what separate people who can investigate an alert from people who can only run a tool.

Which certification should I start with?

Most beginners start with a foundational security certification after week 10, once the concepts are already familiar. Certifications validate knowledge faster than they teach it.

Is ethical hacking the same as cyber security?

No. Offensive testing is one specialisation. Most entry-level hiring is defensive — monitoring, triage and hardening — which is why this roadmap ends on the blue team side.

Do I need a powerful laptop?

Anything that can run two virtual machines with 8 GB of RAM is enough for every lab in this plan.

Want this plan scheduled for you?

Pathlix turns roadmaps like this into daily goals sized to your study hours, tracks your streak, and tests you every week.

Other roadmaps