Video summary

stop wasting your time in cybersecurity

Main summary

Key takeaways

Educational

Main ideas / lessons conveyed

  • The speaker shares their personal history of trying to break into cybersecurity, including being unemployed for ~1.5 years, before eventually getting hired without actively applying.
  • Core message: To enter cybersecurity faster and more effectively, prioritize:
    • foundational skills,
    • practical IT/admin experience,
    • networking (the skill),
    • and public proof of learning (posting projects/writeups).
  • The speaker argues against spending heavily on outdated academic content, and instead recommends a pathway built on a structured roadmap plus hands-on practice.
  • Cybersecurity is framed as not truly “entry-level.” A realistic entry path is through help desk, and especially Microsoft 365 (M365) administration, alongside Windows/AD/security fundamentals.
  • Networking and visibility (LinkedIn/blog/CTFs/projects) are presented as major drivers of interviews and jobs.

Key takeaway repeated: don’t just learn—make it visible and connect with humans.


Suggested pathway / methodology (checklist style)

1) Reconsider formal education approach

If starting over, the speaker would skip:

  • Boot camp (in their opinion)
  • Bachelor’s degree (in their opinion, college content is “outdated”/wasteful)

They still emphasize building skills through structured learning resources and hands-on labs.


2) Use a structured learning roadmap (roadmap.sh)

  • Use the cybersecurity roadmap on roadmap.sh (the speaker suggests searching for “cyber roadmap”).
  • Follow it step-by-step and check items off as you learn.
  • The speaker claims it covers “security plus”-like concepts more clearly.

Fundamentals to cover (as listed)

  • Cybersecurity fundamentals
  • Fundamental IT skills
  • Computer hardware components
  • Connection types and their functions
  • OS-independent troubleshooting
  • Basics of popular software suites
  • Basics of computer networking (explicitly emphasized), including:
    • Subnetting (the speaker admits they didn’t know this and calls it important)
    • Public vs. private IP addresses
    • localhost
    • subnet mask
    • default gateway
    • CIDR
    • terminology: DHCP, DNS, IP addressing concepts
    • VLAN concepts
    • Router vs. switch
    • Network topologies
    • How packets are made and how OSI layers stack
    • OSI model (emphasized as “extreme clutch”)
  • Troubleshooting tools:
    • nslookup
    • ipconfig
    • ping
    • dig
  • Authentication methodologies:
    • Kerberos
    • LDAP
    • SSO
    • RADIUS
  • More security-focused topics (as suggested by the roadmap):
    • DDoS
    • Evil twin
    • Deauth/deauthentication attacks (“Deoth” in subtitles)
    • Attack concepts and kill chain
    • Diamond model
    • Tool/term references like “Parid OS” and “Cali” (likely related to Kali Linux and adjacent pen-testing topics)

Cloud concepts to include (as stated)

  • S3
  • Dropbox
  • Google Drive
  • OneDrive
  • AWS
  • GCP
  • Azure

Additional roadmaps the speaker recommends

Explore other roadmaps on the same site, such as:

  • Role-based (examples mentioned):
    • AI engineer
    • Software architect
    • Game developer
    • Technical writer
  • Skill-based (examples mentioned):
    • Prompt engineering
    • prompt injection
    • hallucinations
    • model weights/parameters
    • AI red teaming roadmap
    • zero-shot prompting
    • chain-of-thought prompting

The speaker notes they got “off track” into AI, but still praises the site overall.


3) Certification strategy (baseline first)

  • Strong recommendation: Security+ as a base certification.
  • Network+
    • The speaker skipped it early due to disliking networking.
    • Later, they suggest taking it—or skipping it if you can prove networking fundamentals (subnets/configs).
  • Certifications can help with HR filters and non-technical hiring.

4) Add M365 administration (the “missing” piece)

A major point: many people don’t emphasize M365 administration, but the speaker considers it crucial.

Practical M365 admin learning goals:

  • Provision users
  • Provision groups
  • Set up distribution lists
  • Reset passwords
  • Investigate phishing emails

The speaker also claims you’ll likely need help desk first, and that cybersecurity isn’t truly “entry level.”

Microsoft certification suggestion

  • Microsoft 365 Administrator exam (used as a way to prove M365 admin skills; the speaker hasn’t taken it personally, but it’s seen as relevant).

5) Consider (but don’t overinvest in) A+

  • A+ is described as “vendor agnostic.”
  • The speaker personally hasn’t taken it and suggests it’s likely not worth the money if you’re already doing the work requiring it.
  • Suggested content source:
    • Professor Messer videos

6) Use hands-on training platforms (learning + proof)

  • TryHackMe (recommended for beginners moving toward intermediate):
    • Lessons
    • CTFs (capture the flag)
    • Learning path certifications/badges
  • Hack the Box (recommended after you build comfort):
    • Similar style but more advanced CTFs/learning

The speaker includes a note about using their referral link for Hack the Box (kickback).


7) Take notes and publish them publicly

  • Take notes of everything you do:
    • labs, CTFs, learnings, certifications
  • Post your work to:
    • LinkedIn
    • your own blog

Examples mentioned:

  • Hack the Box / TryHackMe writeups
  • Badges/certifications earned
  • Projects

The speaker stresses: knowledge-sharing creates visibility.


8) Network aggressively (job-getting strategy)

The speaker claims they’ve never gotten a job through applying; instead, roles came from:

  • online networking
  • social media visibility
  • referrals
  • in-person networking

Suggested channels:

  • Discord
  • Conferences
  • Defcon (explicitly mentioned)
  • Local meetups

Guidance:

  • Network like your job depends on it
  • Build connections by talking to people and showing passion

9) Choose “practical” skills over purely flashy security topics (initial focus)

If starting over, the speaker would prioritize:

  • help desk
  • M365 administration
  • Windows hardening
  • Windows security
  • Active Directory (AD) security

Rationale: build security-adjacent capability first (help desk/security/IT/admin), then move toward more cybersecurity-specific roles.

They advise not focusing too early on highly competitive/less practical areas like:

  • pen testing
  • red teaming

Outcome / example outcome from the speaker

  • The speaker posted learning content publicly and got noticed by a CEO.
  • The CEO invited them to interview, which led to their first cybersecurity job.
  • Key takeaway repeated: make your learning visible and connect with humans.

Speakers / sources featured

Speaker

  • “Maddie” (referred to in subtitles as Maddie; likely the video creator)

Named sources / platforms

  • roadmap.sh
  • Professor Messer
  • TryHackMe
  • Hack the Box
  • LinkedIn
  • Medium
  • Microsoft 365 Administrator (exam mentioned)
  • Discord
  • Defcon
  • OSI model (explicitly mentioned)
  • Google Drive / OneDrive / Dropbox
  • AWS / GCP / Azure

Other people mentioned

  • “CEO” (not named)
  • “non-technical hiring manager” (not named)

Original video