Video summary
stop wasting your time in cybersecurity
Main summary
Key takeaways
Main ideas / lessons conveyed
- The speaker shares their personal history of trying to break into cybersecurity, including being unemployed for ~1.5 years, before eventually getting hired without actively applying.
- Core message: To enter cybersecurity faster and more effectively, prioritize:
- foundational skills,
- practical IT/admin experience,
- networking (the skill),
- and public proof of learning (posting projects/writeups).
- The speaker argues against spending heavily on outdated academic content, and instead recommends a pathway built on a structured roadmap plus hands-on practice.
- Cybersecurity is framed as not truly “entry-level.” A realistic entry path is through help desk, and especially Microsoft 365 (M365) administration, alongside Windows/AD/security fundamentals.
- Networking and visibility (LinkedIn/blog/CTFs/projects) are presented as major drivers of interviews and jobs.
Key takeaway repeated: don’t just learn—make it visible and connect with humans.
Suggested pathway / methodology (checklist style)
1) Reconsider formal education approach
If starting over, the speaker would skip:
- Boot camp (in their opinion)
- Bachelor’s degree (in their opinion, college content is “outdated”/wasteful)
They still emphasize building skills through structured learning resources and hands-on labs.
2) Use a structured learning roadmap (roadmap.sh)
- Use the cybersecurity roadmap on roadmap.sh (the speaker suggests searching for “cyber roadmap”).
- Follow it step-by-step and check items off as you learn.
- The speaker claims it covers “security plus”-like concepts more clearly.
Fundamentals to cover (as listed)
- Cybersecurity fundamentals
- Fundamental IT skills
- Computer hardware components
- Connection types and their functions
- OS-independent troubleshooting
- Basics of popular software suites
- Basics of computer networking (explicitly emphasized), including:
- Subnetting (the speaker admits they didn’t know this and calls it important)
- Public vs. private IP addresses
- localhost
- subnet mask
- default gateway
- CIDR
- terminology: DHCP, DNS, IP addressing concepts
- VLAN concepts
- Router vs. switch
- Network topologies
- How packets are made and how OSI layers stack
- OSI model (emphasized as “extreme clutch”)
- Troubleshooting tools:
nslookupipconfigpingdig
- Authentication methodologies:
- Kerberos
- LDAP
- SSO
- RADIUS
- More security-focused topics (as suggested by the roadmap):
- DDoS
- Evil twin
- Deauth/deauthentication attacks (“Deoth” in subtitles)
- Attack concepts and kill chain
- Diamond model
- Tool/term references like “Parid OS” and “Cali” (likely related to Kali Linux and adjacent pen-testing topics)
Cloud concepts to include (as stated)
- S3
- Dropbox
- Google Drive
- OneDrive
- AWS
- GCP
- Azure
Additional roadmaps the speaker recommends
Explore other roadmaps on the same site, such as:
- Role-based (examples mentioned):
- AI engineer
- Software architect
- Game developer
- Technical writer
- Skill-based (examples mentioned):
- Prompt engineering
- prompt injection
- hallucinations
- model weights/parameters
- AI red teaming roadmap
- zero-shot prompting
- chain-of-thought prompting
The speaker notes they got “off track” into AI, but still praises the site overall.
3) Certification strategy (baseline first)
- Strong recommendation: Security+ as a base certification.
- Network+
- The speaker skipped it early due to disliking networking.
- Later, they suggest taking it—or skipping it if you can prove networking fundamentals (subnets/configs).
- Certifications can help with HR filters and non-technical hiring.
4) Add M365 administration (the “missing” piece)
A major point: many people don’t emphasize M365 administration, but the speaker considers it crucial.
Practical M365 admin learning goals:
- Provision users
- Provision groups
- Set up distribution lists
- Reset passwords
- Investigate phishing emails
The speaker also claims you’ll likely need help desk first, and that cybersecurity isn’t truly “entry level.”
Microsoft certification suggestion
- Microsoft 365 Administrator exam (used as a way to prove M365 admin skills; the speaker hasn’t taken it personally, but it’s seen as relevant).
5) Consider (but don’t overinvest in) A+
- A+ is described as “vendor agnostic.”
- The speaker personally hasn’t taken it and suggests it’s likely not worth the money if you’re already doing the work requiring it.
- Suggested content source:
- Professor Messer videos
6) Use hands-on training platforms (learning + proof)
- TryHackMe (recommended for beginners moving toward intermediate):
- Lessons
- CTFs (capture the flag)
- Learning path certifications/badges
- Hack the Box (recommended after you build comfort):
- Similar style but more advanced CTFs/learning
The speaker includes a note about using their referral link for Hack the Box (kickback).
7) Take notes and publish them publicly
- Take notes of everything you do:
- labs, CTFs, learnings, certifications
- Post your work to:
- your own blog
Examples mentioned:
- Hack the Box / TryHackMe writeups
- Badges/certifications earned
- Projects
The speaker stresses: knowledge-sharing creates visibility.
8) Network aggressively (job-getting strategy)
The speaker claims they’ve never gotten a job through applying; instead, roles came from:
- online networking
- social media visibility
- referrals
- in-person networking
Suggested channels:
- Discord
- Conferences
- Defcon (explicitly mentioned)
- Local meetups
Guidance:
- Network like your job depends on it
- Build connections by talking to people and showing passion
9) Choose “practical” skills over purely flashy security topics (initial focus)
If starting over, the speaker would prioritize:
- help desk
- M365 administration
- Windows hardening
- Windows security
- Active Directory (AD) security
Rationale: build security-adjacent capability first (help desk/security/IT/admin), then move toward more cybersecurity-specific roles.
They advise not focusing too early on highly competitive/less practical areas like:
- pen testing
- red teaming
Outcome / example outcome from the speaker
- The speaker posted learning content publicly and got noticed by a CEO.
- The CEO invited them to interview, which led to their first cybersecurity job.
- Key takeaway repeated: make your learning visible and connect with humans.
Speakers / sources featured
Speaker
- “Maddie” (referred to in subtitles as Maddie; likely the video creator)
Named sources / platforms
- roadmap.sh
- Professor Messer
- TryHackMe
- Hack the Box
- Medium
- Microsoft 365 Administrator (exam mentioned)
- Discord
- Defcon
- OSI model (explicitly mentioned)
- Google Drive / OneDrive / Dropbox
- AWS / GCP / Azure
Other people mentioned
- “CEO” (not named)
- “non-technical hiring manager” (not named)