Video summary
How I Would Learn Cyber Security If I Could Start Over in 2026 (6 Month Plan)
Main summary
Key takeaways
6-Month Cybersecurity Job Plan (Key Wellness + Productivity/Strategy Highlights)
Step 1: Build your foundation (learn broadly + start hands-on immediately)
- Learn what cybersecurity is and what roles actually do: protecting data from theft/destruction/unauthorized access.
-
Use four foundational trainings/certificates in sequence:
- Google Cybersecurity Professional Certificate
- Broad intro across OS, networking, IT, and risk management
- Includes hands-on labs (Linux, MySQL, Python) early—don’t wait to “be ready”
- GRC Mastery
- Understand cybersecurity from a business/compliance/risk perspective
- Covers risk management, audits, frameworks (NIST, ISO 27001)
- Includes practical assessments/case studies
- Results in completion certificate + ISO 27001 lead auditor certificate
- TryHackMe (Security Analyst / “SAL 1”)
- Built for zero knowledge and revisits fundamentals
- Includes a SOC-simulator workflow (assign tickets, investigate, respond)
- CompTIA Security+ (later in the process)
- Positioned as easier to pass because you’ll have context after the first three courses
- Suggested prep resource: CompTIA Security+ Sybex book
- Google Cybersecurity Professional Certificate
-
Mindset/workflow tip
- It’s normal to “forget” in a new field—use repetition via the plan rather than panic-memorization.
- Don’t force a rigid deadline; use your time efficiently (6 months is the goal, not a failure condition).
Step 2: Build a job-ready resume + apply consistently (productivity + anxiety management)
-
Don’t treat certificates as the finish line.
- A common failure: spending only ~5–10 minutes on a resume and applying immediately.
-
Resume strategy (use a structured template, then tailor)
- Professional summary: short statement of your target interest (no life story)
- Training/certifications section first (for candidates without experience)
- Education only if you have a degree
- Practical projects: brief 1-sentence descriptions (not long)
- Experience section: can be minimal, but highlight transferable, relevant parts
- Template source mentioned: unixgu.com/free (free cyber resume template)
-
Job application strategy
- Apply after GRC Mastery so you can better represent your understanding.
- Use a simple job-search filter keyword:
- Search LinkedIn Jobs for “cyber”
- Apply even when postings ask for experience:
- Treat your labs as evidence you can do the work + learn quickly.
- Daily consistency:
- Spend at least 30 minutes every day applying (not just weekends).
-
Wellness/mental resilience
- Rejection is normal—expect it and use interviews as learning data.
- Don’t spiral into beliefs like “everyone wants degrees” or “I’m not good enough.”
Step 3: Use AI strategically (reduce fear; become more competitive)
- Key idea: AI won’t eliminate cybersecurity jobs, but it will change some specializations.
- Two ways to stay resilient:
- Become a generalist (avoid being a “one-trick pony”)
- Learn AI and apply it to your cybersecurity workflow
-
Learning resource mentioned:
- Anthropic/Clo training library (free; suggested can be completed in a weekend)
-
Timing note
- Don’t jump into “AI for cybersecurity” before you understand cybersecurity fundamentals.
Step 4: Continue learning + keep applying until you land the role (avoid random study)
After foundations/certs, focus on two ongoing priorities:
- Apply consistently
- Keep learning
Learning areas (not random):
- Advanced blue teaming skills
- Suggested certs: CyberDefenders CCDL1 → CCDL2 (incident response, forensics)
- Also: Hack The Box CDSA
- Optional practice: Let’s Defend SOC path (to reinforce prior SOC skills)
- Cloud security
- Azure: SC900 → SC200 → aim for Azure Engineer Associate
- AWS: Cloud Practitioner → Solutions Architect → AWS Security Specialty
- Offensive security (optional)
- EJPT → TryHackMe PT1 → then harder paths (e.g., OSCP-level or equivalent)
- Mentioned alternatives: Hack The Box CPTS
“Three Deadly Mistakes” (motivation + anti-procrastination)
- Mistake #1: Thinking it’s easy / wanting the minimum
- Don’t aim for “absolute bare minimum.” The plan is simple but requires effort, consistency, and hard work.
- Mistake #2: Getting confused by different opinions
- Ignore advice from people without real cybersecurity experience (treat it as procrastination/noise).
- Mistake #3: Can’t handle rejection
- Expect rejection as part of the process; don’t turn it into doom narratives or “bad news” scrolling.
- Use rejection as motivation to keep improving and applying.
Presenters / Sources Mentioned
- Anthropic (training library for AI, mentioned in context of “Clo”)
- Cybex (CompTIA Security+ book recommendation: CompTIA Security Plus Cybex book)
- Exemplar Global (recognition mentioned for ISO 27001 lead auditor credential)
- Google (Google Cybersecurity certificate)
- GRC Mastery (GRC training platform)
- TryHackMe (SAL 1 / SOC-simulator training)
- CompTIA (Security+ exam)
- LinkedIn (job search/applying platform)
- unixgu.com (free cyber resume template)
- CyberDefenders (CCDL certifications)
- Hack The Box (CDSA and CPTS; also PT1 is TryHackMe)
- Let’s Defend (SOC Analyst path / practice)
- Microsoft Azure (SC900, SC200, Azure Engineer Associate)
- Amazon AWS (Cloud Practitioner, Solutions Architect, AWS Security Specialty)
- Indeed, Dice, Seek.com.au (job boards mentioned as secondary platforms)
- NIST (framework referenced)
- ISO 27001 (framework referenced)
- OSCP / Offensive Security (referenced as a typical next step for pentesting)