The pathway
How you actually get there, here
How you become one varies far more by country than what one does. This is the UK route. Most people take one of these ways in; the right one depends on where you're starting from.
- 1
University Graduate (Computer Science/Cyber Security)
0-1 year post-graduationSkills to master
- Translate academic knowledge into practical application, learn specific IoT protocols and hardware interfaces, develop strong documentation habits.
You're ready to move on when
- Completed relevant final year projects or dissertations in security.
- Achieved good grades in modules related to networking, operating systems, or low-level programming.
- Participated in university CTF teams or security clubs.
- 2
Self-Taught Hacker/Bug Bounty Hunter
1-2 years of self-study/practical experienceSkills to master
- Formalise testing methodologies, improve reporting standards, learn to work within a structured team environment, understand business risk vs. technical risk.
You're ready to move on when
- Demonstrable portfolio of personal security projects (e.g., GitHub repos, blog posts).
- Successful submissions to bug bounty programmes (even small ones).
- Active participation in online security communities and forums.
- 3
IT Support/Network Engineer Transition
2-3 years in previous role + 6-12 months focused security studySkills to master
- Deep dive into embedded systems and hardware security, learn reverse engineering tools, shift from 'keeping things running' to 'breaking things securely'.
You're ready to move on when
- Strong existing knowledge of networking and system administration.
- Completed entry-level security certifications (e.g., CompTIA Security+, CCNA Security).
- Demonstrated initiative to learn security concepts outside of core job duties.


