The pathway
How you actually get there, here
How you become one varies far more by country than what one does. This is the UK route. Most people take one of these ways in; the right one depends on where you're starting from.
- 1
IT Helpdesk / Technical Support
1-2 yearsSkills to master
- Troubleshooting, understanding user behaviour, basic network diagnostics, customer service, ticket management.
You're ready to move on when
- You're consistently solving complex user issues, not just password resets.
- You've shown an interest in security-related tickets and escalated potential threats.
- You've taken the initiative to learn about security tools or concepts in your own time.
- 2
University Graduate (Cyber Security/Computer Science)
0-1 year (post-graduation)Skills to master
- Applying theoretical knowledge to practical scenarios, understanding corporate IT environments, professional communication.
You're ready to move on when
- You've completed relevant modules or projects in cyber security.
- You've engaged in internships or extracurricular security activities.
- You can articulate how your academic knowledge applies to real-world security challenges.
- 3
Self-Taught / Enthusiast
Varies (often 1-3 years of dedicated self-study)Skills to master
- Practical application of security tools, strong understanding of attack/defence concepts, disciplined learning, problem-solving.
You're ready to move on when
- You have a portfolio of personal security projects (e.g., home lab, CTF achievements, open-source contributions).
- You've earned industry certifications like CompTIA Security+.
- You can clearly explain complex security concepts and demonstrate hands-on skills.