The pathway
How you actually get there, here
How you become one varies far more by country than what one does. This is the UK route. Most people take one of these ways in; the right one depends on where you're starting from.
- 1
IT Support / Helpdesk Specialist
1-2 yearsSkills to master
- Troubleshooting, basic network understanding, customer service, incident response (even if just password resets), and an early exposure to security issues.
You're ready to move on when
- You're consistently resolving complex technical issues for users.
- You've shown an interest in the 'why' behind security-related tickets (e.g., locked accounts, suspicious emails).
- You've taken initiative to learn more about cybersecurity outside your core role.
- 2
University Graduate (Cybersecurity/Computer Science)
0-1 year (post-graduation)Skills to master
- Theoretical understanding of security principles, programming fundamentals, data structures, and perhaps some project work in security.
You're ready to move on when
- Strong academic performance in relevant modules.
- Completed a dissertation or major project with a cybersecurity focus.
- Participated in CTF (Capture The Flag) competitions or security clubs.
- 3
Apprenticeship in IT/Cybersecurity
2-3 years (during/post-apprenticeship)Skills to master
- Practical application of IT skills, exposure to enterprise environments, and specific security training provided by the apprenticeship.
You're ready to move on when
- Successful completion of apprenticeship modules and projects.
- Positive feedback from mentors and supervisors on your technical aptitude and work ethic.
- Demonstrated ability to work effectively in a professional setting.


