The pathway
How you actually get there, here
How you become one varies far more by country than what one does. This is the UK route. Most people take one of these ways in; the right one depends on where you're starting from.
- 1
IT Support / Helpdesk Specialist
1-2 yearsSkills to master
- Troubleshooting basic IT issues, understanding user behaviour, basic networking, customer service. This gives you a solid grasp of how IT systems actually work day-to-day.
You're ready to move on when
- You're the 'go-to' person for tricky technical problems in your current role.
- You've shown a keen interest in security, maybe by flagging suspicious emails or suggesting security improvements.
- You've taken some personal time to study security fundamentals or get a basic certification.
- 2
Cyber Security Apprenticeship / Bootcamp Graduate
0-1 yearSkills to master
- Foundational security concepts, basic networking, some scripting, exposure to security tools. These programmes are designed to give you a direct route into roles like this.
You're ready to move on when
- You've successfully completed all modules and projects of your programme.
- You can articulate core security principles and demonstrate basic tool usage.
- You've built a small portfolio of security-related projects or labs.
- 3
Self-Taught Enthusiast with Portfolio
Variable (often 1-3 years of dedicated self-study)Skills to master
- Dedication to learning, practical application of security concepts (e.g., home lab, CTF participation), strong problem-solving, resourcefulness.
You're ready to move on when
- You can clearly demonstrate practical security skills through personal projects, GitHub repos, or CTF write-ups.
- You've immersed yourself in security communities and can discuss current threats and technologies.
- You've likely achieved one or more entry-level security certifications through self-study.