Cyber security is one of the few high-demand fields where skills matter more than a specific degree. If you can prove you can defend and test systems, employers will talk to you. Here is a practical roadmap for India.
The learning path (in order)
- Foundations: networking (TCP/IP, DNS, HTTP), Linux basics, and how the web works.
- Security basics: common attacks (phishing, malware, misconfig) and defences.
- Ethical hacking & web-app security: the OWASP Top 10, hands-on labs, and tools like Nmap, Burp Suite, Wireshark.
- Specialise: pick a lane — SOC/blue-team, VAPT/penetration testing, or cloud security.
- Certify (optional but helpful): a recognised certification plus real lab work.
Build proof, not just theory
- Do hands-on labs and capture-the-flag (CTF) challenges.
- Write short blogs or notes on what you practised — this becomes your portfolio.
- Contribute to a home lab; document a small VAPT of a test app.
Entry roles to target
SOC analyst (L1), junior penetration tester, security support, and IT-security intern are realistic first jobs. From there you grow into VAPT, incident response, or cloud security.
FAQ
Do I need a computer-science degree?
No. A degree helps but is not required. Demonstrable, hands-on skills and a portfolio matter most for entry roles.
How long does it take to become job-ready?
With consistent daily practice, many learners reach entry-level readiness in several months. The key is hands-on labs, not just watching videos.
Which should I learn first — networking or hacking?
Networking and Linux first. Ethical hacking makes far more sense once you understand how systems talk to each other.

