Last updated: September 2026 | By the LearnPath Team
Quick Answer: How to Learn Cybersecurity from YouTube in 2026
Yes: you can learn enough cybersecurity from YouTube to reach an entry-level SOC analyst or junior pentester role, using channels like NetworkChuck, Professor Messer, and IppSec alongside hands-on labs on TryHackMe and HackTheBox. Plan on 6-12 months of consistent study at 1-2 hours a day to go from zero to interview-ready.
Demand remains real: ISC2's 2024 Cybersecurity Workforce Study put the gap between the security staff organizations say they need and the staff they actually have at 4,763,963 people worldwide (ISC2 did not publish an updated gap estimate in its 2025 study), and Pluralsight's 2025 Tech Skills Report lists cybersecurity among the top three tech skills gaps in IT, alongside cloud and AI/ML - 48% of IT professionals report abandoning a project for lack of the right skills. On LearnPath's own product data, pulled in September 2026, learners have opened 163 cybersecurity paths and queued 641 videos, but only 17 videos have actually been finished, spread across just 11 of those 163 paths. The bottleneck was never access to content. It's finishing what you start.
The hard part is not finding free content - YouTube has more cybersecurity tutorials than any human could watch. The hard part is sequencing them, knowing what to skip, and proving your skills on the way to a paying job.
This post gives you the channels, the roadmap, and the practical guide to going from zero to SOC analyst (or junior pentester) using only free content, checked and re-verified as of September 2026, including which channels are still active.
Why Cybersecurity Is Different from Other Subjects on YouTube
Cybersecurity differs from most YouTube subjects because the technical content ages fast, hiring splits into an easy entry tier and a much harder tier above it, and knowledge without hands-on practice does not transfer to a job. Unlike a linear "watch videos, get hired" path, cybersecurity requires sequencing, current sources, and constant lab practice alongside every video.
First, it is a moving target. A buffer overflow tutorial from 2019 may walk you through techniques that modern OS protections have neutralized. A SOC tooling video from 2018 will reference Splunk syntax that has changed twice since. The half-life of technical depth here is shorter than in Python or React.
Second, hiring is bimodal. Entry-level defensive roles (SOC tier 1, IT security analyst, junior pentester) have low formal requirements and are reachable from YouTube plus certs plus labs. But the pay tier above them often requires either a degree, a security clearance, or specialist depth that takes years to build. Plan for the entry tier as a stepping stone, not a final destination.
Third, hands-on dwarfs everything else. Watching ten hours of pentesting walkthroughs without trying anything yourself is roughly equivalent to watching ten hours of cooking videos and calling yourself a chef. Cybersecurity hiring managers test, not interview. Every channel below pairs naturally with a hands-on platform: TryHackMe, HackTheBox, OverTheWire, or PicoCTF. Use them.
For a general framework on sequencing any skill from YouTube, not just cybersecurity, see our guide on how to learn anything from YouTube.
The 10 Best YouTube Channels for Cybersecurity in 2026
The ten channels below cover the full cybersecurity career arc: NetworkChuck and Professor Messer for foundations, John Hammond, The Cyber Mentors, and IppSec for offensive practice, David Bombal for career context, HackerSploit and Null Byte for tooling, LiveOverflow for exploit depth, and Computerphile for theory - ranked by usefulness from absolute beginner to mid-level professional. Seven of the ten are still actively uploading as of September 2026 (checked below); three have gone quiet for more than a year, though their back catalogs remain worth watching for specific skills. For an even broader shortlist across specialties, see our full best YouTube channels for cybersecurity in 2026 roundup.
- NetworkChuck - Best for networking, Linux, and the entry-level on-ramp. ~5.4M subscribers.
- Professor Messer - Best free CompTIA Security+ and Network+ exam prep. ~1.35M subscribers. (dormant - more than a year since last upload)
- John Hammond - Best for CTFs, malware analysis, and "see how a real practitioner thinks." ~2.16M subscribers.
- The Cyber Mentors (TCM) - Best for ethical hacking bootcamp-style learning. ~1M subscribers.
- IppSec - Best for HackTheBox walkthroughs and offensive technique mastery. ~316K subscribers.
- David Bombal - Best for networking + ethical hacking interviews and gear demos. ~3.1M subscribers.
- HackerSploit - Best for Linux, Kali, and offensive security tooling. ~1M subscribers. (dormant - more than a year since last upload)
- LiveOverflow - Best for binary exploitation, reverse engineering, and AppSec depth. ~944K subscribers.
- Null Byte (WonderHowTo) - Best for practical, project-style hacking tutorials. ~955K subscribers. (dormant - more than a year since last upload)
- Computerphile - Best for cryptography, fundamentals, and conceptual depth. ~2.63M subscribers.
Channel Comparison Table
This table puts all ten channels side by side by specialty, track, skill level, and subscriber count, plus the update this refresh adds: how recently each one has actually uploaded, so you can weigh a quiet channel's back catalog against actively maintained ones before you commit hours to it.
| Channel | Best For | Track | Level | Subscribers (Sep 2026) | Last Upload |
|---|---|---|---|---|---|
| NetworkChuck | Networking, Linux on-ramp | Foundations | Beginner | ~5.4M | 6 days ago |
| Professor Messer | Security+ / Network+ prep | Certifications | Beginner | ~1.35M | More than a year ago |
| John Hammond | CTFs, malware analysis | Offensive / DFIR | Intermediate | ~2.16M | 4 days ago |
| The Cyber Mentors | Ethical hacking bootcamp | Offensive | Beginner-Intermediate | ~1M | 10 days ago |
| IppSec | HackTheBox walkthroughs | Offensive | Intermediate-Advanced | ~316K | 2 weeks ago |
| David Bombal | Networking, ethical hacking | Foundations | Beginner-Intermediate | ~3.1M | 1 day ago |
| HackerSploit | Kali, offensive tooling | Offensive | Beginner-Intermediate | ~1M | More than a year ago |
| LiveOverflow | Binary exploitation, AppSec | Offensive / AppSec | Advanced | ~944K | 8 days ago |
| Null Byte | Project-style tutorials | Offensive | Beginner-Intermediate | ~955K | More than a year ago |
| Computerphile | Cryptography, fundamentals | Theory | All levels | ~2.63M | 4 days ago |
Currency Check: Which of These Channels Are Still Publishing
Seven of the ten channels are actively uploading; three - Professor Messer, HackerSploit, and Null Byte - have not posted in more than a year, checked via each channel's Videos tab on September 1, 2026. Messer's existing Security+ course is still exam-current and worth watching regardless; the two tooling channels matter less as their tool coverage ages.
For a learner deciding how to use this list today: treat Professor Messer's SY0-701 course as a finished textbook. It won't be updated further, but the exam objectives haven't changed either, so the free playlist is still the fastest path to the cert. For HackerSploit and Null Byte, be more skeptical - commands, tool versions, and UI screenshots in year-old videos are more likely to have drifted, so pair every technique with the tool's current docs before trusting it in a lab.
The seven active channels are the safer default for anything where currency actually matters: exam version changes, tool updates, CVE-driven content. That doesn't mean skip the dormant three - it means read their back catalogs like an archive: strong for concepts that don't move, riskier for anything that does.
The 10 Channels in Detail
Each of the ten channels below gets a short profile: what it's best for, its current status, and exactly which free video or playlist to start with, linked directly, so the next hour you spend watching goes to a video that is actually free, actually exists, and is actually the right one for where you are.
1. NetworkChuck - Best for the Entry-Level On-Ramp
NetworkChuck (~5.4M subscribers) is the channel almost every working cybersecurity professional under 30 names as their starting point. Chuck Keith covers networking, Linux, Cisco fundamentals, ethical hacking, and home lab setup with an energetic, project-driven style that genuinely makes networking fun.
For someone who has never opened a terminal, his "Linux for Hackers" and CCNA series build the foundation the rest of cybersecurity sits on top of. He also covers practical projects - building a home lab, setting up a Pi-hole, running a personal VPN - that double as portfolio pieces.
His content does sometimes lean toward "cool factor" over depth. Use NetworkChuck to fall in love with the field; pair it with Professor Messer's existing library for exam-grade rigor.
Best For: Absolute beginners who need the on-ramp from "I use a computer" to "I understand how networks and Linux work." Start With: Linux for Hackers (and everyone) // FREE Course for Beginners and FREE CCNA 200-301 // Complete Course // NetworkChuck 2025.
2. Professor Messer - The Gold Standard for Cybersecurity Certifications (Currently Dormant)
Professor Messer (~1.35M subscribers) built one of the most respected bodies of free cybersecurity certification training on YouTube, and its complete Security+, Network+, and A+ course playlists are all still online. The channel itself has not posted a new video in more than a year as of September 2026, but the existing library has not gone stale with it.
The videos are no-frills and exam-aligned. The full Security+ SY0-701 course runs to more than 120 videos covering the exam objectives, and SY0-701 is still the current exam version, so nothing here needs replacing yet.
If you only watch one channel for the first three months, watch this one anyway. The channel being quiet doesn't change that Security+ is the cert that opens almost every entry-level cyber door, and Messer's existing training is still the most efficient free path to it - just don't expect new uploads while you work through it.
Best For: Anyone planning to take CompTIA Security+ (you should), with the caveat that you're working from a finished library, not an active channel. Start With: CompTIA SY0-701 Security+ Training Course, in order.
3. John Hammond - How a Real Practitioner Thinks
John Hammond (~2.16M subscribers) is a Senior Principal Security Researcher on the Adversary Tactics team at Huntress, and was previously an instructor and curriculum developer with the US Department of Defense (Huntress author profile, 2026). His channel sits at the intersection of CTFs, malware analysis, and real-world threat hunting, and watching him work through problems is one of the fastest ways to internalize how a security professional actually thinks.
His "Day in the Life" videos and live malware analysis sessions are particularly valuable. They show the messy reality of the work - Googling unfamiliar APIs, hitting dead ends, recovering - that polished tutorials hide. This realism builds confidence that you, too, can make progress when you don't immediately know the answer.
He covers HackTheBox machines, recent CVE writeups, and PicoCTF challenges. Pair his videos with active CTF practice on those platforms.
Best For: Intermediate learners who want to see how a working professional approaches unknown problems. Start With: PicoCTF 2022 - work through the challenges yourself first, then watch how he solves each one.
4. The Cyber Mentors (TCM) - Bootcamp-Style Offensive Security
Heath Adams runs The Cyber Mentors (~1M subscribers) and TCM Security, which sells well-regarded paid training, including the popular Practical Ethical Hacking course - a paid product sold through TCM Security's academy, not a free YouTube upload. Don't go looking for it on the channel; it isn't there.
The free YouTube library is still substantial: full playlists on network penetration testing fundamentals, beginner pentesting concepts ("Pentesting for n00bs"), cybersecurity fundamentals, and Linux for ethical hackers. Followed in order - fundamentals, then Linux, then network pentesting - that's genuinely free, course-grade preparation for the offensive track. Just don't confuse it with the paid bootcamp.
Best For: Aspiring pentesters who want a structured, genuinely free offensive curriculum. Start With: Cybersecurity 101, then Beginner Linux for Ethical Hackers, then Zero to Hero: A Practical Network Penetration Testing Course.
5. IppSec - HackTheBox Mastery
IppSec (~316K subscribers) is the single most-cited resource for offensive security skill-building. His channel is almost entirely walkthroughs of HackTheBox machines, explaining each tool, technique, and decision in detail. The library is organised into difficulty-graded playlists, and the easy Linux set alone runs to more than fifty walkthroughs.
The leverage is enormous. Once you finish a HackTheBox machine (or get stuck on one), watching IppSec's walkthrough teaches you techniques and tooling tricks you would have missed solving alone. He goes beyond the solution to demonstrate alternative approaches, which builds the kind of flexible thinking pentest interviews probe for.
This is not a beginner channel. Watch IppSec only after you are comfortable with The Cyber Mentors' beginner playlists or have spent 1-2 months on TryHackMe.
Best For: Intermediate offensive security learners who are actively working through HackTheBox. Start With: CTF - Nix - Easy - work through the easy-difficulty walkthroughs first, ideally after you've attempted each box yourself.
6. David Bombal - Networking and Ethical Hacking with Industry Voices
David Bombal (~3.1M subscribers) is a long-time networking instructor who pivoted toward cybersecurity over the last few years. His channel mixes hands-on Kali Linux demos, ethical hacking segments, and (uniquely) interviews with prominent security professionals: founders, OSCP holders, former black hats turned defenders.
His playlist tab is mostly vendor and conference content - Cisco Live sessions, Black Hat and DEF CON recaps, sponsor demos - rather than a single structured beginner course, so don't go looking for a dedicated "Kali Linux for Beginners" series; it isn't there. The real value is his standalone interview videos, watched individually: hearing how dozens of practitioners broke into the field and what hiring managers actually look for beats a hundred tutorial videos.
Best For: Career-focused learners who want both technical fundamentals and industry context. Start With: Learn Linux in 180s for a quick primer (it's a short three-video set, not a full course), then browse his channel directly for 3-5 recent practitioner interviews.
7. HackerSploit - Kali Linux and Offensive Tooling (Currently Dormant)
HackerSploit (~1M subscribers) built one of the more consistent libraries of offensive security tutorials on YouTube, but the channel has gone quiet - no new upload in more than a year as of September 2026. Its back catalogue covers Kali Linux setup, Metasploit, Nmap, Burp Suite, and web application pentesting in a calm, methodical style. The "Linux Security" and "Web App Sec" playlists are the strongest surviving structured content. Because the channel is inactive and tool versions move fast, treat everything here as a technique primer, not a current reference: verify commands against the tool's own docs before relying on them in a lab.
Best For: Learners who want a quiet, structured primer on offensive tools, with the understanding that it's a frozen library, not a maintained one. Start With: Linux Security, then Web App Sec once you're comfortable in a terminal.
8. LiveOverflow - Binary Exploitation and AppSec Depth
LiveOverflow (~944K subscribers) covers the deepest end of offensive security on YouTube: binary exploitation, reverse engineering, browser security internals, kernel exploitation, and applied cryptography. The host is a security researcher with a teaching style that respects your intelligence - he shows the actual code and tools, not simplified abstractions.
This is not where you start. It is where you go after 12-18 months in the field, when you are deciding whether to specialize in application security, vulnerability research, or exploit development. For learners on a defensive track, LiveOverflow may be more depth than the role requires.
Best For: Advanced learners moving toward AppSec, vulnerability research, or exploit development roles. Start With: Binary Exploitation / Memory Corruption by LiveOverflow - but only after you can read C and assembly comfortably.
9. Null Byte (WonderHowTo) - Project-Driven Hacking Tutorials (Currently Dormant)
Null Byte (~955K subscribers, part of the WonderHowTo network) built its reputation on a project-driven format, but like Professor Messer and HackerSploit it has gone quiet - more than a year since its last upload as of September 2026. Each video in the back catalog is a self-contained mini-project: a USB Rubber Ducky payload, cracking a Wi-Fi password in a lab, a phishing engagement, automating recon with Bash. Because the channel is inactive and tooling-heavy, treat it as inspiration rather than a current reference - hardware and tool versions in older videos may not match what's available today. Verify against current docs before you build.
Best For: Learners with a basic Kali setup who want project ideas, cross-checked against current docs since the channel itself is no longer maintained. Start With: Cyber Weapons Lab - pick any project you haven't built, verify the tool versions, then actually build it.
10. Computerphile - Cryptography and Computer Science Fundamentals
Computerphile (~2.63M subscribers) is a fundamentals channel built around interviews with academic computer scientists, not a "how to hack" channel. It covers cryptography, hashing, public-key infrastructure, TLS, password security, and computer science topics that underlie every other cybersecurity skill.
The reason this channel matters: most YouTube cybersecurity content jumps to tools without explaining the math and mechanics underneath. Computerphile fills that gap. A single 12-minute video on RSA or Diffie-Hellman will teach you concepts that would take three security tutorials to half-explain.
Best For: Anyone who wants conceptual depth in cryptography and applied computer science alongside their hacker-tool training. Start With: Mike Pound on Computerphile - a 27-video collection covering cryptography and security fundamentals, and the best single entry point on the channel.
How to Learn Cybersecurity from YouTube: A 6-12 Month Roadmap
This roadmap sequences the ten channels above into a 6-12 month path from zero to interview-ready for an entry-level SOC analyst or junior pentester role: two months on networking and Linux foundations, two months on Security+ certification, three months of guided hands-on labs, three months of HackTheBox and specialization, and a final push on portfolio and job search.
Watching the channels above randomly leads to the most common cybersecurity learning failure: knowing scattered tools without being able to do a job. Here is the structured version.
Stage 1 - Foundations (Months 1-2)
Watch NetworkChuck's Linux for Hackers series and his networking videos, and mix in a handful of David Bombal's standalone Kali Linux demos and practitioner interviews (his channel doesn't have a single structured "Kali for Beginners" course, so pick individual videos rather than a playlist). Set up a home lab on your own machine: install VirtualBox or VMware, run a Kali VM, run a vulnerable Linux VM (Metasploitable 2 or 3) for practice targets.
Daily commitment: 1 hour video + 30 minutes hands-on lab. By the end of month 2, you should be comfortable in a Linux terminal, understand basic networking (subnetting, DNS, HTTP), and have done a basic Nmap scan and exploited a known vulnerability in your lab.
Stage 2 - Security+ Track (Months 2-4)
Begin Professor Messer's full CompTIA SY0-701 Security+ course alongside continued lab practice - the channel is dormant, but SY0-701 is still the exam CompTIA is testing, so the course is not out of date. Take notes by hand. Use Anki (free flashcard app) to review key concepts daily - security domains, encryption types, common attack vectors, network controls.
At month 4, schedule and pass the Security+ exam (CompTIA raised the voucher price to $439 in 2026). Many entry-level cyber jobs filter on this one cert. Passing it is your first job-market signal.
Stage 3 - Hands-On Offensive Practice (Months 4-7)
Start TryHackMe. The free tier gives you free rooms and a capped 1-hour-per-day AttackBox, but full access to the Pre-Security and Cyber Defense learning paths needs Premium (EUR 16.99/month, or EUR 10.50/month billed annually - TryHackMe's pricing page displays the price in the visitor's local currency, checked September 2026). Budget for Premium once you've worked through the free rooms; it's the cheapest paid step in this whole roadmap.
Pair every TryHackMe room with a relevant video: John Hammond for the offensive mindset, The Cyber Mentors' Beginner Linux for Ethical Hackers playlist for Linux depth, or HackerSploit's Linux Security playlist (a dormant channel, but the content still applies). After completing a room, write a short markdown writeup of what you did. These writeups become your portfolio.
By month 7, you should have completed 30-50 TryHackMe rooms and written up at least 10 of them on a personal blog (free on GitHub Pages).
Stage 4 - HackTheBox and Specialization (Months 7-10)
Move up to HackTheBox. Start with retired easy machines. After each box, watch IppSec's walkthrough and note techniques you missed. The contrast between your approach and his is where the deepest learning happens.
Choose your specialization track:
- Defensive (SOC): Add Splunk Fundamentals (free Splunk training portal) and Microsoft SC-200 study materials. Focus on log analysis, SIEM tools, MITRE ATT&CK framework.
- Offensive (pentesting): Continue HackTheBox and study for the OSCP path. TryHackMe's Junior Penetration Tester learning path is good preparation, though full access to it needs the paid Premium tier described above.
- AppSec: Add LiveOverflow and start working through PortSwigger's Web Security Academy (free, by the makers of Burp Suite).
Stage 5 - Job Search and Portfolio (Months 10-12)
Polish your portfolio: 10-20 published HackTheBox or TryHackMe writeups, your home lab setup documented, your Security+ cert listed, and a LinkedIn profile that ties it together.
Apply to entry-level SOC analyst roles, junior pentester positions, IT security analyst roles, or MSSP (managed security service provider) positions. MSSPs hire heavily at entry level and provide rapid skill-building.
LearnPath can compress the navigation overhead significantly. Tell it your goal - "become a SOC analyst" or "prepare for OSCP" - and the AI builds a structured learning path from the YouTube content above, generates quizzes from each video transcript so concepts actually stick, and uses spaced repetition so the material from month 1 is still sharp at month 9.
5 Common Mistakes When Learning Cybersecurity from YouTube
These five mistakes account for most of the wasted time in a YouTube-only cybersecurity education: skipping fundamentals, watching instead of doing, chasing certifications without lab time, training offensive skills the entry-level market doesn't hire for, and neglecting the writing skills that get you through the interview. Fix these and the same YouTube content gets you hired faster.
1. Skipping the networking and Linux foundation. The single biggest cause of cybersecurity stall is jumping into hacking tutorials without understanding TCP/IP, subnetting, DNS, HTTP, or how a Linux file system actually works. Every offensive technique sits on top of these fundamentals. Spend the first 2 months on NetworkChuck and David Bombal's networking content before touching a single Metasploit module.
2. Watching without doing. Cybersecurity is one of the few technical fields where you can convince yourself you've learned something without ever opening a terminal. Every video should be paired with a TryHackMe room, a HackTheBox machine, or a home lab exercise. If you watch a Metasploit tutorial, run Metasploit yourself within an hour.
3. Chasing certifications without lab time. A passed Security+ exam plus zero lab experience is worse than no cert plus an active GitHub of writeups. Hiring managers test, not interview. Build the portfolio first; let the certs supplement it.
4. Going offensive before defensive. Most entry-level cyber jobs are blue team (SOC, IR, security engineering). Most YouTube cyber content is red team (pentesting, hacking). This mismatch trips up many learners who train for offensive roles, fail to land them, and have not built the defensive skills the actual entry-level market wants. Build defensive depth first; specialize into offensive later.
5. Underestimating soft skills. Cybersecurity is fundamentally a communication job. SOC analysts write incident reports. Pentesters write executive summaries. Security engineers explain risk to non-technical stakeholders. Practice writing clear, structured technical writeups from day one - your TryHackMe and HackTheBox writeups are the real interview portfolio.
Skip the Manual Curation
The 10 channels above represent far more content than anyone can watch. Sequencing them, keeping track of what you've covered, remembering to review earlier material as you advance, and maintaining momentum through a 6-12 month grind is the actual hard part of learning cybersecurity from YouTube. This is exactly the trap our guide to getting out of tutorial hell describes: endless consumption without a path forward.
LearnPath handles that layer. Tell it your goal - "land an entry-level SOC analyst job" or "prepare for OSCP" - and the AI builds a structured learning path from the best free YouTube content. Each video gets a quiz generated from the transcript so you actively recall, not passively watch. Get one wrong, and the path branches to reinforce that concept. Spaced repetition resurfaces month 1 material at month 9 so it actually sticks.
Same free YouTube content. Curriculum layer on top.
Frequently Asked Questions
The questions below are the ones learners ask most often before starting a YouTube-based cybersecurity education: whether it's possible without a degree, which channel to start with, how long it takes, and which certifications and specializations to prioritize. Each answer stands on its own if you only read one.
Can I really get into cybersecurity from YouTube alone?
Yes - many entry-level SOC analysts and junior pentesters have broken into the field with no degree, using only free YouTube content plus hands-on labs (TryHackMe, HackTheBox). The bottleneck is rarely content quality. It is structure, certifications, and provable hands-on experience. Plan for 6-12 months of consistent study to reach interview-ready for entry-level roles.
What is the best YouTube channel for cybersecurity beginners?
NetworkChuck and Professor Messer's existing library are the two best starting points. NetworkChuck's energetic, project-based videos make networking and Linux approachable. Professor Messer's channel has gone quiet, but his complete Security+ SY0-701 course is still exam-current and remains the gold-standard free prep for CompTIA's two entry-level certs. Watch both in parallel.
How long does it take to learn cybersecurity from YouTube?
For an entry-level SOC analyst role, expect 6-12 months of focused study at 1-2 hours per day. This includes networking fundamentals (1-2 months), security basics and Security+ prep (2-3 months), hands-on labs on TryHackMe and HackTheBox (3-6 months), and a portfolio project. For pentesting or red team roles, plan on 12-18 months - the technical depth required is significantly higher.
Do I need a degree to work in cybersecurity?
No. ISC2's 2023 Cybersecurity Workforce Study found hiring professionals preferred entry-level experience over a cybersecurity bachelor's degree by 70% to 30%. Common entry paths: 52% first held a non-cybersecurity IT job, 51% earned a certification first, and 45% learned cybersecurity independently. A strong hands-on portfolio outweighs a degree alone.
Is cybersecurity hard to learn from YouTube?
Cybersecurity is wide rather than uniformly hard. The networking and Linux fundamentals required for entry-level SOC roles are very approachable through YouTube channels like NetworkChuck and David Bombal. Specializations like binary exploitation, malware reverse engineering, and advanced offensive security have steep learning curves. Most learners can reach entry-level proficiency from YouTube; specialist mastery typically requires structured training plus mentorship.
What certifications should I pursue alongside YouTube learning?
For entry-level defensive roles, prioritize CompTIA Security+, then Network+ if needed; Professor Messer's free courses remain sufficient prep even though the channel has stopped uploading. For offensive security, OSCP is the gold standard but expensive - TryHackMe's Junior Penetration Tester path is a strong precursor, though full access needs paid Premium. Add Splunk Core Certified User or SC-200 for SOC roles.
Should I focus on offensive (red team) or defensive (blue team) cybersecurity first?
Defensive (blue team) roles like SOC analyst have far more open positions and lower barriers to entry. Most cybersecurity careers start there, even for those aiming at red team work later. Build a defensive foundation first - Security+, log analysis, SIEM tools - then specialize; starting offensive often stalls when the deeper technical skills employers expect aren't there yet.
