Video summary

How I Would Learn Cyber Security If I Could Start Over in 2026 (6 Month Plan)

Main summary

Key takeaways

Wellness and Self-Improvement

6-Month Cybersecurity Job Plan (Key Wellness + Productivity/Strategy Highlights)

Step 1: Build your foundation (learn broadly + start hands-on immediately)

  • Learn what cybersecurity is and what roles actually do: protecting data from theft/destruction/unauthorized access.
  • Use four foundational trainings/certificates in sequence:

    1. Google Cybersecurity Professional Certificate
      • Broad intro across OS, networking, IT, and risk management
      • Includes hands-on labs (Linux, MySQL, Python) early—don’t wait to “be ready”
    2. GRC Mastery
      • Understand cybersecurity from a business/compliance/risk perspective
      • Covers risk management, audits, frameworks (NIST, ISO 27001)
      • Includes practical assessments/case studies
      • Results in completion certificate + ISO 27001 lead auditor certificate
    3. TryHackMe (Security Analyst / “SAL 1”)
      • Built for zero knowledge and revisits fundamentals
      • Includes a SOC-simulator workflow (assign tickets, investigate, respond)
    4. CompTIA Security+ (later in the process)
      • Positioned as easier to pass because you’ll have context after the first three courses
      • Suggested prep resource: CompTIA Security+ Sybex book
  • Mindset/workflow tip

    • It’s normal to “forget” in a new field—use repetition via the plan rather than panic-memorization.
    • Don’t force a rigid deadline; use your time efficiently (6 months is the goal, not a failure condition).

Step 2: Build a job-ready resume + apply consistently (productivity + anxiety management)

  • Don’t treat certificates as the finish line.

    • A common failure: spending only ~5–10 minutes on a resume and applying immediately.
  • Resume strategy (use a structured template, then tailor)

    • Professional summary: short statement of your target interest (no life story)
    • Training/certifications section first (for candidates without experience)
    • Education only if you have a degree
    • Practical projects: brief 1-sentence descriptions (not long)
    • Experience section: can be minimal, but highlight transferable, relevant parts
    • Template source mentioned: unixgu.com/free (free cyber resume template)
  • Job application strategy

    • Apply after GRC Mastery so you can better represent your understanding.
    • Use a simple job-search filter keyword:
      • Search LinkedIn Jobs for “cyber”
    • Apply even when postings ask for experience:
      • Treat your labs as evidence you can do the work + learn quickly.
    • Daily consistency:
      • Spend at least 30 minutes every day applying (not just weekends).
  • Wellness/mental resilience

    • Rejection is normal—expect it and use interviews as learning data.
    • Don’t spiral into beliefs like “everyone wants degrees” or “I’m not good enough.”

Step 3: Use AI strategically (reduce fear; become more competitive)

  • Key idea: AI won’t eliminate cybersecurity jobs, but it will change some specializations.
  • Two ways to stay resilient:
    • Become a generalist (avoid being a “one-trick pony”)
    • Learn AI and apply it to your cybersecurity workflow
  • Learning resource mentioned:

    • Anthropic/Clo training library (free; suggested can be completed in a weekend)
  • Timing note

    • Don’t jump into “AI for cybersecurity” before you understand cybersecurity fundamentals.

Step 4: Continue learning + keep applying until you land the role (avoid random study)

After foundations/certs, focus on two ongoing priorities:

  • Apply consistently
  • Keep learning

Learning areas (not random):

  • Advanced blue teaming skills
    • Suggested certs: CyberDefenders CCDL1 → CCDL2 (incident response, forensics)
    • Also: Hack The Box CDSA
    • Optional practice: Let’s Defend SOC path (to reinforce prior SOC skills)
  • Cloud security
    • Azure: SC900 → SC200 → aim for Azure Engineer Associate
    • AWS: Cloud Practitioner → Solutions Architect → AWS Security Specialty
  • Offensive security (optional)
    • EJPT → TryHackMe PT1 → then harder paths (e.g., OSCP-level or equivalent)
    • Mentioned alternatives: Hack The Box CPTS

“Three Deadly Mistakes” (motivation + anti-procrastination)

  • Mistake #1: Thinking it’s easy / wanting the minimum
    • Don’t aim for “absolute bare minimum.” The plan is simple but requires effort, consistency, and hard work.
  • Mistake #2: Getting confused by different opinions
    • Ignore advice from people without real cybersecurity experience (treat it as procrastination/noise).
  • Mistake #3: Can’t handle rejection
    • Expect rejection as part of the process; don’t turn it into doom narratives or “bad news” scrolling.
    • Use rejection as motivation to keep improving and applying.

Presenters / Sources Mentioned

  • Anthropic (training library for AI, mentioned in context of “Clo”)
  • Cybex (CompTIA Security+ book recommendation: CompTIA Security Plus Cybex book)
  • Exemplar Global (recognition mentioned for ISO 27001 lead auditor credential)
  • Google (Google Cybersecurity certificate)
  • GRC Mastery (GRC training platform)
  • TryHackMe (SAL 1 / SOC-simulator training)
  • CompTIA (Security+ exam)
  • LinkedIn (job search/applying platform)
  • unixgu.com (free cyber resume template)
  • CyberDefenders (CCDL certifications)
  • Hack The Box (CDSA and CPTS; also PT1 is TryHackMe)
  • Let’s Defend (SOC Analyst path / practice)
  • Microsoft Azure (SC900, SC200, Azure Engineer Associate)
  • Amazon AWS (Cloud Practitioner, Solutions Architect, AWS Security Specialty)
  • Indeed, Dice, Seek.com.au (job boards mentioned as secondary platforms)
  • NIST (framework referenced)
  • ISO 27001 (framework referenced)
  • OSCP / Offensive Security (referenced as a typical next step for pentesting)

Original video