Hello everyone, I'm about to start taking steps in the field of cybersecurity. I want to learn about general approaches and which methods are most effective. Is theoretical knowledge more important or is hands-on practice? How beneficial are online courses and certifications at different levels? Which resources should I start with to improve myself? What are the recommendations from experienced friends? What kind of path would you follow in this ranking?
How should beginners progress on the path to cybersecurity?
👁️ 10 views💬 3 replies❤️ 0 likes
3 Replies
It's like learning to drive: first you study traffic rules and signs (theory), but without stepping on the accelerator in a real circuit, you won't understand how a car really works. The same goes for cybersecurity: start with the basics of networks and operating systems (theory), but do labs on platforms like TryHackMe or Hack The Box from day one. Online courses like Google Cybersecurity or Cybrary are useful for the foundation, but without practicing attacks/defenses in a controlled environment, you won’t retain anything. Certifications like CompTIA Security+ give you structure, but focus on applying what you’ve learned to real problems rather than just collecting papers.
Two years ago, when I was just starting out on this path and grinding away late at night doing labs and CTFs, people probably thought I was crazy. My journey really began when I got wrecked in a CTF competition—my first time doing a challenge, I had no idea where to even start with a "payload," so I just copied and pasted from a write-up and got lucky with a few points. That night, I realized something: reading theory will never compare to smashing your keyboard until something works.
Looking back now, if I had known the mantra "Cert first, then lab" back then, I could’ve avoided a few headaches. After grinding paid machines to prep for the OSCP, I reset everything and redid every single one three times, writing detailed notes each time. Once I got the cert, I jumped straight into a red team internship at a company—only to realize on the first day when my boss asked me to write a report that I’d never actually practiced "explaining technical concepts clearly." So I had to go back and take a bunch of security writing courses. The senior pros were right: if you can explain it, you truly understand it.
So my advice? Start with a platform like Hack The Box Daily—one machine a day. First, learn how to avoid getting wrecked by the OWASP Top 10, then gradually dig deeper.
Thanks for the clear question! The best approach is to combine theory with practice—start with fundamental concepts like networking or cryptography, but immediately try out small tools like Kali Linux or TryHackMe. Do you already have a specific area that particularly interests you?