Cybersecurity roadmap: networking, Linux, security skills, labs and certifications
Cybersecurity professionals protect organisations from attacks: phishing, ransomware, stolen passwords, fraud, data leaks and SIM-swap scams. Kenyan banks, SACCOs, telcos, fintechs, insurers, government agencies, hospitals and universities all need security people, and so do the companies that serve them.
Security is not an entry-level skill on its own. You protect systems you understand. That is why this roadmap starts with IT basics, networking and Linux before any "hacking".
The main job families
| Path | What they do | Typical entry route |
|---|---|---|
| SOC analyst (defensive / "blue team") | Watch alerts, investigate suspicious activity, respond to incidents | The most common first security job |
| Penetration tester (offensive / "red team") | Legally attack systems to find weaknesses before criminals do | Usually after 1–3 years of IT, networking or SOC experience |
| GRC (governance, risk, compliance) | Policies, audits, risk assessments, data protection compliance | Good for people from audit, law or business backgrounds |
| Security engineer | Build and configure firewalls, identity systems and secure cloud setups | After networking or system administration experience |
| Digital forensics and fraud | Investigate incidents and fraud, preserve evidence | Banks, telcos, audit firms, law enforcement |
Stage 1: IT foundations (4–6 weeks)
You must be comfortable with computers before you can secure them.
- Computer parts, operating systems, installing software
- Windows setup, troubleshooting, malware clean-up
Checkpoint: you can install Windows or Linux in a virtual machine (VirtualBox is free) and explain what RAM, CPU, storage and the operating system each do.
Stage 2: Networking (6–8 weeks): the most important foundation
Most attacks travel over networks. You must know how traffic flows.
- What a network is, the OSI and TCP/IP models
- IPv4 addresses, subnet masks, CIDR, subnetting step by step
- TCP, UDP and ports, DNS and DHCP, NAT and routing
- Switching and VLANs, Wi-Fi
- Network commands, troubleshooting
- Network security, firewalls and VPNs
- Lab: your first Packet Tracer lab
Checkpoint: you can subnet a /24 into four networks, name the ports for HTTP, HTTPS, SSH, DNS and RDP, and explain what happens when you type a website address into a browser.
Stage 3: Linux and the command line (4–6 weeks)
Most servers and almost all security tools run on Linux.
- Why Linux, navigating files, viewing and editing files
- Pipes and redirection, permissions, users, groups and sudo
- Processes and packages, services, cron and logs
- SSH and servers, bash scripts
- Project: web server
Checkpoint: you can SSH into a server, read /var/log/auth.log and use grep to find failed logins.
Stage 4: Security fundamentals (4–6 weeks)
The whole Cybersecurity subject:
- Basics: the CIA triad, threats and risk
- Passwords and 2FA, encryption and HTTPS
- Phishing and scams, social engineering and SIM swap
- Malware and devices, backups and ransomware
- Data protection in Kenya, incident response
- Security tools, small business security
Stage 5: Scripting (3–4 weeks)
Security people automate: parsing logs, checking lists of IPs, calling APIs.
- Python: introduction → files and errors → automation and web requests
- Python for networking
- Bash: bash scripts
Checkpoint: a Python script that reads a log file and lists the top 10 IP addresses with failed logins.
Stage 6: Web security (3–4 weeks)
Websites are the most attacked surface. Understand how they're built (do at least HTML, a little JavaScript and PHP/SQL from the web developer roadmap), then:
- Web security: SQL injection, XSS, CSRF, broken authentication
- Forms and security in PHP: how developers prevent them
- The OWASP Top 10 (free at owasp.org): the industry list of the most critical web risks
- Practise legally on deliberately vulnerable apps such as OWASP Juice Shop or DVWA, running on your own machine
Stage 7: Hands-on labs (ongoing, start in stage 3)
| Platform | Cost | Good for |
|---|---|---|
| TryHackMe | Many free rooms; paid plan optional | Guided beginner paths (pre-security, SOC level 1) |
| Hack The Box (Academy and labs) | Free tier + paid | Deeper practice, both offensive and defensive |
| PicoCTF | Free | Beginner capture-the-flag challenges |
| OverTheWire (Bandit) | Free | Linux command line skills through games |
| Blue Team Labs Online / LetsDefend | Free tiers | SOC-style investigation |
| Your own home lab | Free (VirtualBox) | Kali Linux + a vulnerable VM + a Windows VM |
Write a short write-up for each lab you finish (what you found, how, how to fix it). Don't publish write-ups for active competition challenges.
Stage 8: Certifications
Certifications matter more in security than in web development, because many employers and government tenders ask for them. Start with one entry-level certificate:
| Certification | Level | Notes |
|---|---|---|
| ISC2 Certified in Cybersecurity (CC) | Entry | ISC2 has run free training and exam offers for this; check the current terms on isc2.org |
| Google Cybersecurity Certificate | Entry | Online (Coursera); financial aid is available |
| CompTIA Security+ | Entry-to-mid | Widely recognised by employers; the exam is paid |
| Cisco CCNA | Networking | Excellent foundation; Cisco Networking Academy courses are offered at many Kenyan universities and colleges |
| CompTIA CySA+ / Blue Team Level 1 | SOC | After some experience |
| eJPT, then OSCP | Penetration testing | OSCP is advanced and respected |
Prices change; check the official sites and beware of "exam dump" sellers (cheating gets certificates revoked).
Stage 9: Portfolio and first job
Your security portfolio:
- A home lab write-up with a network diagram.
- 5–10 lab write-ups (TryHackMe rooms, PicoCTF challenges).
- A Python security tool, e.g. a log analyser or a password-strength checker, on GitHub.
- A security audit of your own website project: what you tested, what you fixed.
- A security awareness guide for a small business (see small business security): shows you can communicate.
Entry routes: IT support or helpdesk → SOC analyst; network technician → security engineer; graduate trainee programmes at banks and telcos; attachments in ICT departments. See cybersecurity careers and networking careers and certifications. Many people enter security after a year or two in the IT support roadmap; that's a normal, sensible path.
Summary
- Foundations first: IT basics → networking → Linux → security fundamentals → scripting → web security.
- Practise only on legal labs and your own systems.
- One entry certificate (ISC2 CC, Google, Security+ or CCNA) plus a lab portfolio.
- SOC analyst is the most common first security job; IT support is a common stepping stone.
Check yourself
Which Kenyan law makes unauthorised access to computer systems a crime? Name it without the year.
Show answer
Computer Misuse and Cybercrimes Act
What does SOC stand for? (three words)
Show answer
Security Operations Centre
Which list from OWASP covers the most critical web risks? (OWASP Top __)
Show answer
10
What port does SSH use by default?
Show answer
22
In the CIA triad, what does the C stand for?
Show answer
confidentiality