hackwither_

notes / 31 December 2025

The thing about roadmaps in cybersecurity…

I’m HackWitHer, an 18-year-old cybersecurity researcher.

have you ever tried to follow a roadmap in cybersecurity, but it looked something like “learn hacking in [insert clickbait number] dates!!” or but it just didnt help you learn or accomplish anything?
the thing is, everybody learns differently. most of you aren’t lacking motivation, you’re just lost in the noise.

i get this question a lot:

“how do i start in cybersecurity?”

I’ve talked to ~2,000 students about getting started in cybersecurity, and i’ve been one of them myself. truth is, there’s no single right path. one shoe doesn’t fit all, my dear cinderella.

About this roadmap

so, i made a rough structure that might help you find yours. creative liberty matters most in a field like cybersecurity.

the goal here is NOT to spoon-feed you sponsored certs and courses, it’s to help you think for yourself and explore with purpose. this roadmap is just to give you direction. how you decide to learn and explore the colorful field that is cybersecurity, is entirely upto you :)

this is the shoe that fits most:

1. Start with the Big Picture — What is Cybersecurity?

  • hacking? what's that? Don’t jump into coding just yet.
  • Begin with a foundational course (like ISC2 Certified in Cybersecurity (CC) or something if you’d like to gain a low cost “industry” cert on the side. otherwise, there’s plenty of introductory labs like some on TryHackMe that you can take)
  • Understand what roles exist: Red team, blue team, GRC, threat intel, SOC analyst, DFIR, OSINT, etc.
  • Build foundations and understand the HOWs and WHYs. Learn how the internet, systems, and data protection work, to the best of your curiosity!

2. Pick a Starting Point — A Niche to Explore

  • Choose one path that piques your interest.
  • Maybe it’s OSINT, maybe it’s appsec, maybe policy & privacy or something non-technical.
  • Don’t worry about picking “the perfect one.”
  • Just start reading blogs, following researchers and replicating small things others have done.

Tip: spend at least 10 days exploring a niche before you move on to the next.

3. If It Doesn’t Click, Pivot.

  • You don’t owe any niche your loyalty.
  • Test out another subfield. Rinse and repeat until something sparks.
  • The “click” comes when curiosity beats burnout.

4. Go Deeper, Go Niche-Specific

  • Once you find your thing, this is when you lock in, niche specific roadmaps==your besties
  • Specialized courses (TryHackMe, TCM, SANS, etc)
  • Certifications (specific to your niche)
  • Labs, writeups, research, content, projects in that niche

There’s plenty of roadmaps and resources specific to “niches” like red teaming, blue teaming, AI/ML security etc. that you can find online!

⸻

You don’t need to be a coder to start.

You don’t need to spend money to learn.

You just need to be curious enough to keep exploring.

The rest? We’ll build it along the way.
Stay tuned for more. happy hacking

–HackWitHer ❤