Your learning journey
The career-changer track is self-paced, takes roughly 80-120 hours, and runs across 14 modules (M0-M13). Everything is mapped to the CompTIA Security+ (SY0-701) exam domains, the ASD Cyber Skills Framework, and what Australian employers actually ask of entry-level candidates.
As you go, every module ends with an interactive self-check (a short scored quiz plus flashcards that come back on a spaced schedule) and your progress is tracked privately on your own device (see your progress page).
The journey at a glance
- Foundations (M0-M3): work out if cyber is for you, then build the computing, networking and command-line base everything else stands on.
- Core security (M4-M7): security fundamentals, the Australian frameworks employers expect you to know, identity, and how real attacks actually start.
- Applied & defensive (M8-M11): life in a SOC, web application security, governance and risk, and cloud, the day-to-day of entry-level roles.
- Capstone & career (M12-M13): build a portfolio that proves your skills, then turn it into applications, interviews and a job.
Module map
| Module | What you'll cover | Hands-on practice |
|---|---|---|
| M0: Orientation: Is cyber for you? | Real roles, real salaries, realistic pathways, decide with evidence | None |
| M1: Computing & digital foundations | How computers, operating systems and files actually work | Build a free virtual machine (optional stretch) |
| M2: Networking fundamentals | TCP/IP, DNS, ports: how data moves between computers | Free video course + packet basics |
| M3: Operating systems & the command line | Windows and Linux essentials every analyst needs | Practise Linux in your browser (TryHackMe, OverTheWire Bandit) |
| M4: Security fundamentals | The CIA triad, threat types, and crypto basics | None |
| M5: The Australian cyber context | Essential Eight, the ISM, the Privacy Act: what local employers expect | Run an Essential Eight self-assessment |
| M6: Identity & access management | Authentication, MFA, Active Directory and Entra ID | None |
| M7: Threats & social engineering | How attacks really start: phishing, scams, manipulation | Analyse a phishing email step by step |
| M8: Defensive ops & the SOC | Alerts, triage, SIEMs and the incident response lifecycle | TryHackMe SOC Level 1 path (browser) |
| M9: Web & application security | The OWASP Top 10: how web apps get broken and defended | PortSwigger Web Security Academy (browser); local Juice Shop (optional stretch) |
| M10: Governance, Risk & Compliance | Risk, frameworks, audit: the GRC analyst's toolkit | Build a mock risk register |
| M11: Cloud security fundamentals | The shared responsibility model and cloud-native threats | Free-tier cloud walkthrough |
| M12: Capstone / CTF | Turn your skills into portfolio evidence | picoGym challenges + professional write-ups; self-hosted CTF (optional stretch) |
| M13: Career launch | Résumé, applications, interviews, Security+ exam strategy | Build your application pack |
Most hands-on practice runs in your browser on free platforms that host the environment for you. Items marked (optional stretch) involve setting up software on your own computer, worth doing, never required.
Security+ SY0-701 alignment
The course covers all five Security+ SY0-701 exam domains. Each module names the domain it maps to at the top of the page, so you can study for the exam alongside the course.
Where this content comes from
We write our own explanations, adapt only openly licensed material (always with attribution), and link you to the best free resources rather than copying them. Credits for the material we adapt are on the attributions page.
Ready to start? Begin with Module 0: Orientation, it's designed to help you decide if this path is for you.