Let’s talk

Cyvora / Cyber Learning Hub

Starting your cyber security learning journey

Build foundations, learn responsibly and discover the different kinds of work within cyber security.

For people exploring the field

By Cyvora · Published and updated 6 October 2026

01 / Start with systems and people

Learn how operating systems, networks, web applications and account access work. Understand the basics of data handling and why business context matters. Security is broader than tools: governance, communications and human behaviour also shape outcomes.

02 / Explore different roles

Look at advisory, governance, engineering, testing, incident response and security operations. Use the NICE Framework to understand the tasks and knowledge associated with different areas. You do not need to choose a specialisation immediately.

03 / Practise with permission

Use learning environments that explicitly authorise your activity. Never test a public website, organisation or another person’s accounts without clear permission. Keep exercises within the stated rules and document your reasoning and observations.

04 / Read and communicate

Use official documentation and reputable community projects. Practise writing a clear finding: what you observed, why it matters, what evidence supports it and which improvement you recommend. Explain technical ideas in language your audience can use.

05 / Build a sustainable plan

Choose one topic at a time, keep learning notes and review what you understand. Create small, authorised projects and reflect on their limitations. Return to the foundations as your interests develop; a learning path is not a promise of employment or certification.

A first project you can explain clearly

Choose an application or laboratory environment that explicitly permits your activity. Map its basic components, describe how a user signs in and identify the information that needs protection. Record one observation and explain what it means, what evidence you gathered and what remains uncertain. Avoid including credentials, private information or unapproved details in a public portfolio.

What to include in your learning notes

  • The question you set out to answer and the permitted scope.
  • The steps you took and the evidence you observed.
  • A clear explanation of the result and its limitations.
  • What you would investigate next within the authorised environment.

This exercise builds analysis and communication alongside technical knowledge. You can adapt the same structure to a governance review, an incident scenario or a configuration assessment as your interests develop.

Explore the different kinds of security work

Compare governance, risk and compliance, penetration testing and assurance and incident response to understand how their objectives differ. Visit Cyvora careers for the current status of opportunities; no vacancies are currently listed.

Continue learning

This is a general starting point. Adapt the actions to your environment and responsibilities.

Read the official supporting guidance