September 26, 2026
The Hacker’s Roadmap (How to Get Started in IT in 2026)
Eight steps from Complete beginner to Professional Penetration Tester

By Shahzaib
4 min read
I wasted two years learning the wrong things. I memorized commands i never used. I studied for certifications that did not matter. I jumped between topics like a pinball networking one week Python the next then back to Linux never going deep enough to actually understand anything.
The problem was not my effort. It was my direction. I did not have a roadmap.
Here's the one I wish I had had. Eight phases. Each one builds on the last. Skip one and the next won't make sense. Follow it and you will go from "I know nothing" to "I can actually do this" faster than you'd expect.
Part 1: Foundations the Boring stuff that actually matters
Nobody wants to hear this.But you can not build a house on sand.
Foundations mean understanding how computers work.What happens when you press a key? How does data move from one machine to another? What does "operating system" actually mean?
You don't need to know everything.But you need to know enough. Start with the basics: hardware software and the space between them. Learn what a CPU does. Learn what RAM is for. Learn how storage works.
This phase takes a month or two. It feels slow. Stick with it. Everything else depends on it.
Part 2: Security the Mindset before the Skills
Security isn't just a set of tools. It's a way of thinking.
Before you learn a single exploit you need to understand what you are protecting.What is confidentiality? What is integrity? What is availability?What does it mean when someone says a system is "secure"?
Learn the CIA triad. Learn about risk. Learn about threat models. Learn why attackers do what they do.
This phase is conceptual. It's not about doing. It's about understanding.
I spent a week reading about security theory and thought I was wasting my time. Then i started practicing and everything clicked. The theory gave me a framework. Without it i was just memorizing commands.
Part 3: Networking the Invisible Highway
Every hack involves a network.You can't secure or exploit what you don't understand.
Learn the OSI model. Not because you will use it daily you won't but because it's the language of networking.Learn how TCP/IP works.Learn what a subnet is.Learn how DNS resolves names to addresses. Learn how packets actually move.
Set up a small network at home. Configure a router. Use ping and traceroute and netstat. See what happens when you break something.
This phase takes a few months. It's the longest phase so far. Don't skip it. I have seen too many people try to hack networks they don't understand. It never ends well.
Part 4: Linux the Hacker's Home
Most security tools run on Linux. Most servers run on Linux. Most attackers use Linux. If you are serious about this field you need to live in Linux.
Install Ubuntu or Debian. Use it as your daily driver. Learn the command line. Learn the file system. Learn permissions. Learn how to manage processes. Learn how to write a bash script.
I spent a month forcing myself to use Linux for everything. It was painful. But after that month i was faster in the terminal than I had ever been with a GUI.
The goal is not to become a system administrator. The goal is to be comfortable. Linux is your workspace. Make it feel like home.
Part 5: Coding the Language of Automation
You don't need to be a software engineer. You need to be able to write scripts.
Python is the language of cybersecurity. Learn it. Not at a computer science level. At a practical level. Learn how to read files. Learn how to make network requests. Learn how to automate boring tasks.
Write a port scanner. Write a password cracker. Write a log analyzer. These projects teach you more than any course.
The goal isn't to build the next great app. The goal is to stop being dependent on tools other people built. When you can write your own, you become dangerous.
Part 6: Start Hacking the Moment of truth
This is where you apply everything you have learned.
Set up a home lab. VirtualBox. Kali Linux. Metasploitable. A vulnerable web app. Build a target then break it.
Start with simple challenges. TryHackMe. HackTheBox. PortSwigger Academy. Do one room or box every day. Fail. Learn. Try again.
The first time you get a shell on a target something changes. You understand what this work is. It's not magic. It's a process. And you can do it.
This phase never ends. You keep hacking. You keep learning. You get better.
Part 7: Hacking Certifications the Credentials that Matter
Certifications are not a substitute for skills. But they open doors. They get you past HR filters. They prove you know what you are talking about.
Start with CompTIA Security+. It's the baseline. Then consider practical certifications.
The eJPT (eLearnSecurity Junior Penetration Tester) is a good entry-level practical cert. The PNPT (Practical Network Penetration Tester) is more advanced. The OSCP is the gold standard.
Don't collect certifications just to collect them.Each one takes time and money. Pick the ones that align with your goals.
Part 8: OSCP the Mountain Everyone Wants to Climb
OSCP is the most respected penetration testing certification in the industry.
It's a 24 hour practical exam. You get a lab network and a target. You have to break in escalate privileges and write a professional report. No multiple choice. No theoretical questions. Just proof that you can do the work.
The exam is brutal. The pass rate is low. The preparation is intense.Most people spend six months to a year getting ready.
But passing OSCP changes how people see you. It proves you can hack. It proves you can write. It proves you can work under pressure.
If you have made it through the first seven phases you are ready to start preparing.
The Roadmap is a Guide not a Prison
I followed this roadmap. It worked for me.But it's not the only way.
Some people skip foundations and learn by doing. Some people specialize early.Some people never get a certification and still have amazing careers.
The roadmap is a starting point. It's not a rulebook. Use it to orient yourself. Then adjust based on what you learn.The best roadmap is the one you actually follow.
One last Thing
I spent two years feeling lost. I thought I was not smart enough. I thought i had missed something everyone else knew.
I had npt. I just didn't have a plan.
Now I do. You do too. Start with foundations. Build from there. Don't rush. Don't skip.
The only question left is: when do you start?
Thanks for reading Shahzaib
Good Luck and start your Journey!