The 5-Step IT/Cyber Entry Framework: A Practical Roadmap for Getting Into Cybersecurity

If you are trying to get into cybersecurity, you have probably asked questions like what certification should I get, do I need a degree, should I build a home lab, or how do I get experience when nobody will hire me.
Those can be reasonable questions, but they often come too early.
One reason beginners get stuck is that they are preparing for an industry instead of preparing for a job. Cybersecurity is not one job. A SOC analyst, GRC analyst, penetration tester, IAM analyst, and cloud security professional can require very different combinations of knowledge, skills, and experience.
When you prepare for cybersecurity as a whole instead of a specific role, you end up collecting random certifications, building things you cannot explain, and following generic advice that may not apply to the destination you eventually choose.
What you need instead is an ordered process for making career decisions.
The 5-Step Cybersecurity Entry Framework is a career-planning model developed by cybersecurity practitioner and educator Dr. Leonard Simon (Professor Simon) for people trying to enter cybersecurity. The five stages are Discover, Foundation, Skills, Proof, and Entry. Instead of collecting certifications or learning unrelated security tools, the framework starts with identifying a target role and then building the foundation, skills, evidence, and entry strategy needed for that specific career path.
The 5 Steps at a Glance
- Discover: Identify the cybersecurity role you actually want.
- Foundation: Build the IT and security fundamentals that role requires.
- Skills: Develop the technical and professional skills needed for that role.
- Proof: Demonstrate those skills through projects and practical experience.
- Entry: Target realistic opportunities that move you toward your desired cybersecurity role.
Prefer to read the full breakdown? Keep scrolling. Prefer to watch? Full video above.
The Problem With Starting Too Early
Most people start their cybersecurity career planning by asking tactical questions about certifications, degrees, home labs, and job applications before understanding where they are actually trying to go.
This creates several problems.
First, you build the wrong foundation. Someone preparing for a SOC analyst role should not necessarily follow the same path as someone interested in GRC, penetration testing, IAM, or cloud security. But without a specific destination, you cannot tell which preparation moves you closer to your goal and which preparation wastes time.
Second, you pursue irrelevant certifications. You stack credentials simply because they appear on generic lists or sound impressive, not because they help you build or validate knowledge relevant to the role you eventually want.
Third, you create proof that does not align with the roles you pursue. You build elaborate home labs that demonstrate technical ability in areas that do not matter for your target position, or you cannot articulate what you learned from the projects you completed.
Fourth, you struggle to identify realistic entry points. You apply indiscriminately to hundreds of positions because you cannot determine which opportunities move you closer to your destination and which do not.
The solution is not to avoid certifications, labs, or preparation. The solution is to make those decisions in the right order.
Why You Need a Framework
Cybersecurity is not one job but many different roles requiring different combinations of knowledge, skills, experience, and technical depth.
A SOC analyst investigates alerts, analyzes logs, and triages potential security incidents. A GRC analyst evaluates risk, documents controls, and ensures compliance with regulations and frameworks. A penetration tester identifies vulnerabilities through authorized testing. An IAM analyst manages identities, permissions, and access controls. A cloud security professional secures infrastructure, applications, and data in cloud environments.
These roles can require different technical foundations, different practical skills, and different types of experience.
That means your preparation should begin by understanding where you are trying to go, not by deciding to work in cybersecurity.
The 5-Step Cybersecurity Entry Framework addresses this problem by connecting each career decision to a specific destination. Each step influences the next, and the order matters. Together, the five stages create an ordered process for making career decisions instead of collecting random credentials and following conflicting advice.
Each step influences the next. The order matters. Together, they create an ordered process for making career decisions instead of collecting random credentials and following conflicting advice.
Step 1: Discover
The first step is to research specific cybersecurity roles rather than simply deciding to work in cybersecurity.
This does not mean you must choose a career forever. It means you need enough direction to stop preparing randomly.
Start by identifying three to five specific cybersecurity roles that interest you. Then research beyond job titles and certification requirements to understand what someone in that role actually does.
What are the day-to-day responsibilities? What technologies do people in that role commonly use? What technical depth does the work require? What business responsibilities come with the position? What skills do employers request? What qualifications appear frequently in job postings? What entry points do people typically use to reach that role?
You can answer these questions through job postings, informational interviews, online communities like Reddit’s cybersecurity and IT career forums, LinkedIn profiles of people in those roles, and career research on professional organization websites.
The goal is to build a realistic picture of each role before choosing a direction.
Once you understand what someone in that position actually does, you can make better decisions about what to learn next. Without this step, you build the wrong foundation, pursue irrelevant certifications, and create proof that does not align with the roles you eventually pursue.
Step 2: Foundation
Entry-level cybersecurity does not mean entry-level technology.
Someone does not necessarily need ten years of IT experience before moving into cybersecurity, but they do need to understand the technology they are trying to secure.
The required depth varies by role.
A SOC analyst needs to understand networking concepts, operating systems, common protocols, log analysis, and how attackers move through systems. A GRC analyst may need less technical depth in network packet analysis but still needs to understand how controls work, what risks different technologies introduce, and how systems interact. A cloud security professional needs to understand cloud architecture, identity and access management, infrastructure as code, and the shared responsibility model.
The destination you identified during Discover determines what underlying technology and IT knowledge you need to build.
Map the foundation requirements by identifying what knowledge your target role depends on. Do you need to strengthen your understanding of networking? Operating systems? Identity and access management? Cloud fundamentals? Active Directory? Basic scripting? Security fundamentals?
Be honest about gaps in your current knowledge and prioritize filling those gaps before moving to more advanced topics.
This step should not be interpreted as a universal requirement to work help desk for five years. But understanding the technology you are trying to secure still matters. Someone who does not understand how Active Directory works will struggle to analyze suspicious authentication activity, evaluate identity security controls, or understand privilege escalation techniques.
Step 3: Skills
Knowing cybersecurity and being able to do cybersecurity are different things.
At some point, learning has to become practice.
What skills development looks like depends on the target role you identified during Discover and the foundation you built in the previous step.
A SOC analyst needs to practice investigating alerts, analyzing logs, using SIEM tools, identifying indicators of compromise, and documenting findings. A GRC analyst needs to practice evaluating controls, mapping requirements to frameworks, conducting risk assessments, and documenting compliance evidence. An IAM analyst needs to practice configuring access controls, reviewing permissions, managing groups and roles, and troubleshooting authentication issues.
This is where certification decisions should connect back to your destination.
Do not stack certifications simply because they are popular or appear on generic lists. Ask whether a certification helps build or validate knowledge and skills relevant to your target role.
Security+ can be valuable because it covers foundational security concepts that apply to many roles. But whether you should pursue CISSP, CySA+, CEH, GCIH, OSCP, or other certifications depends entirely on where you are trying to go and what you need to learn or demonstrate.
The same principle applies to home labs.
Build what you need to learn, not what sounds impressive. If you are targeting a SOC analyst role, build a lab that lets you practice investigating alerts, analyzing logs, and working with security tools. If you are targeting a cloud security role, build environments in AWS or Azure where you can practice implementing security controls, managing identities, and securing infrastructure.
The goal is not the lab itself but what you can learn to do because you built and used it.
Step 4: Proof
This step directly confronts the common problem of needing experience to get hired but needing to get hired to gain experience.
Employment is one way to gain experience, but not the only way to develop or demonstrate ability.
Proof can come from projects, home labs, existing IT responsibilities, internships, volunteer work, competitions, documentation, or relevant responsibilities from current non-security positions.
The important part is not simply claiming to have built something, but being able to explain what you were trying to learn, what went wrong, how you troubleshot it, and what you would do differently.
That creates evidence of reasoning, troubleshooting, curiosity, and practical ability.
If you built a home lab to practice investigating alerts, can you explain what tools you used, what types of activity you simulated, how you analyzed the results, what patterns you identified, and what you learned about detection and response? If you completed a project analyzing security controls for a compliance framework, can you explain which controls you evaluated, how you determined whether they were effectively implemented, what gaps you identified, and what recommendations you made?
A simple project you deeply understand may provide better evidence than a complicated project you cannot explain.
Document what you build, investigate, or solve in a way that demonstrates your reasoning and troubleshooting ability. Write about what you were trying to learn. Explain what you built and why you configured it that way. Describe what went wrong and how you troubleshot it. Discuss what you learned and what you would do differently next time.
This preparation gives you something concrete to discuss during interviews and helps employers see what you can actually do.
Step 5: Entry
A realistic entry point into cybersecurity may be a job that does not have cybersecurity anywhere in the title.
Depending on your current background and target destination, useful entry points could include IT support, help desk, systems administration, network administration, cloud operations, identity and access management, compliance, audit, risk, or other technology roles that build relevant experience.
These should not automatically be viewed as failures or detours.
If a position gives you meaningful exposure to technology you will eventually need to secure, it may be a valuable step toward your destination. The question should not only be whether something is a cybersecurity job, but also whether it moves you closer to the cybersecurity role you eventually want.
Someone targeting a SOC analyst role might benefit from experience in IT support or help desk where they gain exposure to troubleshooting, working with tickets, analyzing logs, and understanding how systems behave. Someone targeting a cloud security role might benefit from experience in cloud operations where they gain hands-on experience with AWS or Azure infrastructure, identity and access management, and cloud architecture.
Someone targeting a GRC analyst role might benefit from experience in compliance, audit, or risk management where they gain exposure to frameworks, controls, and regulatory requirements.
Look for roles where your existing background, developing skills, and evidence create a reasonable match. Do not limit your search only to positions with cybersecurity or security in the title.
Ask whether each opportunity moves you closer to your target cybersecurity role by providing relevant exposure to technology, processes, controls, or responsibilities you will eventually need to secure.
How the Five Steps Connect
The framework is a connected process where each step influences the next, not five independent tips.
Discover determines the destination. Foundation determines what you need to understand. Skills determine what you need to be able to do. Proof demonstrates that ability. Entry turns that preparation into a realistic career move.
The order matters.
If you skip Discover, you may build the wrong foundation. If the foundation is weak, practical skills become harder to develop. If you develop skills but never create proof, employers may have difficulty seeing what you can actually do. If you complete all of that work but approach Entry by applying indiscriminately to hundreds of unrelated positions, much of the advantage created by the earlier steps is lost.
After understanding this framework, you should stop asking only how to get into cybersecurity and instead work through a more useful sequence of questions.
What role am I trying to reach? What does someone in that role actually do? What foundation does that work require? What do I need to be able to do? How can I practice and prove those abilities? What jobs or opportunities can move me closer to that destination?
That gives you a repeatable process rather than another list of certifications or generic career tips.
Where to Start
Begin with Discover. Research three to five specific cybersecurity roles that interest you before making decisions about certifications, degrees, or home labs.
Look beyond job titles and certification requirements to understand day-to-day responsibilities, technologies commonly used, and what someone actually spends their day doing.
Then work through the remaining steps in order, allowing each step to inform the next. Map the foundation requirements based on your chosen destination. Develop skills intentionally rather than collecting random credentials. Create proof that demonstrates reasoning and troubleshooting ability. Approach entry by looking for roles where your preparation creates a reasonable match.
The path into cybersecurity should follow a connected process where each step influences the next, starting with discovering a specific destination rather than preparing generically for an entire industry.
If you found this framework helpful, I regularly share additional guidance on researching cybersecurity roles, building intentional certification strategies, creating effective proof through projects and documentation, and identifying realistic entry points into the field. Subscribe to stay updated on future content that breaks down each step in greater depth.
Tagged:
Enjoyed this article?
Subscribe to Professor Simon's weekly newsletter for practical insights, career guidance, and leadership lessons delivered every Friday.
A confirmation email will be sent. If you don't receive it, please check your spam or junk folder.
No spam. Unsubscribe anytime.
Prefer to Listen?
Listen to Professor Simon’s IT & Cybersecurity Podcast for practical conversations about cybersecurity careers, certifications, security leadership, and real-world lessons from the field.
Listen on Spotify
