Where to keep learning.
Named specifically rather than kept vague. Almost everything here has a genuinely useful free tier or is free outright. Platforms and prices change, so verify current details before committing money.
The single most valuable UK resource
NCSC guidance, at ncsc.gov.uk. Free, authoritative, written for practitioners rather than by vendors, and specifically British — which no American resource can be. Its guidance on risk management, cloud security, zero trust, incident management and secure design is the closest thing the field has to a national reference, and reading it will improve your interviews as much as any paid course. The Cyber Assessment Framework and the Cyber Essentials scheme both live here too.
Hands-on practice
TryHackMe is the gentler on-ramp, with structured pathways — its SOC Level 1 and pre-security paths are a reasonable curriculum in themselves — and a free tier that goes a long way. Hack The Box is harder, less guided, and closer to the experience of real testing; its Academy arm adds structure. LetsDefend and Blue Team Labs Online are the defensive equivalents, which matter because most career changers are heading for defensive roles and most free practice material is offensive. Whichever you use, work it for depth rather than completion count: three exercises you can discuss to the root beat three hundred you cannot.
Capture the flag
CTFtime lists events year-round, most of them free to enter. UK conferences run their own — BSides events almost always have one, and they are far more welcoming to beginners than the name suggests. The value is not the score; it is having something specific and technical you can talk about in an interview.
Cloud, free of charge
Microsoft Learn is the most directly relevant for the UK market given how Microsoft-heavy enterprise and government estates are — it is free, well structured, and maps directly onto the SC-900, SC-200 and AZ-500 certifications. AWS Skill Builder and Google Cloud Skills Boost are the equivalents for their own platforms. All three providers offer free tiers generous enough to build and secure real infrastructure, which is where the interview material actually comes from.
Staying current
Pick two or three and read them consistently rather than subscribing to twenty and reading none. The Record and BleepingComputer for news; Krebs on Security for investigative depth; the NCSC’s own advisories for what UK organisations are actually being told. For practitioner depth in your chosen path, find two or three blogs written by people doing the job — the SANS Internet Storm Center diaries and vendor research blogs are reasonable starting points. One vulnerability you understood properly is worth more than fifty headlines you skimmed.
UK community and events
BSides events run in London, Cheltenham, Leeds, Manchester, Bristol and elsewhere — affordable, welcoming, and genuinely useful for newcomers. CyberUK is the NCSC’s own annual conference. 44CON and SteelCon are long-running UK technical conferences. Locally, OWASP chapters, ISACA and (ISC)² UK branches, DEF CON groups and the regional cyber clusters meet regularly and mostly free. You do not need to speak or know anyone to attend; being present and curious is the entire entry requirement, and this is how the hidden job market becomes visible to you.
Books worth the time
Three categories rather than a list that dates. One foundational text on how systems and networks actually work, chosen for your path — for most people that means networking or Windows internals. One on the human and organisational side of security, because that is where most of the real difficulty lives; Ross Anderson’s Security Engineering is the standing recommendation and is freely available online. And one written by a practitioner about the reality of the work rather than its theory. Ask the people you meet at events what they would recommend now — the answer changes, and the asking is itself the useful act.
From Appendix D of The Honest Guide to UK Cybersecurity Interviews.
Told when this page changes?
Salary bands, certifications and funding rules all move. The list covers material changes here as well as new books.
Never shared, never sold. One-click unsubscribe.