Section 01 · Module 01 Available 🕑 ~45–60 min read

> cat module-01-understanding-the-industry.md

Understanding the IT & Cybersecurity Industry

Before you learn networking, Active Directory, cloud, Linux or cybersecurity, you need to understand how the technology industry actually works — who does what, who reports to whom, and who gets called when something breaks.

Introduction

Before learning networking, Active Directory, cloud computing, Linux or cybersecurity, you need to understand how the technology industry actually works.

A common mistake made by people entering IT is to immediately start collecting technical knowledge without understanding where that knowledge fits within a company.

You might learn:

  • TCP/IP
  • Windows
  • Linux
  • AWS
  • Azure
  • Active Directory
  • Firewalls
  • PowerShell
  • SIEM platforms
  • Vulnerability scanning
  • Penetration testing

But who actually uses those technologies? What jobs use them? Which teams own them? Who do those teams report to? What happens when something breaks? Who gets called at 2:00 AM? Who speaks to the customer? Who approves changes? Who decides whether a vulnerability represents an acceptable business risk?

These questions are just as important as learning the technology itself.

In this module, you will learn how modern IT and cybersecurity organisations operate, what the major career paths look like, how multinational companies structure their technology teams, what different jobs actually involve and how you can build a realistic career plan.

1 IT Exists to Support the Business

The first principle to understand is:

Companies do not normally operate technology simply because technology is interesting. They operate technology because it allows the business to function.

A bank uses technology to:

  • allow customers to make payments
  • process transactions
  • operate mobile banking
  • protect customer accounts
  • store financial records
  • detect fraud
  • meet regulatory requirements

A hospital may use technology to:

  • maintain patient records
  • operate medical systems
  • communicate between departments
  • protect sensitive health information
  • provide remote consultations

A retailer may use technology to:

  • operate its website
  • process card payments
  • manage warehouses
  • track stock
  • communicate with suppliers
  • analyse customer behaviour

A multinational technology company may use technology to:

  • develop software
  • host cloud services
  • support customers
  • operate global data centres
  • manage employee devices
  • provide authentication
  • monitor cybersecurity threats

This means that good IT professionals eventually learn to think beyond:

"How do I fix the server?"

They start asking:

"What business service depends on this server?"

That difference in thinking becomes increasingly important as you move into senior positions.

2 IT Is Much Bigger Than “The IT Department”

In a small company, five people might be responsible for almost everything. One administrator may manage laptops, email, networking, Microsoft 365, servers, backups, security and user accounts.

In a multinational organisation with 50,000 employees, every one of those areas may have an entire department. A large organisation might have separate teams for:

  • Service Desk
  • Desktop Engineering
  • Endpoint Management
  • Windows Server
  • Linux
  • Active Directory
  • Identity and Access Management
  • Network Engineering
  • Network Security
  • Cloud Engineering
  • Database Administration
  • Application Support
  • DevOps
  • Site Reliability Engineering
  • Security Operations
  • Incident Response
  • Vulnerability Management
  • Threat Intelligence
  • Penetration Testing
  • Governance, Risk and Compliance
  • Enterprise Architecture
  • IT Service Management
  • Change Management
  • Disaster Recovery
  • Business Continuity

This is why job titles can sometimes be confusing. A "Systems Engineer" at one company might manage Windows servers. At another company, a Systems Engineer might design cloud infrastructure. At a technology vendor, a Systems Engineer might work with customers before a sale.

Always read the job description, not just the job title.

3 The Main IT Career Families

IT careers can roughly be divided into several areas.

IT Support

Typical roles include: Help Desk Analyst, Service Desk Analyst, Desktop Support Engineer, IT Support Engineer, Technical Support Engineer, Application Support Engineer.

These roles usually involve troubleshooting problems and supporting users, systems or customers. IT support is one of the most common starting points for an IT career.

Infrastructure

Infrastructure teams operate the technology that applications and users depend upon. Typical roles include: Systems Administrator, Windows Administrator, Linux Administrator, Network Engineer, Storage Engineer, Virtualisation Engineer, Infrastructure Engineer.

Infrastructure engineers may manage technologies such as Windows Server, Linux, VMware, Hyper-V, Active Directory, DNS, DHCP, SAN storage, routers, switches, load balancers and firewalls.

Cloud

Cloud teams design and operate infrastructure using platforms such as Amazon Web Services, Microsoft Azure and Google Cloud Platform.

Typical roles include: Cloud Administrator, Cloud Engineer, Cloud Platform Engineer, Cloud Architect, Cloud Security Engineer.

Cloud engineers increasingly work with automation rather than manually configuring servers. Common technologies include Terraform, Kubernetes, Docker, Python, PowerShell, Bash, Git and CI/CD pipelines.

4 Cybersecurity Is Not One Job

Another common misunderstanding is that cybersecurity means "hacking". Penetration testing is only one small part of the cybersecurity industry. Cybersecurity includes many disciplines.

Defensive Security

Defensive security focuses on protecting organisations. Roles include: SOC Analyst, Security Analyst, Security Engineer, Detection Engineer, Incident Responder, Digital Forensics Analyst, Threat Hunter, Malware Analyst.

Offensive Security

Offensive security attempts to identify weaknesses by behaving like an attacker. Roles include: Penetration Tester, Red Team Operator, Application Security Tester, Security Researcher.

Security Engineering

Security engineers implement and operate security technologies. They may work with firewalls, endpoint detection and response, SIEM platforms, identity systems, email security, privileged access management, vulnerability management, cloud security and data loss prevention.

Identity Security

Identity has become one of the most important parts of modern cybersecurity. Roles include: IAM Analyst, IAM Engineer, Identity Architect, PAM Engineer.

Technologies might include Microsoft Entra ID, Active Directory, Okta, CyberArk, Ping Identity, SailPoint, authentication platforms, MFA systems and Single Sign-On.

Governance, Risk and Compliance

Cybersecurity is not entirely technical. GRC professionals help organisations understand and manage risk. They work with policies, regulations, cybersecurity frameworks, audits, risk assessments, vendor assessments, data protection and compliance programmes.

Common standards and frameworks include ISO 27001, the NIST Cybersecurity Framework, SOC 2, PCI DSS, GDPR and various national financial-sector regulations.

5 Role Deep Dive – Help Desk / Service Desk Analyst

Help Desk is one of the most common entry points into IT. In large organisations, the Help Desk may also be called Service Desk, IT Service Desk, IT Support, Level 1 Support or L1 Support.

The Service Desk normally acts as the first point of contact when an employee experiences a technology problem.

Typical responsibilities

You might receive requests such as:

  • "I forgot my password."
  • "My laptop cannot connect to Wi-Fi."
  • "Outlook is not working."
  • "My account is locked."
  • "I can't access this application."
  • "My VPN is disconnected."
  • "Microsoft Teams isn't detecting my microphone."
  • "I need access to a shared folder."

You may communicate with users through phone, email, chat, ticketing systems and remote support software.

Technologies you may encounter

A Service Desk analyst might use Windows, macOS, Microsoft 365, Active Directory, Entra ID, Intune, VPN clients, ServiceNow, Jira, remote desktop tools and antivirus/EDR software.

Skills employers look for

Technical knowledge is important, but communication is extremely important. A good Help Desk analyst can:

  1. gather information
  2. identify symptoms
  3. ask logical questions
  4. perform basic troubleshooting
  5. document what happened
  6. resolve the issue or escalate it correctly

Career progression

A common progression is:

Help Desk Desktop Support Systems Administration Cloud / Networking / Security

However, Help Desk is not a mandatory starting point. Someone with sufficient knowledge and practical experience may enter directly into another junior role.

6 Desktop Support Engineer

Desktop Support usually involves deeper endpoint troubleshooting than Service Desk. Desktop Support engineers often physically or remotely manage company laptops and desktops.

Typical responsibilities

You may install laptops, replace hardware, troubleshoot Windows, reinstall operating systems, configure printers, troubleshoot VPN clients, investigate performance problems, manage endpoint software, support executive users, configure monitors and docking stations, and troubleshoot device drivers.

In modern enterprises you may also work with Microsoft Intune, Windows Autopilot, Microsoft Configuration Manager, mobile device management, endpoint security platforms and software deployment systems.

Desktop Support is an excellent role for learning how enterprise IT environments actually function.

7 Technical Support Engineer

Technical Support Engineer is a particularly broad title. It often refers to supporting a company's product rather than its employees.

Imagine a cybersecurity company sells authentication software to banks. The bank experiences a problem with authentication. Instead of contacting its internal Help Desk, the bank opens a support case with the software vendor. A Technical Support Engineer working for that vendor may investigate the problem.

Responsibilities might include

Reproducing customer problems, analysing logs, troubleshooting APIs, analysing databases, inspecting network traces, analysing HTTP requests, debugging configuration, reading product documentation, investigating authentication failures, escalating software defects to engineering, coordinating major incidents, and communicating with customers.

You might work with customers across Europe, North America, Asia-Pacific, the Middle East and Africa — this makes communication extremely important.

Technical Support levels

Many companies use structures such as:

L1 – First-line supportBasic troubleshooting and case collection.
L2 – Technical SupportMore advanced troubleshooting.
L3 – Senior / Product SupportDeep product knowledge.
Engineering / DevelopmentSoftware defects or product changes.

Not every company uses exactly this structure.

8 Systems Administrator

A Systems Administrator manages the systems employees and applications depend upon. Traditionally this meant physical servers. Today it might include physical servers, virtual machines, cloud servers, identity systems, storage and SaaS platforms.

Typical responsibilities

A Systems Administrator might build Windows or Linux servers, create user accounts, manage Active Directory, manage Group Policy, install software, apply patches, monitor system performance, investigate outages, manage backups, renew certificates, maintain DNS, troubleshoot authentication and manage file servers.

You may sometimes hear the term "Sysadmin" — this simply means Systems Administrator.

Important skills

Strong Systems Administrators normally understand Windows, Linux, networking, Active Directory, DNS, virtualization, scripting, authentication, storage, backups and security fundamentals.

PowerShell and Bash become particularly useful because repetitive administration should increasingly be automated.

9 Network Engineer

Nearly everything in modern IT depends on networking. A Network Engineer designs, configures and troubleshoots the infrastructure that allows systems to communicate.

Technologies include

Routers, switches, firewalls, Wi-Fi, VPN, DNS, DHCP, load balancers, WAN connectivity and SD-WAN.

Networking concepts you must understand

Network Engineers need strong knowledge of IP addresses, subnetting, routing, switching, VLANs, DNS, NAT, TCP, UDP, VPNs and firewalls.

A network engineer might investigate a problem such as:

Users in the Singapore office can connect to an application hosted in Europe, but users in Tokyo cannot.

They may analyse routing, firewall rules, DNS, packet captures, latency, VPN tunnels and network policies.

Career progression

Network Support Network Engineer Senior Network Engineer Network Architect

Networking knowledge is also extremely valuable for cybersecurity.

10 SOC Analyst

SOC stands for Security Operations Centre. The SOC monitors systems for potential cybersecurity attacks. A SOC might operate 24 hours per day.

Large global organisations sometimes use teams across different regions so responsibility can pass between time zones. This is sometimes called follow-the-sun support. For example:

Asia-Pacific Europe North America Asia-Pacific

What does a SOC Analyst do?

They may investigate alerts generated by endpoint security, firewalls, cloud platforms, identity systems, SIEM platforms, email security and intrusion detection systems. Examples include suspicious PowerShell activity, malware detection, impossible travel, repeated login failures, suspicious administrator activity, unusual data transfers and phishing emails.

Common technologies

SOC analysts may use platforms such as Microsoft Sentinel, Splunk, Elastic, CrowdStrike, Microsoft Defender, Palo Alto and SentinelOne. The exact products are less important than understanding logs, networks, operating systems, authentication and attacker behaviour.

Career progression

SOC Analyst Senior SOC Analyst Incident Responder / Detection Engineer / Security Engineer / Threat Hunter

11 Security Engineer

A SOC Analyst frequently investigates security events. A Security Engineer is more likely to build and maintain the controls that generate or prevent those events.

For example, Security Engineers might configure EDR, firewalls, SIEM, MFA, privileged access, email security, vulnerability scanners, cloud security policies and web application firewalls.

The exact role varies significantly. Some Security Engineers are infrastructure specialists. Others focus on identity, cloud, endpoints, networks or applications.

A strong Security Engineer usually needs considerable understanding of general IT. This is one reason cybersecurity is often easier to understand after gaining experience with networking, Windows, Linux, cloud and identity.

12 Cloud Engineer

Companies are increasingly moving infrastructure from traditional data centres into cloud environments. The three major cloud ecosystems commonly encountered globally are Amazon Web Services, Microsoft Azure and Google Cloud Platform.

A Cloud Engineer may build virtual machines, networks, storage, databases, Kubernetes clusters, identity policies, serverless applications, monitoring and backups.

Cloud engineering increasingly involves Infrastructure as Code. Instead of manually creating twenty servers, an engineer might define infrastructure using code:

Terraform — creates Azure/AWS infrastructure Git — stores the configuration CI/CD pipeline — deploys the changes

This makes skills such as scripting and automation increasingly important.

Career progression

Systems Administrator Cloud Engineer Senior Cloud Engineer Cloud Architect

or

Cloud Engineer Platform Engineer DevOps / SRE

13 DevOps Engineer

DevOps is frequently misunderstood. DevOps is not simply "someone who knows Docker". The idea behind DevOps is to improve collaboration between Development and Operations.

Software developers create applications. Operations teams keep systems running. Historically these groups sometimes worked separately. DevOps practices attempt to make software delivery faster, more automated, more reliable and repeatable.

DevOps Engineers might work with

Git, GitHub, GitLab, Jenkins, Azure DevOps, Terraform, Ansible, Docker, Kubernetes, AWS, Azure, Linux, Python, Bash and CI/CD pipelines.

A DevOps engineer might automate the process:

Developer writes code Code pushed to Git Automated tests run Infrastructure created Application deployed Monitoring verifies deployment

DevOps roles are generally not true beginner positions because they require knowledge across several technical areas.

14 Penetration Tester

A Penetration Tester is authorised to attempt to compromise systems in order to discover security weaknesses. This is sometimes called ethical hacking.

The important word is authorised. Attempting to compromise systems without permission may be illegal.

Penetration testers may test

Websites, APIs, internal networks, Active Directory, cloud environments, mobile applications and wireless networks.

A penetration test normally involves

  1. defining scope
  2. reconnaissance
  3. enumeration
  4. identifying vulnerabilities
  5. controlled exploitation
  6. privilege escalation
  7. evidence gathering
  8. reporting
  9. remediation guidance

The final report is extremely important. Finding a vulnerability is useful. Explaining why it matters, how it can be exploited, what the business impact is, and how to fix it is what provides value to the customer.

OffSec's PEN-200, for example, focuses heavily on practical enumeration, exploitation and evidence gathering rather than purely theoretical knowledge.

15 Governance, Risk and Compliance – GRC

Not everyone in cybersecurity spends their day looking at terminals. GRC professionals work at the intersection of:

Technology+ Business+ Risk+ Regulation

They may ask questions such as: what information does the company hold? How sensitive is it? Who can access it? What happens if it is stolen? What regulations apply? Are our controls sufficient? What risks are we accepting?

Typical responsibilities

GRC professionals may perform risk assessments, create security policies, coordinate audits, review supplier security, maintain risk registers, prepare compliance evidence, and assess cybersecurity controls and ISO 27001 programmes.

They often work closely with Legal, Privacy, IT, Cybersecurity, Internal Audit and senior management.

GRC can be an excellent cybersecurity career for people who enjoy technology, business, communication, documentation and risk analysis but do not necessarily want a deeply technical engineering position.

16 Incident Response

Incident Responders investigate significant cybersecurity incidents. An incident might involve ransomware, compromised administrator accounts, stolen credentials, malicious insiders, data theft, cloud compromise, malware or supply-chain attacks.

Incident Response normally follows phases similar to:

  1. Preparation
  2. Detection
  3. Analysis
  4. Containment
  5. Eradication
  6. Recovery
  7. Lessons learned

During a serious incident, responders may work alongside SOC, infrastructure teams, security engineering, cloud teams, management, communications, legal teams, regulators and external forensic specialists.

Technical ability is important. However, communication under pressure is equally important. During a major cybersecurity incident, senior management does not want someone to say:

"There are weird logs in the SIEM."

They need to know:

"We have identified suspicious administrator activity affecting approximately 20 servers. We have isolated the affected accounts and are investigating whether customer data was accessed."

That is professional incident communication.

17 Other Careers Students Should Know About

The roles above represent only part of the industry. Students should also be aware of careers including:

Application Support Engineer

Supports business applications and production systems.

Database Administrator

Manages database platforms such as Oracle, Microsoft SQL Server, PostgreSQL and MySQL.

Site Reliability Engineer

Focuses on availability, reliability, automation and performance of large systems.

Platform Engineer

Builds internal platforms that development teams use to deploy applications.

IAM Engineer

Designs and manages identity and access systems.

Vulnerability Management Analyst

Identifies, prioritises and tracks security vulnerabilities.

Threat Intelligence Analyst

Studies attackers, campaigns, malware and emerging threats.

Security Architect

Designs how security controls should work across an organisation.

Cloud Security Engineer

Secures cloud infrastructure and services.

Application Security Engineer

Works with developers to secure software.

Digital Forensics Analyst

Collects and investigates digital evidence.

Security Awareness Specialist

Educates employees about security threats and behaviour.

IT Auditor

Evaluates whether organisational controls are operating effectively.

18 Salary Expectations

Salary is one of the most difficult parts of the technology industry to compare globally. The same job may pay dramatically different salaries depending on country, city, industry, company size, experience, technical specialisation, security clearance, certifications, shift work, on-call responsibilities and management responsibility.

A Cybersecurity Engineer in San Francisco should not expect the same numerical salary as someone performing similar work in Warsaw, London, Bangalore or Manila. You therefore need to understand salary bands, not simply search "cybersecurity salary".

Example – United States

Recent US labour data demonstrates the differences between career levels. US median pay for information security analysts was approximately $129,180 in May 2025, while network and computer systems administrators were around $99,130 in updated occupational data. Computer support roles sit considerably lower; BLS reported user-support specialists around $60,000 in its previous occupational breakdown.

These are national occupational figures rather than guarantees of what a new graduate will earn.

Example – United Kingdom

The UK's 2026 Robert Half technology salary data shows the same pattern. Examples include approximately:

  • Information Security Analyst: £42,250–£56,000
  • Security Network Engineer: £49,250–£70,750
  • DevOps Engineer: approximately £57,000–£81,000

depending on skills and experience. Again, London salaries may differ from other locations.

19 Never Compare Salaries Across Countries Using Currency Conversion Alone

Imagine Engineer A earns $100,000 in the United States. Engineer B earns €70,000 in Europe. Engineer C earns significantly less numerically in another market. It does not automatically mean Engineer C is being underpaid.

You also need to consider cost of living, taxation, healthcare, pension contributions, bonuses, stock, annual leave, employment protection and purchasing power.

Multinational organisations may also use geographical compensation bands. Two engineers working for the same company may therefore have different salaries because they live in different employment markets.

20 Total Compensation

Your basic salary is not always your total compensation. Packages can include annual bonus, company shares, Restricted Stock Units, pension contributions, private healthcare, life insurance, overtime, on-call payments, shift allowance, certification budgets, training budgets, company car and relocation assistance.

For example:

£70,000 base salary + 15% bonus + pension + shares

may be considerably more valuable than:

£75,000 salary with no additional benefits

Learn to evaluate the whole package.

21 Remote vs Hybrid vs Office Jobs

Modern technology teams may operate in three main ways.

Fully Office-Based

You attend the company's office most or all working days.

Advantages: easier access to colleagues, easier mentoring, physical access to hardware, strong networking opportunities, potentially easier for junior employees.

Disadvantages: commuting, less flexibility, limited geographical job market.

Hybrid

You work some days remotely and some days in the office — for example, 3 days home + 2 days office. Hybrid work remains common across the technology sector. The 2026 Robert Half UK technology research describes remote and hybrid working as firmly embedded within the sector, although employer policies continue to evolve.

Fully Remote

You work from home or another approved location. This sounds attractive, but fully remote work requires strong communication, time management, documentation and independence.

Junior employees should also understand that remote jobs are often highly competitive. Companies may also restrict where remote employees can work because of employment law, taxation, security requirements, data protection and customer contracts.

"Remote" does not necessarily mean "work from any country in the world."

22 What Is an MSP?

MSP means Managed Service Provider. An MSP manages technology for other organisations.

Imagine a company with 150 employees. It needs laptops, Microsoft 365, backups, networking and cybersecurity. Instead of hiring a large internal IT team, it may pay an MSP to provide those services.

A single MSP engineer may therefore support dozens of companies.

23 Working at an MSP

MSPs can be excellent places to start an IT career. You may encounter many technologies very quickly.

One morning: Microsoft 365 problem Later: Firewall problem Then: VPN issue Then: Active Directory problem Then: Backup failure

This creates broad experience.

Advantages: exposure to many technologies, different customers, rapid learning, many troubleshooting opportunities.

Challenges: busy ticket queues, strict SLAs, frequent context switching, significant customer interaction, potentially high workload.

MSPs are often excellent environments for developing troubleshooting ability.

24 Working in Enterprise IT

Enterprise IT means working inside a larger organisation — banks, airlines, governments, pharmaceutical companies, manufacturers, telecommunications companies, multinational retailers.

Instead of supporting many unrelated companies, you support one organisation. The technology environment may be enormous. A bank might have 80,000 employees, thousands of servers, multiple data centres, multiple cloud environments, thousands of applications and teams across 30 countries.

Your responsibilities may therefore become much more specialised. At an MSP you might manage Microsoft 365 + networking + backups + servers. At a global bank you might spend your entire job specialising in Active Directory authentication.

Neither approach is inherently better. They offer different types of experience.

25 MSP vs Enterprise

MSPEnterprise
Many customersOne organisation
Broad technical exposureGreater specialisation
Fast-movingOften more structured
Heavy ticket workloadMore defined responsibilities
Excellent troubleshooting exposureDeep enterprise technology exposure
Customer-facingMore internal collaboration
Often smaller environmentsVery large environments

A common career route is:

MSPEnterprise Specialist

because MSP experience can provide broad technical foundations.

26 Working for a Technology Vendor

Another major career path is working for the company that actually creates the technology. Examples of technology vendors include companies producing networking equipment, cybersecurity software, identity platforms, databases, cloud services and operating systems.

A vendor might have departments including Engineering, Product Management, Professional Services, Technical Support, Sales Engineering, Customer Success, Research and Security.

27 Vendor Technical Support

Suppose your company develops an authentication platform. Customers install that product around the world. When something goes wrong, they contact Technical Support.

The engineer may need to understand the product, networking, operating systems, databases, APIs, authentication, cloud infrastructure and customer architecture.

This can create extremely valuable technical experience. Vendor engineers can become specialists in complex enterprise systems used by some of the world's largest organisations.

28 Consultancy

Consultants normally help customers design systems, deploy products, migrate infrastructure, assess security and solve business problems.

A consultant might work on a three-month project for a bank and then move to another customer. Consultancy therefore normally involves considerable customer interaction, presentations, documentation, project work and travel in some roles.

29 Technical Support vs Consultancy

Consider this example. A customer wants to deploy a new authentication platform.

Professional Services / ConsultantDesigns the solution, installs it, configures it, integrates it, migrates users.
Six months later the system stops working
Technical SupportAnalyses logs, troubleshoots the failure, identifies the root cause, determines whether the product has a defect.

Meanwhile:

  • Engineering may fix the underlying software bug.
  • Product Management may decide whether a requested improvement belongs in a future release.

Understanding these boundaries is important in large technology companies.

30 How Global Companies Are Structured

A simplified multinational technology organisation might look like:

CEO CIO / CTO / CISO Vice Presidents Directors Heads of Department Managers Team Leads / Principal Engineers Senior Engineers Engineers Junior Engineers / Analysts

The exact titles differ considerably.

31 CIO vs CTO vs CISO

CIO – Chief Information Officer

The CIO normally focuses on internal technology supporting the business. This might include corporate IT, applications, infrastructure and digital transformation.

CTO – Chief Technology Officer

The CTO often focuses more heavily on technology strategy and, particularly in technology companies, the products or platforms the company builds. However, CIO and CTO responsibilities differ between organisations.

CISO – Chief Information Security Officer

The CISO is responsible for cybersecurity strategy and risk. The CISO organisation might contain Security Operations, Incident Response, Security Engineering, IAM, GRC, Security Architecture, Threat Intelligence, Application Security and Vulnerability Management.

32 Understanding Organisational Boundaries

Imagine a phishing attack compromises an employee account. Different teams may become involved.

Service DeskReceives the initial report.
SOCInvestigates suspicious login events.
Incident ResponseCoordinates investigation if compromise is serious.
IAM TeamDisables credentials.
Endpoint SecurityInvestigates the laptop.
Network SecurityChecks connections.
GRC / Privacy / LegalDetermines whether reporting obligations exist.
ManagementCoordinates business response.

Cybersecurity is therefore highly collaborative.

33 Global Teams

Large organisations may operate teams across several regions. You may hear:

  • EMEA – Europe, Middle East and Africa
  • APAC – Asia Pacific
  • NAM / NA – North America
  • LATAM – Latin America

A global support organisation might have:

SingaporeLondonNew York

allowing coverage 24 hours per day. This is called follow-the-sun.

Communication and documentation become extremely important because another engineer may need to continue your investigation after your working day finishes.

34 Tickets

Much of enterprise IT revolves around tickets. Examples include incidents, service requests, problems, changes and security cases.

Common platforms include ServiceNow, Jira, Zendesk and Salesforce.

A ticket creates a record of what happened, who is affected, what has been investigated, what actions have been taken, and who owns the issue. Ticket management will be explored later in this course.

35 Incidents vs Problems vs Changes

These terms have specific meanings.

Incident

Something is broken. Example: VPN service unavailable. Goal: restore service.

Problem

Investigate the underlying cause of repeated incidents. Example: Why does the VPN service crash every Friday?

Change

A planned modification. Example: Upgrade VPN software from version 8.2 to 8.3.

Changes may require testing, approval, rollback plans and change windows. This discipline becomes extremely important in banks, governments and other regulated organisations.

36 SLAs

SLA means Service Level Agreement. An SLA defines expectations around service. For support teams, this may include response time, restoration targets and availability.

Severity levels may look like:

  • P1 / Critical – Entire production service unavailable.
  • P2 / High – Major functionality affected.
  • P3 / Medium – Limited impact.
  • P4 / Low – Minor issue or question.

Every company defines severity differently. Never assume that P1 means exactly the same thing everywhere.

37 On-Call Work

Some IT jobs involve being on-call — examples include infrastructure, networking, cloud, security, DevOps, incident response and production support.

If a critical system fails at 02:00, the on-call engineer may be contacted. Before accepting such a job, ask:

  • How often is the rotation?
  • Is on-call paid?
  • How frequently are engineers contacted?
  • Is coverage global?
  • What constitutes an emergency?

On-call responsibilities can significantly affect work-life balance.

38 Career Progression

There is no single IT career ladder. One possible path is:

Help Desk Desktop Support Systems Administrator Senior Systems Engineer Cloud Engineer Cloud Architect

But someone else might take:

Help Desk SOC Analyst Security Engineer Senior Security Engineer Security Architect

Another person might take:

Network Support Network Engineer Network Security Engineer Security Engineer Security Architect

And another:

IT Support Junior Penetration Tester Penetration Tester Senior Penetration Tester Red Team Operator

These careers frequently overlap.

39 Individual Contributor vs Management

You do not necessarily have to become a manager to progress. Large technology companies often have two career tracks.

Management Track

Engineer Team Lead Manager Director VP CIO / CTO / CISO

Individual Contributor Track

Engineer Senior Engineer Staff Engineer Principal Engineer Distinguished Engineer / Architect

Titles vary enormously. A Principal Engineer may earn more than many managers. Technical expertise can therefore remain a career for decades.

40 Certifications – Do They Matter?

Yes. But certifications are frequently misunderstood. A certification should support your skills. It should not replace them.

Someone with ten certifications who cannot troubleshoot a simple DNS problem is less useful than someone with two certifications and genuine practical ability.

The strongest combination is:

Knowledge + Hands-on Experience + Certification + Communication

41 Entry-Level Certifications

For someone beginning an IT career, useful foundational certifications may include:

CompTIA A+

Useful for general IT support fundamentals. Topics normally include hardware, operating systems, troubleshooting, networking and security. Most useful for Help Desk / Desktop Support.

CompTIA Network+

Useful for networking foundations. Most useful for IT Support, Systems Administration and cybersecurity beginners. However, candidates interested specifically in networking may eventually gain more value from CCNA.

CompTIA Security+

A widely recognised general cybersecurity certification. Useful for understanding threats, security controls, identity, network security and risk. It can be useful for people moving from general IT toward security.

42 Cisco CCNA

CCNA remains one of the strongest foundational networking certifications. Cisco's current CCNA exam covers network fundamentals, network access, IP connectivity, IP services, security fundamentals, and automation and programmability.

CCNA can be valuable even if you do not plan to work entirely with Cisco equipment because the networking knowledge transfers across technologies.

Best suited to Network Engineers, Systems Engineers, Security Engineers and technical support professionals.

43 Microsoft Certifications

If you work in enterprise IT, Microsoft knowledge is extremely valuable. A useful foundational option is Azure Fundamentals – AZ-900. Microsoft describes AZ-900 as a beginner credential covering cloud concepts, Azure services, management and governance.

For security-focused students: Security, Compliance and Identity Fundamentals – SC-900, which covers foundational security, compliance and identity concepts across Microsoft cloud environments.

Microsoft now also provides Applied Skills, which use interactive labs to validate real tasks. For example, Microsoft's Entra identity Applied Skills credential assesses user management, groups, password protection, MFA and Conditional Access.

⚠ Course-maintenance note

Certification programmes change. For example, Microsoft retired MS-900 – Microsoft 365 Fundamentals – on 31 March 2026 and introduced newer Microsoft 365 learning and certification options such as AB-900.

Never blindly follow an old certification roadmap. Always check the vendor's current certification catalogue.

44 AWS Certifications

For students interested in cloud: AWS Certified Cloud Practitioner. AWS describes this as a foundational credential covering high-level AWS Cloud knowledge, services and terminology, and specifically positions it as a starting point for people without prior cloud experience.

Useful for cloud beginners, support professionals, technical sales, and IT professionals moving toward AWS.

For more technical cloud careers: AWS Certified Solutions Architect – Associate. This validates the ability to design solutions using AWS and the AWS Well-Architected Framework. This is more valuable for a Cloud Engineer than simply collecting several beginner certifications.

45 ISC2 Certifications

For cybersecurity beginners: ISC2 Certified in Cybersecurity – CC. ISC2 specifically positions CC for entry-level cybersecurity professionals and requires no previous experience. Topics include security principles, access controls, network security, incident response concepts and security operations.

For experienced professionals: CISSP. CISSP is significantly more advanced. It should not normally be treated as your first cybersecurity certification.

ISC2 requires five years of cumulative professional experience across at least two CISSP domains, with certain qualifications able to reduce the requirement by up to one year.

CISSP becomes particularly relevant for Senior Security Engineers, Security Architects, Security Consultants and Security Managers.

46 Penetration Testing Certifications

For offensive security, practical certifications can become valuable. One of the best-known examples is OSCP / OSCP+.

OffSec's PEN-200 training focuses on hands-on penetration testing including enumeration, exploitation, privilege escalation and evidence gathering.

OffSec itself describes PEN-200 as foundational penetration-testing training but recommends that learners already have solid TCP/IP, networking and Linux knowledge.

This is important. Do not start your cybersecurity journey by immediately attempting advanced penetration testing.

Learn:

Networking Linux Windows Active Directory Scripting Security fundamentals

then offensive security.

47 Certifications for GRC

Professionals progressing into governance and security management may eventually consider qualifications such as CISA, CISM, CISSP and ISO 27001-related certifications.

These are generally more useful once someone understands how organisations and security programmes actually operate. A beginner should not feel pressured to collect senior-level certifications immediately.

48 What Certifications Cannot Teach You

A certification exam cannot fully teach you:

  • how to deal with an angry customer
  • how to troubleshoot an unknown outage
  • how to write an executive incident update
  • how to communicate during a P1 incident
  • how to recognise when you need help
  • how to work with engineering
  • how to hand over an incident
  • how to investigate incomplete logs

These skills come from practical experience. That is why this course will place strong emphasis on practical labs.

49 Degrees vs Certifications vs Experience

There is no single correct route into IT. People enter the industry through university degrees, apprenticeships, internships, certifications, self-study, Help Desk roles and career changes.

A university degree can be extremely valuable. But it is not the only path. Likewise, certifications can help demonstrate knowledge. But certifications alone are not experience.

The ideal candidate might have strong fundamentals, practical labs, a certification, good communication and evidence of continuous learning.

50 Building Experience Without Having a Job

This creates a common problem:

"Every job wants experience. How do I get experience without a job?"

Build your own experience. Create a home lab.

For example:

Install VirtualBox / VMware / Hyper-V Install Windows Server Create Active Directory Create users Join Windows clients Configure DNS Create Group Policies Install Linux Create a small network Deploy a SIEM Generate security logs Investigate them

Now instead of saying:

"I studied Active Directory."

you can say:

"I created an Active Directory lab with a Windows Server domain controller, joined Windows clients to the domain, configured users, groups and Group Policy and troubleshot DNS and authentication issues."

That is considerably more powerful in an interview. We will build a full home lab later in this course.

51 What Employers Actually Want

Junior candidates often believe companies expect them to know everything. They don't.

A strong junior candidate demonstrates:

Fundamentals

You understand computers, networks, operating systems and security basics.

Curiosity

You investigate unfamiliar problems.

Logical troubleshooting

You do not randomly click buttons.

Communication

You explain problems clearly.

Documentation

You record what you did.

Honesty

You can say: "I don't know the answer, but here is how I would investigate it." That is often much better than pretending.

52 Technical Skills vs Soft Skills

As your career develops, technical skills alone become less sufficient. An engineer might be technically excellent but unable to explain an outage, write a clear ticket, communicate with customers, coordinate teams, or explain risk to management. That can limit career progression.

Senior engineers spend significant amounts of time writing, explaining, coordinating, mentoring, designing and reviewing. Communication is therefore a technical career skill.

53 What a Global Technology Incident Might Look Like

Imagine a bank's customers suddenly cannot authenticate to online banking. The bank opens a critical incident.

Service DeskReceives reports.
Application SupportConfirms the banking application is affected.
Network TeamChecks connectivity.
Database TeamChecks database health.
IAM TeamInvestigates authentication.
Vendor SupportInvestigates the authentication product.
EngineeringReviews whether a software defect exists.
Incident ManagerCoordinates the response.
ManagementReceives status updates.

This is much closer to real enterprise IT than the common image of one person sitting alone "fixing computers".

54 Career Progression Is Based on More Than Years

Two people may both have five years of experience.

Person A: has repeated the same basic tasks for five years.

Person B: has progressively handled complex incidents, architecture, automation, customer communication, mentoring and major outages.

Person B may progress much faster. Career progression depends on increasing:

  • Scope – how much technology you understand.
  • Complexity – how difficult the problems are.
  • Responsibility – how much the company trusts you with.
  • Impact – how important the systems you work on are.

55 Specialist vs Generalist

Early in your career, being a generalist is valuable. Learn Windows, Linux, networking, cloud, security and scripting.

As you progress, you may specialise. For example:

General IT Engineer Identity Engineer Senior IAM Engineer Identity Architect

The strongest specialists still understand the technologies surrounding their speciality. A security engineer who does not understand networking will eventually struggle. A cloud engineer who does not understand identity will eventually struggle. A penetration tester who does not understand operating systems will eventually struggle.

Fundamentals matter.

56 A Realistic Career Strategy

Do not start with: "I want to become a CISO."

Start with: "What skills do I need for my next role?"

Goal: Security Engineer

Potential route:

Help Desk Systems Administration SOC / Security Analyst Security Engineer

During the journey learn Windows, Linux, networking, Active Directory, cloud, logs, scripting and cybersecurity.

Goal: Cloud Engineer

Potential route:

IT Support Systems Administration Cloud Administrator Cloud Engineer

Learn Linux, networking, AWS/Azure, PowerShell/Python, Git, Terraform and containers.

Goal: Penetration Tester

Potential route:

IT Fundamentals Networking + Linux Active Directory Security Fundamentals Web Security Penetration Testing

Do not skip the foundations.

57 What Students Should Take Away From This Module

By the end of this module, you should understand that the technology industry is an ecosystem. IT is not one job. Cybersecurity is not one job.

Companies need people who support users, operate infrastructure, manage networks, build cloud environments, monitor security, respond to incidents, test systems, assess risk, design architecture and support customers.

The important question is not:

"What is the best IT job?"

The better question is:

"Which area interests me, and what skills do I need to reach it?"

Practical Exercise 1 – Choose Three Careers

🧪 Practical exercise

Choose three roles from this module. For each role research:

  1. What does the person do?
  2. What technologies do they use?
  3. What entry-level knowledge is expected?
  4. What jobs normally come before it?
  5. What jobs can it lead to?
  6. What is the salary range in your country?
  7. Find three real job advertisements.
  8. Identify the five skills appearing most frequently.

Do not simply look at job titles. Read the actual job descriptions.

Practical Exercise 2 – Read Enterprise Job Descriptions

🧪 Practical exercise

Search major international employers such as technology companies, banks, consultancies, cybersecurity vendors and cloud providers.

Search for: "Technical Support Engineer", "Security Analyst", "Cloud Engineer", "Network Engineer".

Compare five advertisements. Notice how dramatically the responsibilities can differ despite having the same job title.

Practical Exercise 3 – Design Your Career Path

🧪 Practical exercise

Write down:

My target role:

Skills required:

Technologies I need to learn:

Useful certifications:

Home lab projects I could build:

Possible first job:

Possible second job:

Three-year goal:

Knowledge Check

Click a question once you're confident you can answer it from memory — it's a quick way to see what's actually stuck versus what needs a re-read.

0 / 15 reviewed

Final Lesson

If you remember only one thing from Module 1, remember this:

Do not chase cybersecurity before understanding IT.

Cybersecurity protects computers, networks, identities, applications, databases and cloud environments. If you do not understand how those technologies normally work, it becomes much harder to understand how they fail or how attackers exploit them.

Throughout this course we will therefore build your knowledge in layers:

Computer Fundamentals Networking Operating Systems Active Directory and Identity Cloud Cybersecurity Security Operations Incident Response Automation and Troubleshooting Professional IT Skills Getting Your First Job

By the end, the goal is not simply for you to know cybersecurity terminology. The goal is for you to understand how real IT environments operate and how you can become useful inside one.