Study Materials

CyberPrepHub ยท Study Resources

Cybersecurity Study Materials & Training Platforms

Cybersecurity is too broad to learn effectively from one source. The strongest study plans normally combine structured theory, hands-on practice, reference books and repeated problem-solving.

This page brings together online course providers, hacking labs, cyber ranges, DevSecOps training, free practice environments and recommended books for learners ranging from complete beginners to experienced security professionals.

๐ŸŽ“

Learn the Theory

Use structured courses to build foundations and prepare for certifications.

COURSES
๐Ÿงช

Practise the Skills

Use legal lab environments to apply what you learn against realistic systems.

HANDS-ON LABS
๐Ÿ“š

Build a Reference Library

Books are useful for deeper explanations, revision and long-term reference.

BOOKS
Referral disclosure

The Udemy links on this page use a CyberPrepHub referral/tracking link. If you make a qualifying purchase after using that link, CyberPrepHub may receive a commission at no additional cost to you. Other links on this page are normal external links unless stated otherwise.

Course catalogues, subscriptions, prices and book availability can change. This resource page was reviewed in August 2026.

How to Use These Resources

Avoid collecting subscriptions without a study plan. Pick resources that serve different purposes.

1. Learn

Use a structured course or book to understand the concept first.

2. Practise

Reproduce the concept in a safe lab such as TryHackMe, HackerDNA, Hack The Box or PortSwigger Academy.

3. Explain

Write your own notes and make sure you can explain why the technique or control works.

4. Repeat

Return to the same concept through a different platform, scenario or question set.

5. Apply

Use realistic challenges, projects or certification practice to test whether the knowledge transfers.

6. Review

Revisit weak areas rather than repeatedly studying topics you already know.

Simple Study Formula

THEORYUnderstand it
LABDo it
NOTESExplain it
REPEATRemember it
SCENARIOApply it

Quick Platform Guide

ResourceBest Used ForTypical Learning Style
UdemyAffordable individual courses and certification preparationVideo-led courses
PluralsightStructured technology and security skill pathsCourses + paths + labs
CourseraUniversity/company programmes and professional certificatesStructured programmes
TryHackMeBeginner-friendly practical cybersecurityGuided rooms + labs
HackerDNAEthical hacking and penetration-testing practiceCourses + isolated hacking labs
Hack The BoxDeeper offensive, defensive and job-role skillsAcademy + realistic labs
ImmersiveEnterprise cyber-skills development and cyber resilienceHands-on labs + exercises
Practical DevSecOpsDevSecOps, AppSec and AI-security engineeringCourses + browser labs + practical exams
PortSwigger Web Security AcademyWeb application and API securityFree theory + exploit labs
OverTheWireLinux, shell and foundational exploitation skillsFree wargames
Structured Learning

Online Course Platforms

These platforms are useful when you want a structured explanation before moving into practical labs.

Udemy

A large course marketplace with cybersecurity training covering certification preparation, ethical hacking, penetration testing, cloud security, Linux, Python, networking, governance and many specialist topics. Course quality varies by instructor, so check the curriculum, update date and learner feedback before buying.

Certification + broad cyber topics Beginner โ†’ Advanced Paid courses / regional options

Good searches to try:

CISSP Security+ Ethical Hacking Penetration Testing Cloud Security Linux Python DevSecOps

Explore Udemy โ†’

Pluralsight

A technology-skills platform with cybersecurity courses, guided learning paths, assessments and hands-on labs. It is particularly useful for learners who also want strong coverage of the underlying IT, cloud, development and infrastructure technologies that security professionals need to understand.

Tech depth + security paths Beginner โ†’ Professional Subscription

Explore Pluralsight Security โ†’

Coursera

A learning platform offering courses and professional certificates from universities and major technology companies. Cybersecurity options include beginner career programmes as well as more specialised study in risk, cloud, networking, security operations and related subjects.

Structured certificates Beginner โ†’ Intermediate Courses / subscriptions

Explore Cybersecurity on Coursera โ†’

Using Udemy Effectively

Certification Preparation

Useful for CISSP, CompTIA Security+, CySA+, PenTest+, cloud certifications and other exam-focused study.

Technical Foundations

Search for networking, Linux, Windows, Active Directory, Python, PowerShell and cloud fundamentals.

Offensive Security

Courses cover ethical hacking, web penetration testing, privilege escalation, Active Directory attacks and red-team topics.

Defensive Security

Look for SOC, SIEM, incident response, threat hunting, malware analysis and digital forensics courses.

Application Security

Useful searches include OWASP, secure coding, API security, threat modelling and DevSecOps.

Choose Carefully

Prefer recently updated courses with a clear curriculum, hands-on exercises and instructors who demonstrate the techniques rather than only reading slides.

Browse Udemy using the CyberPrepHub referral link โ†’

โ–ถ๏ธ Useful Pluralsight Starting Points Structured paths for foundations, certification and management
  • Information and Cyber Security Foundations - covers foundational Windows, Linux, networking and application knowledge useful before deeper security study.
    Open the Foundations path
  • Security Certifications - certification-oriented learning across security architecture, operations, threats and governance.
    Browse security certification training
  • Cyber Security Management - useful for learners moving toward security leadership, programme design, policy and enterprise security strategy.
    Open the Cyber Security Management path
๐ŸŽ“ Cybersecurity Programmes on Coursera Good structured starting points from major organisations

Google Cybersecurity Professional Certificate

A beginner-focused professional certificate covering the work of entry-level cybersecurity analysts and foundational security skills. No previous professional experience is required by the programme.

Entry-level analyst Beginner Professional Certificate

View Google Certificate โ†’

IBM Cybersecurity Analyst Professional Certificate

A structured analyst programme covering practical cybersecurity concepts and tools, with content intended to help learners build entry-level analyst skills.

SOC / analyst foundations Beginner Professional Certificate

View IBM Certificate โ†’

Microsoft Cybersecurity Analyst Professional Certificate

A Microsoft-led programme aimed at learners building job-ready cybersecurity analyst skills and familiarity with Microsoft security technologies.

Microsoft security + analyst Beginner Professional Certificate

View Microsoft Certificate โ†’

IBM & ISC2 Cybersecurity Specialist

A programme designed to build cybersecurity foundations while helping learners prepare for the ISC2 Certified in Cybersecurity - CC - certification.

ISC2 CC preparation Beginner Professional Certificate

View IBM & ISC2 Programme โ†’

Learn by Doing

Hands-On Hacking & Cybersecurity Platforms

Practical platforms give you systems that are intentionally designed for training. They let you practise scanning, exploitation, investigation and defence without attacking systems you do not own.

Only perform security testing against systems you own or environments where you have explicit permission. Training labs and CTF platforms exist specifically to provide safe and legal targets.

TryHackMe

What it is

A guided cybersecurity learning platform with interactive rooms, labs and learning paths. TryHackMe currently advertises more than 1,000 training labs and pathways spanning beginner through experienced learners.

Best used for
Beginners Networking Linux Web Security SOC Offensive Security Defensive Security

The Pre Security path is a good option for people starting from the fundamentals, while paths such as SOC Level 1 move into practical defensive-security analysis.

Explore TryHackMe learning paths โ†’

HackerDNA

What it is

HackerDNA is a hands-on cybersecurity platform combining courses with isolated hacking labs. Its current catalogue spans beginner through advanced ethical hacking, penetration testing and security-certification skills.

Topics currently represented
Linux & Kali Web Security API Security Active Directory Cloud Mobile OSINT Reverse Engineering

Labs are graded by difficulty, making HackerDNA useful for progressively developing ethical-hacking and penetration-testing skills rather than jumping immediately into advanced targets.

Visit HackerDNA โ†’

Hack The Box & HTB Academy

HTB Academy

Guided training modules and skill/job-role paths that explain the theory and then require practical exercises. HTB describes Academy as suitable from beginner through advanced levels.

Hack The Box Labs

A large collection of practical systems, challenges and attack/defence content. It is particularly valuable once you are comfortable working more independently.

Penetration Testing Red Team Blue Team Active Directory Web Cloud Forensics Threat Hunting

Visit HTB Academy โ†’    Visit Hack The Box โ†’

Immersive

Immersive, widely known for Immersive Labs, is primarily positioned as an organisational cyber-resilience and skills platform. It provides hands-on, scenario-based labs across technical cybersecurity disciplines and broader team readiness.

Offensive Security

Attack-focused exercises and realistic technical scenarios.

Defensive Security

Threat detection, incident response, SOC and defensive-security practice.

Cloud Security

Hands-on content across AWS, Azure and GCP security topics.

Application Security

Developer and engineering labs covering secure coding and AppSec concepts.

AI Security

Current labs include areas such as prompt injection and defending AI-enabled systems.

Cyber Drills

Team exercises can recreate realistic incidents to test organisational readiness.

Who is it best for?

Immersive is particularly useful if your employer, university or organisation already provides access. Its product positioning is more enterprise/team focused than consumer subscription platforms such as TryHackMe.

Explore Immersive hands-on labs โ†’

Specialist Engineering Training

Practical DevSecOps

Practical DevSecOps specialises in hands-on training and certifications for DevSecOps, application security and AI security.

It is a strong choice for security professionals who already understand general cybersecurity and want to learn how security controls are integrated into software development and CI/CD pipelines.

Secure CI/CD

Learn how security testing and controls are integrated into modern build and deployment pipelines.

SAST / DAST / SCA

Practise common application-security testing approaches within development workflows.

Infrastructure as Code

Apply security controls to programmable infrastructure and deployment configuration.

Vulnerability Management

Learn how findings are triaged and managed as part of engineering workflows.

Application Security

Move beyond generic hacking into secure software engineering and AppSec programme concepts.

AI Security

Current specialist material includes hands-on AI/LLM security and AI supply-chain topics.

๐Ÿงฐ Example: Certified DevSecOps Professional - CDP Hands-on DevSecOps training

Practical DevSecOps currently describes its CDP course as hands-on training in secure CI/CD, SAST, DAST, SCA and Infrastructure as Code security, with practical browser-based lab work and a challenge-based exam.

View the Certified DevSecOps Professional course

Visit Practical DevSecOps โ†’

PortSwigger Web Security Academy

One of the strongest free resources for learning web application security. PortSwigger describes Web Security Academy as a 100% free online training centre with learning material and interactive labs.

SQL Injection XSS Authentication Access Control SSRF Request Smuggling API Testing Web Cache Attacks LLM / AI Web Attacks

It is also an excellent way to learn Burp Suite while practising against deliberately vulnerable applications.

Start Web Security Academy โ†’

Free Resources Worth Knowing

More Hands-On Practice

OverTheWire

A classic collection of free cybersecurity wargames. Bandit teaches Linux and shell fundamentals, Natas focuses on server-side web security, and other games move into exploitation concepts.

Linux + fundamentals Beginner โ†’ Intermediate Free

Explore OverTheWire โ†’

CyLab Security Academy / picoCTF

Carnegie Mellon University's free cybersecurity learning platform. In 2026, the picoCTF learning experience moved into the broader CyLab Security Academy while retaining the team's challenge-based learning approach.

CTF + broad foundations Beginner โ†’ Intermediate Free

Visit CyLab Security Academy โ†’

Cisco Skills for All

Cisco's free learning environment includes introductory cybersecurity, networking, network defence and career-path material. It is particularly useful for learners who need stronger networking foundations.

Networking + cyber foundations Beginner Free

Explore Cisco Cybersecurity โ†’

ISC2 Self-Study Resources

Official self-study material for ISC2 certifications, including exam outlines, training options, study resources and certification-specific materials.

ISC2 certification Certification candidates Free + paid options

Explore ISC2 Resources โ†’

Choosing a Platform

What Should I Use?

Your GoalGood Starting Combination
I am completely new to cybersecurityCoursera or Cisco Skills for All + TryHackMe Pre Security + a beginner book
I want Security+ or another foundation certificationUdemy / Pluralsight + official study guide + TryHackMe
I am studying CISSPCISSP Official Study Guide + CyberPrepHub + Udemy / Pluralsight + practice questions
I want to become a penetration testerTryHackMe โ†’ HackerDNA โ†’ HTB Academy โ†’ Hack The Box labs
I want web / application securityPortSwigger Web Security Academy + Hacking APIs + HTB / TryHackMe web labs
I want DevSecOpsPractical DevSecOps + Pluralsight + cloud/platform fundamentals
I want SOC / blue-team skillsTryHackMe SOC paths + HTB Academy defensive content + Immersive if available through work
I want strong Linux fundamentalsLinux Basics for Hackers + OverTheWire Bandit + TryHackMe Linux rooms
I want security engineering / architecture depthSecurity Engineering + Pluralsight + cloud/security architecture study
Recommended Reading

Cybersecurity Books

Courses are excellent for guided learning, but a good technical book is often better when you need a detailed explanation, want to revisit a concept or need a reference beside you while working through labs.

The books below are grouped by purpose rather than ranked. Amazon availability and editions can change, so always check that the edition matches the certification or technology you are currently studying.

Certification Study

Certification Books

ISC2 CISSP Official Study Guide, 10th Edition

Author: Mike Chapple, James Michael Stewart & Darril Gibson

One of the primary books for CISSP preparation. This edition was updated for the 2024 CISSP exam outline and provides broad coverage across all eight CISSP domains.

CISSP / Advanced Book Amazon UK

View on Amazon UK โ†’

CompTIA Security+ Study Guide - Exam SY0-701, 9th Edition

Author: Mike Chapple & David Seidl

A structured Security+ study guide covering the SY0-701 exam objectives. Useful for learners building a broad foundation before moving into specialist security areas.

Beginner / Security+ Book Amazon UK

View on Amazon UK โ†’

Architecture & Engineering

Security Engineering & Design

Security Engineering: A Guide to Building Dependable Distributed Systems, 3rd Edition

Author: Ross Anderson

A deep security-engineering reference covering how dependable systems are designed, attacked and defended. Excellent for experienced practitioners, architects and anyone who wants security knowledge beyond exam memorisation.

Intermediate โ†’ Advanced Book Amazon UK

View on Amazon UK โ†’

Threat Modeling: Designing for Security

Author: Adam Shostack

A detailed guide to threat modelling, including structured ways to identify what can go wrong and turn threat analysis into engineering decisions.

Intermediate Book Amazon UK

Note: Published earlier than several books on this page, but remains a widely used conceptual threat-modelling reference.

View on Amazon UK โ†’

Designing Secure Software: A Guide for Developers

Author: Loren Kohnfelder

A practical guide to building security into software design. Useful for developers, AppSec practitioners, security consultants and anyone studying secure SDLC principles.

Beginner โ†’ Intermediate Book Amazon UK

View on Amazon UK โ†’

Application Security

AppSec & Secure Coding Books

Alice and Bob Learn Application Security

Author: Tanya Janca

An accessible AppSec book covering security requirements, secure design, secure coding, threat modelling, testing and building an application-security programme.

Beginner โ†’ Intermediate Book Amazon UK

View on Amazon UK โ†’

Alice and Bob Learn Secure Coding

Author: Tanya Janca

A developer-focused secure-coding guide designed to make common security mistakes and safer implementation patterns easier to understand.

Developer / AppSec Book Amazon UK

View on Amazon UK โ†’

Hacking APIs: Breaking Web Application Programming Interfaces

Author: Corey J. Ball

A hands-on introduction to testing modern APIs. Useful for penetration testers, bug bounty hunters and AppSec practitioners who want practical API-security methodology.

Intermediate Book Amazon UK

View on Amazon UK โ†’

Bug Bounty Bootcamp

Author: Vickie Li

A practical guide to web hacking and bug bounty methodology, including reconnaissance, finding vulnerabilities, reporting them professionally and developing a repeatable testing workflow.

Beginner โ†’ Intermediate Book Amazon UK

View on Amazon UK โ†’

Hands-On Offensive Skills

Linux, Hacking & Automation

Linux Basics for Hackers, 2nd Edition

Author: OccupyTheWeb

A beginner-friendly introduction to Linux using Kali Linux as the learning environment. Covers command-line skills, networking, scripting and security-oriented Linux tasks.

Beginner Book Amazon UK

View on Amazon UK โ†’

Black Hat Python, 2nd Edition

Author: Justin Seitz & Tim Arnold

Shows how Python can be used to build security and penetration-testing tools. Best used after you already understand basic Python syntax and networking concepts.

Intermediate Book Amazon UK

View on Amazon UK โ†’

Practical Malware Analysis

Author: Michael Sikorski & Andrew Honig

A classic hands-on guide to analysing malicious software using static analysis, debugging, disassembly and controlled lab environments.

Intermediate โ†’ Advanced Book Amazon UK

Note: Some tools and screenshots are older, but the core malware-analysis methodology remains useful. Pair it with modern tooling and current labs.

View on Amazon UK โ†’

Cloud & DevSecOps

Cloud Security & DevSecOps Books

Practical Cloud Security, 2nd Edition

Author: Chris Dotson

A practical guide to cloud security across areas such as data protection, IAM, vulnerability management, network security and incident response in multicloud environments.

Intermediate Book Amazon UK

View on Amazon UK โ†’

Securing DevOps: Security in the Cloud

Author: Julien Vehent

Explains how security can be integrated into DevOps and cloud-service delivery, including CI/CD and infrastructure-focused security thinking.

Intermediate Book Amazon UK

Note: An older DevSecOps text, so use it for principles and architecture rather than current product-specific commands.

View on Amazon UK โ†’

If You Only Buy a Few Books

GoalSuggested Book
Prepare for CISSPCISSP Official Study Guide, 10th Edition
Build cybersecurity foundationsCompTIA Security+ Study Guide - SY0-701
Understand security architecture deeplySecurity Engineering - Ross Anderson
Start ethical hackingLinux Basics for Hackers, 2nd Edition
Learn web / application securityAlice and Bob Learn Application Security
Practise web hackingBug Bounty Bootcamp
Learn API penetration testingHacking APIs
Learn secure software designDesigning Secure Software
Learn cloud securityPractical Cloud Security, 2nd Edition
Putting It Together

Example Study Roadmaps

๐ŸŒฑ Beginner Cybersecurity Roadmap Build the technical base first
Cisco / Coursera Foundationsโ†’Core Theory
TryHackMe Pre Securityโ†’Hands-On Basics
OverTheWire Banditโ†’Linux & Shell
Security+ Materialโ†’Broad Security Foundation
Choose a Specialismโ†’Blue / Red / AppSec / Cloud / GRC
๐Ÿ”ด Penetration Testing Roadmap Move from guided labs to independent targets
Linux + Networkingโ†’Technical Foundation
TryHackMeโ†’Guided Attacks
PortSwigger Academyโ†’Web Exploitation
HackerDNA / HTB Academyโ†’Deeper Techniques
Hack The Box Labsโ†’Independent Practice
Writeups + Notesโ†’Build Methodology
๐Ÿ›ก๏ธ Blue-Team / SOC Roadmap Detection, investigation and response
Networking + Windows + Linuxโ†’Systems Foundation
TryHackMe SOC Pathsโ†’Guided Analysis
HTB Academy Defensive Modulesโ†’Threat Hunting / Forensics
Immersive - if availableโ†’Enterprise Scenarios
Home Lab / SIEM Practiceโ†’Operational Experience
๐Ÿ” AppSec / DevSecOps Roadmap Secure software from code to deployment
Programming + Git + Web Fundamentalsโ†’Engineering Base
PortSwigger Academyโ†’Understand Web Vulnerabilities
Alice & Bob / Designing Secure Softwareโ†’Secure Design
Hacking APIsโ†’API Security
Practical DevSecOpsโ†’CI/CD Security
Cloud + IaCโ†’Modern Deployment Security

Do Not Try to Use Everything at Once

ONE COURSEFor structure
ONE LAB PLATFORMFor practice
ONE MAIN BOOKFor depth
YOUR OWN NOTESFor retention
REAL SCENARIOSFor application

The best resource is the one you actively work through - not the tenth subscription sitting unused in your browser.

๐Ÿ“š Platform & Book Sources Official sites and verified book listings used to review this page