Breaking In — Resources
Companion link list for the Breaking Into Security field guide.
Hands-on labs
- TryHackMe — guided paths from zero; strong SOC/defense tracks.
- Hack The Box — realistic practice machines and an academy track.
- LetsDefend — blue-team alert triage in a simulated SOC.
- OverTheWire — free, terminal-first wargames; Bandit is a classic Linux warm-up.
- PortSwigger Web Security Academy — free and excellent for web/AppSec fundamentals.
Certifications
- CompTIA Security+ — the standard first cert and HR filter.
- ISC2 Certified in Cybersecurity (CC) — entry-level; ISC2 has run free/cheap exam programs for it.
- CompTIA CySA+ — the defense-side follow-on.
- OffSec OSCP — the hands-on offense benchmark; for later, not first.
- SANS/GIAC — deep, role-specific, excellent, and expensive; ideally employer-funded.
- ISC2 CISSP — the management-track staple; check how your IT years count toward its experience requirement.
Community
- BSides — find the nearest city's event; the best first security conference.
- DEF CON groups — local recurring meetups.
- Risky Business — weekly news podcast with real analysis.
- SANS Internet Storm Center — daily diary of what's actually being attacked.
- Krebs on Security — long-running investigative security journalism.
Healthcare security (the niche)
- HHS HIPAA Security Rule — the regulatory floor, from the source.
- HITRUST — the framework healthcare vendors get certified against.
- FDA medical device cybersecurity — premarket and postmarket expectations for device makers.
- Health-ISAC — the sector's threat-sharing community.
- HHS 405(d) / HICP — practical healthcare cybersecurity practices, sized for small through large organizations.
Free structured learning
- Professor Messer — free full video courses for the CompTIA track.
- Cybrary — free-tier courses across security roles.
- MITRE ATT&CK — the shared map of attacker techniques; skim it early, absorb it forever.