Enterprise cybersecurity technology research that connects the dots.

Free Training's Role in Cybersecurity

It's easy to find free training in cybersecurity, but is free the best option for entering the field?

A woman looks at a laptop computer screen with a blackboard image of formulas and equations behind her.
Source: Gerd Altmann via Pixabay

How far can you go for free? It's an interesting question if you're traveling, but it can be critical if you're trying to build a career in cybersecurity. In the last few months, a number of vendors and organizations have announced new or expanded rosters of free cybersecurity classes. Would it be possible to launch a career based only on the not-for-charge offerings?

From the Ground Up

There's no question that our industry is dramatically short of skilled and trained professionals to deal with the daily onslaught of attacks and attempted exploits. There is a very real question about the best way to close the gap between open positions and available talent.

One potential method of closing the talent gap isn't a realistic option: There is no way to put enough human beings through formal certification training to meet the need. When I talk to executives at training companies, all admit that, as good as they are, there's just not enough time/bandwidth/money for them to take all the necessary candidates through the process. And that conversation doesn't even begin to look at the question of whether the candidates could afford the time and investment to take the courses.

Among the answers offered to this question is the availability of free training classes in cybersecurity. Recent months have seen a wave of new no-cost options for those interested in getting into cybersecurity. Among the options are:

  • FedVTE: The Federal Virtual Training Environment offers free courses on many topics for US military veterans along with federal, state, local, tribal, and territorial government employees, and federal contractors.

  • IBM: IBM SkillsBuild uses Coursera to deliver training for cybersecurity analyst as well as a wide variety of other IT professional positions. Some courses leading to "badges" are free; some certification requires payment.

  • Cybrary: In February, Cybrary announced that more than 500 hours of cybersecurity courses were being made available at no charge. These courses cover topics ranging from cybersecurity fundamentals to professional certification prep as well as role-based material for professional development.

  • SANS: SANS offers courses beginning with the Cyber Aces program on awareness, continuing with free workshops and the ability to "test drive" courses that will be paid offerings. Membership in the SANS.org community is also free and provides access to information from many cybersecurity professionals and instructors.

  • Oxford Home Study: Based in the UK, this organization offers a number of different cybersecurity courses at no cost, some leading to the possibility of certification in cybersecurity.

There are others, of course, but all present the same question to would-be cybersecurity professionals: How far can I go with free courses?

The answer lies as much in what they don't provide as in what they do. With rare exceptions, the free courses can provide knowledge but not credentials. And while that is not the issue in cybersecurity that it might have been 10 years ago, it can't be completely ignored.

Sidestepping Credentials

So what is the aspiring cybersecurity professional to do? First, definitely take advantage of free knowledge. Though they may take you only so far, free courses can take a budding cybersecurity professional beyond a first step. Next, get some hands-on experience. For those who are not employed in cybersecurity (and even those who are), capture-the-flag (CTF) exercises can be a valuable and accessible way to gain experience in the hands-on details of the field.

Next, the free courses can be a valuable tool when deciding whether or not it would be worthwhile to invest in a paid course in cybersecurity. In too many cases, the only way to find out whether a field is right for an individual is to spend money to become educated in that field. In cybersecurity, though, individuals have the opportunity to find out whether they want to pursue a career without making a huge monetary investment.

And the Enterprise?

A business could be sorely tempted to turn employees toward free courses when the individuals ask for professional training. And if the individual says that they're curious about cybersecurity, free courses could be an appropriate answer. But for professional training that will create an individual ready to step onto the beginning track of cybersecurity, there are paid courses of study that offer much more in the way of training, assessment, and accountability than do the free options.

Free courses in cybersecurity are good for the industry and for individuals, but they have a role to play in cybersecurity training and shouldn't be asked to go wildly beyond that role. Keep expectations realistic and opportunities for hands-on experience readily available, and free courses can play a solid supporting role in early cybersecurity career development.

About the Author(s)

Curtis Franklin, Principal Analyst, Omdia

Curtis Franklin Jr. is Principal Analyst at Omdia, focusing on enterprise security management. Previously, he was senior editor of Dark Reading, editor of Light Reading's Security Now, and executive editor, technology, at InformationWeek, where he was also executive producer of InformationWeek's online radio and podcast episodes

Curtis has been writing about technologies and products in computing and networking since the early 1980s. He has been on staff and contributed to technology-industry publications including BYTE, ComputerWorld, CEO, Enterprise Efficiency, ChannelWeb, Network Computing, InfoWorld, PCWorld, Dark Reading, and ITWorld.com on subjects ranging from mobile enterprise computing to enterprise security and wireless networking.

Curtis is the author of thousands of articles, the co-author of five books, and has been a frequent speaker at computer and networking industry conferences across North America and Europe. His most recent books, Cloud Computing: Technologies and Strategies of the Ubiquitous Data Center, and Securing the Cloud: Security Strategies for the Ubiquitous Data Center, with co-author Brian Chee, are published by Taylor and Francis.

When he's not writing, Curtis is a painter, photographer, cook, and multi-instrumentalist musician. He is active in running, amateur radio (KG4GWA), the MakerFX maker space in Orlando, FL, and is a certified Florida Master Naturalist.

Keep up with the latest cybersecurity threats, newly discovered vulnerabilities, data breach information, and emerging trends. Delivered daily or weekly right to your email inbox.

You May Also Like


More Insights