Preparing for Your MSc in Cyber Security
A Practical Guide for New Master's Students
Dr Kyounggon Kim, Course Leader, MSc Cyber Security
Welcome
Congratulations on joining the MSc Cyber Security course.
Starting a master's degree is both exciting and challenging. Compared with undergraduate study, you will be expected to learn more independently, think critically, and engage with current research while developing practical technical skills.
This guide brings together recommendations that I frequently share with new students. You do not need to master everything before the course begins, but becoming familiar with these areas will help you make a strong start.
1. Strengthen Your Foundations
Before the course starts, I recommend reviewing the following topics.
-
Computer Networking (TCP/IP, DNS, HTTP/HTTPS, Routing)
-
Linux fundamentals and command-line usage
-
Basic Windows administration
-
Python programming
-
Git and GitHub
-
Virtual machines (VMware or VirtualBox)
These topics will make many of the practical sessions much easier to follow.
2. Learn Python
Python is one of the most useful programming languages in cyber security.
You do not need to become an expert before September, but you should feel comfortable with variables, loops, functions, file handling, and basic object-oriented programming.
Python is widely used for scripting, automation, malware analysis, digital forensics, artificial intelligence, and penetration testing.
3. Become Comfortable with Linux
Many cyber security tools are designed for Linux environments.
Try using Ubuntu or Kali Linux regularly and become familiar with:
-
Terminal commands
-
File permissions
-
SSH
-
Package management
-
Bash scripting
Confidence with Linux will benefit you throughout the course.
4. Learn by Building
The best way to improve your technical skills is by creating your own projects.
For example:
-
Build a simple network scanner
-
Analyse packet captures with Wireshark
-
Create a Python log parser
-
Complete Capture the Flag (CTF) challenges
-
Publish your work on GitHub
Employers often value practical projects just as much as certificates.
5. Read Research Papers
One of the biggest differences between undergraduate and postgraduate study is learning to engage with research literature.
I recommend developing the habit of reading at least one cyber security paper each week.
Useful sources include:
-
IEEE Xplore
-
ACM Digital Library
-
Computers & Security
-
USENIX
-
Google Scholar
Do not worry if you cannot understand everything at first. Reading research becomes easier with practice.
6. Useful Resources
Some excellent free resources include:
-
OWASP
-
MITRE ATT&CK
-
NIST Cybersecurity Framework
-
PortSwigger Web Security Academy
-
Hack The Box
-
TryHackMe
These platforms provide valuable hands-on learning alongside your university studies.
7. Professional Certifications
Certifications are not essential during your MSc, but they can complement your learning.
Depending on your interests, you may wish to consider:
-
CompTIA Security+
-
eJPT
-
PNPT
-
AWS Cloud Practitioner
-
Microsoft Azure Fundamentals
Focus on developing practical knowledge first rather than collecting certifications.
8. Research Opportunities
Ravensbourne is continuing to expand its research activities, and we are actively developing collaborations and external funding opportunities.
Throughout the academic year, opportunities may arise for students to become involved in research projects, funding applications, publications, or other academic activities. While these opportunities cannot be guaranteed, students who demonstrate strong academic performance, technical ability, curiosity, and enthusiasm for research are often well placed to participate.
If you are interested in research, I encourage you to discuss your interests with academic staff early in the programme.
9. My Advice
Do not try to learn everything at once.
Instead, aim to improve a little every week. Build small projects, read regularly, ask questions, collaborate with your classmates, and stay curious.
A master's degree is not simply about obtaining a qualification. It is an opportunity to develop the mindset of a cyber security professional and lifelong learner.
I look forward to welcoming you to Ravensbourne and wish you every success in your MSc journey.
Recommended Books
Fundamentals
- Computer Networking: A Top-Down Approach – Kurose & Ross
- Security Engineering (3rd Edition) – Ross Anderson
Offensive Security
- Black Hat Python (2nd Edition) – Justin Seitz
- The Web Application Hacker's Handbook – Dafydd Stuttard & Marcus Pinto
Malware & Reverse Engineering
- Practical Malware Analysis – Michael Sikorski & Andrew Honig
Security Strategy
- Cybersecurity and Cyberwar – P. W. Singer & Allan Friedman
Recommended Technical Reading
These publications are excellent for keeping up to date with developments in cyber security beyond textbooks.
Phrack Magazine
One of the oldest and most influential underground security magazines. Although many articles are highly technical, Phrack has played an important role in the history of hacker culture and vulnerability research.
PoC||GTFO
A unique publication that combines computer security research with humour, programming, reverse engineering, and creative technical writing. It demonstrates that security research can also be innovative and enjoyable to read.
2600: The Hacker Quarterly
A long-running magazine covering hacking culture, security, privacy, and technology. While not an academic publication, it provides valuable insight into the wider security community.
Krebs on Security
Brian Krebs' investigative blog covering cybercrime, data breaches, ransomware, and threat actors. One of the best sources for understanding real-world cyber security incidents.
Schneier on Security
Bruce Schneier's blog discussing cyber security, cryptography, AI, public policy, and emerging technologies. Particularly useful for developing a broader perspective beyond purely technical topics.
Annual Industry Reports
Rather than reading only research papers, I also recommend reviewing several major industry reports each year.
- Verizon Data Breach Investigations Report (DBIR)
- Google Cloud M-Trends Report (formerly Mandiant M-Trends)
- IBM X-Force Threat Intelligence Index
- CrowdStrike Global Threat Report
- ENISA Threat Landscape
- NCSC Annual Review (UK)
UK Cyber Security Resources
- National Cyber Security Centre (NCSC)
- National Cyber Force (NCF)
- AI Security Institute (AISI)
- DSIT (Department for Science, Innovation and Technology)
- UK Cyber Security Council