Preparing for Your MSc in Cyber Security

A Practical Guide for New Master's Students

Dr Kyounggon Kim, Course Leader, MSc Cyber Security

Welcome

Congratulations on joining the MSc Cyber Security course.

Starting a master's degree is both exciting and challenging. Compared with undergraduate study, you will be expected to learn more independently, think critically, and engage with current research while developing practical technical skills.

This guide brings together recommendations that I frequently share with new students. You do not need to master everything before the course begins, but becoming familiar with these areas will help you make a strong start.


1. Strengthen Your Foundations

Before the course starts, I recommend reviewing the following topics.

  • Computer Networking (TCP/IP, DNS, HTTP/HTTPS, Routing)

  • Linux fundamentals and command-line usage

  • Basic Windows administration

  • Python programming

  • Git and GitHub

  • Virtual machines (VMware or VirtualBox)

These topics will make many of the practical sessions much easier to follow.


2. Learn Python

Python is one of the most useful programming languages in cyber security.

You do not need to become an expert before September, but you should feel comfortable with variables, loops, functions, file handling, and basic object-oriented programming.

Python is widely used for scripting, automation, malware analysis, digital forensics, artificial intelligence, and penetration testing.


3. Become Comfortable with Linux

Many cyber security tools are designed for Linux environments.

Try using Ubuntu or Kali Linux regularly and become familiar with:

  • Terminal commands

  • File permissions

  • SSH

  • Package management

  • Bash scripting

Confidence with Linux will benefit you throughout the course.


4. Learn by Building

The best way to improve your technical skills is by creating your own projects.

For example:

  • Build a simple network scanner

  • Analyse packet captures with Wireshark

  • Create a Python log parser

  • Complete Capture the Flag (CTF) challenges

  • Publish your work on GitHub

Employers often value practical projects just as much as certificates.


5. Read Research Papers

One of the biggest differences between undergraduate and postgraduate study is learning to engage with research literature.

I recommend developing the habit of reading at least one cyber security paper each week.

Useful sources include:

  • IEEE Xplore

  • ACM Digital Library

  • Computers & Security

  • USENIX

  • Google Scholar

Do not worry if you cannot understand everything at first. Reading research becomes easier with practice.


6. Useful Resources

Some excellent free resources include:

  • OWASP

  • MITRE ATT&CK

  • NIST Cybersecurity Framework

  • PortSwigger Web Security Academy

  • Hack The Box

  • TryHackMe

These platforms provide valuable hands-on learning alongside your university studies.


7. Professional Certifications

Certifications are not essential during your MSc, but they can complement your learning.

Depending on your interests, you may wish to consider:

  • CompTIA Security+

  • eJPT

  • PNPT

  • AWS Cloud Practitioner

  • Microsoft Azure Fundamentals

Focus on developing practical knowledge first rather than collecting certifications.


8. Research Opportunities

Ravensbourne is continuing to expand its research activities, and we are actively developing collaborations and external funding opportunities.

Throughout the academic year, opportunities may arise for students to become involved in research projects, funding applications, publications, or other academic activities. While these opportunities cannot be guaranteed, students who demonstrate strong academic performance, technical ability, curiosity, and enthusiasm for research are often well placed to participate.

If you are interested in research, I encourage you to discuss your interests with academic staff early in the programme.


9. My Advice

Do not try to learn everything at once.

Instead, aim to improve a little every week. Build small projects, read regularly, ask questions, collaborate with your classmates, and stay curious.

A master's degree is not simply about obtaining a qualification. It is an opportunity to develop the mindset of a cyber security professional and lifelong learner.

I look forward to welcoming you to Ravensbourne and wish you every success in your MSc journey.


Recommended Books

Fundamentals

  • Computer Networking: A Top-Down Approach – Kurose & Ross
  • Security Engineering (3rd Edition) – Ross Anderson

Offensive Security

  • Black Hat Python (2nd Edition) – Justin Seitz
  • The Web Application Hacker's Handbook – Dafydd Stuttard & Marcus Pinto

Malware & Reverse Engineering

  • Practical Malware Analysis – Michael Sikorski & Andrew Honig

Security Strategy

  • Cybersecurity and Cyberwar – P. W. Singer & Allan Friedman

Recommended Technical Reading

These publications are excellent for keeping up to date with developments in cyber security beyond textbooks.

Phrack Magazine

One of the oldest and most influential underground security magazines. Although many articles are highly technical, Phrack has played an important role in the history of hacker culture and vulnerability research.

PoC||GTFO

A unique publication that combines computer security research with humour, programming, reverse engineering, and creative technical writing. It demonstrates that security research can also be innovative and enjoyable to read.

2600: The Hacker Quarterly

A long-running magazine covering hacking culture, security, privacy, and technology. While not an academic publication, it provides valuable insight into the wider security community.

Krebs on Security

Brian Krebs' investigative blog covering cybercrime, data breaches, ransomware, and threat actors. One of the best sources for understanding real-world cyber security incidents.

Schneier on Security

Bruce Schneier's blog discussing cyber security, cryptography, AI, public policy, and emerging technologies. Particularly useful for developing a broader perspective beyond purely technical topics.


Annual Industry Reports

Rather than reading only research papers, I also recommend reviewing several major industry reports each year.

  • Verizon Data Breach Investigations Report (DBIR)
  • Google Cloud M-Trends Report (formerly Mandiant M-Trends)
  • IBM X-Force Threat Intelligence Index
  • CrowdStrike Global Threat Report
  • ENISA Threat Landscape
  • NCSC Annual Review (UK)

UK Cyber Security Resources

  • National Cyber Security Centre (NCSC)
  • National Cyber Force (NCF)
  • AI Security Institute (AISI)
  • DSIT (Department for Science, Innovation and Technology)
  • UK Cyber Security Council