Blog
Training

Free Cisco cybersecurity courses: what they teach and where they stop

Since January 2024 this page had been recommending six specific courses from the Cisco academy, with their hours and their free-of-charge label. That format stopped being honest: the catalogue is Cisco’s, it changes when Cisco wants it to, and we find out late or not at all. So there is no course list here any more. There is what we can actually stand behind: what kind of knowledge those courses give, where that road ends, and how you carry on if what you want is to learn to attack systems, which is what we do.

A
Asperis Security
Offensive Security team
4 January 2024
8 min read
Share:
Three steps of increasing height, fundamentals, lab and real environment, with the first drawn as the shortest, and in red the two mistakes: skipping the second and freezing on arrival at the third.

What the Cisco academy is and what kind of courses it publishes

Cisco Networking Academy is the Cisco training programme and it lives at netacad.com. Its catalogue moves around networking, cybersecurity fundamentals, operating systems and programming. Historically part of that catalogue has been free and self-paced, with no start date and no assigned tutor, and that is the reason this page exists and the reason people arrive here searching.

What you will not find here is how many courses there are, how long each one lasts, or which ones are free today. Cisco publishes that, Cisco changes it when it wants, and any number we wrote would go stale without anyone noticing. Look at it on their site, which is the only source that is always current.

It sounds like a formality and it is not. When we reviewed this page, every one of the direct links that pointed at the six courses it recommended had moved. The courses still existed, but the addresses we published in 2024 were no longer theirs. If that happens to the addresses, imagine what happens to the hours and to the price.

What you actually learn on an introductory course

With the criticism out of the way, the good part deserves saying, because it is real and because a well-made introductory course solves a problem that nothing else solves: not knowing where to start.

  • Vocabulary. Before you can attack or defend something you have to be able to name it. Knowing what a port, a subnet, a certificate, a hash or an event log is does not make you anybody, but without it no technical conversation lands.
  • How a network is put together. It is the house speciality and it shows. Understanding how a packet travels, what a firewall does and why segmentation exists is the base that almost all offensive work later rests on.
  • The defensive baseline. Backups, updates, passwords, second factor, least privilege. None of it is spectacular and all of it is what fails in the incidents we see.
  • A first contact with Linux and the command line. Which is where you are going to live afterwards, whether you end up attacking or defending.

If you are starting from zero, that is a perfectly reasonable starting point, and it is cheaper and more orderly than working through scattered videos. We sell none of it and we would recommend it anyway.

Where that road ends

This is where this article differs from the one that used to be here, and where it is worth staying if your goal is to work in security and not only to know what it is about.

An introductory course teaches you to recognise concepts. Security work consists of producing a result on a system that you were not meant to own and that nobody prepared for you. Between those two things there is a distance that no syllabus covers, and it takes three concrete forms:

  • A course has a syllabus and a real system does not. The exam asks about what the course explained. A real system does not tell you what technology it runs, what version it is, or where the interesting part sits. Half the work is finding out what you have in front of you.
  • Course exercises have a known solution. And, above all, they have a solution. A good part of real offensive work is trying ten routes that go nowhere before finding the one that does. That is not taught, it is endured, and the only way to learn to endure it is by doing it.
  • A course does not chain. The findings that really matter are almost never one serious flaw on its own: they are three small things that nobody would fix separately and that together hand you control. A syllabus teaches the three pieces in three different chapters and never joins them.

None of this is a defect of the Cisco courses in particular. It is what a course is and what a course cannot be.

What offensive security is and why it is learned differently

Offensive security is the half of the trade that consists of attacking your own systems, with written permission and a signed scope, to find what an attacker would find before he finds it. If the term is new to you, the piece that explains it end to end is what penetration testing is, and if what you are looking at is who to hire rather than how to train yourself, that is hiring an ethical hacker.

Inside that half there are exercises that resemble each other very little, and it is worth not confusing them, because they are not learned the same way:

  • Vulnerability scanning looks for known flaws with tooling. It is the most automatable part and the easiest to learn.
  • A penetration test looks for them and exploits them, and chains what it finds. That already takes judgement.
  • The red team does not look for vulnerabilities: it pursues a specific objective without you noticing, in order to measure whether your detection works.
  • The purple team puts attackers and defenders in the same room so that the organisation learns while it happens.

And if the certification route interests you, the ones asked for in this job are OSCP, OSCE³, OSWE, OSEP, CRTO and CRTP. They all share one thing that separates them from a course: the exam is hands-on. You do not pass by having read, you pass by having achieved something inside a system.

The order that works: fundamentals, lab, real environment

If you arrived looking for free courses and you leave with one idea, let it be this one: courses are the first of three steps and the shortest of the three.

  • Fundamentals. Networking, systems, a programming language and the defensive baseline. This is where the Cisco courses fit, and they fit well. It is a step you climb once.
  • Lab. Machines built to be broken, in an environment where breaking things has no consequences. It is the step where vocabulary turns into technique, and it is the one that almost nobody skips and gets away with. The two reference platforms are compared in Hack The Box vs TryHackMe.
  • Real environment. Systems that were not designed to be an exercise, with written permission and a signed scope. This is where you learn what is written down nowhere: how you decide where to look, when to stop, and how to write up what you found so that somebody fixes it.

The most expensive mistake we see is skipping the second step: people with a lot of courses passed who have never got into anything. The second most expensive is stopping at the second step: people who solve hard labs and freeze the first time a real company is put in front of them, because in a real company you have to explain the risk to somebody who is not technical.

Training a person is not training a team

Everything above is aimed at somebody who wants to learn on their own. If the question in front of you is a different one, and it is how to raise the level of a team that already works, quite a lot changes.

  • A catalogue cannot be assigned or measured. A team is not served by everyone picking on their own. You need to know who has to learn what, and to be able to see who has moved, and that is normally not in the free tier of any platform.
  • A generic syllabus does not teach your house. No course knows your Active Directory, your cloud or your application, which is exactly where you are going to be attacked. The further the material sits from your stack, the more translation your people have to do on their own.
  • A course measures whether one person understood something, not whether the team reacts. Your people knowing what phishing is and your organisation detecting and cutting a phishing attempt are two different things, and only the second one saves you.

We run training for company teams on exactly that second half: on your stack and on the threats that actually apply to you. It does not replace a course or a lab, and we are not saying that out of modesty: to pick up the base, a free course is cheaper and better than we are. What it does not give you is the part that depends on your own house.

A note on this article

This piece originally recommended six specific courses, each one with its length in hours and with the claim that it was free. All of that has been removed. It is data from a catalogue that is not ours and that changes without telling us, and publishing it without being able to review it every month is asserting something about a third party we do not control. When we went to check, the six direct links we gave were no longer the right addresses.

That is why there is only one outbound link here, to the front page of the academy, and no figures. What we can stand behind is the other part: what kind of knowledge those courses give and what is needed afterwards. That does not change when Cisco reorganises its catalogue.

Last reviewed: 3 August 2026. Originally published on 4 January 2024.

A
Asperis Security
Offensive Security team
Share:

If any of this looks like a problem you are carrying, half an hour on a call scoping it with a senior pentester is worth more than reading another article.

Talk to a senior pentester