I recently completed NSE 1 – Fortinet Certified Fundamentals in Cybersecurity.
It’s an entry-level certification, so I wasn’t expecting it to suddenly turn me into a cybersecurity expert. What I wanted was something more useful: a stronger understanding of the fundamentals before going deeper into security.
And that’s exactly how I approached it.
Why I Started With the Fundamentals
Cybersecurity is a huge field.
You can go into penetration testing, SOC operations, cloud security, application security, digital forensics, DevSecOps, threat intelligence, AI security, and many other areas.
When you're starting out, it’s easy to get overwhelmed by tools and technologies.
Kali Linux, Burp Suite, Wireshark, SIEM platforms, cloud security tools, vulnerability scanners — there is always something new to learn.
But tools make much more sense when you understand what you're actually looking at.
That’s why I wanted to strengthen my foundation first.
What NSE 1 Covers
During the certification, I worked through fundamental cybersecurity concepts including:
- Common cybersecurity threats
- Basic security concepts
- Network security fundamentals
- Different types of attacks
- Security terminology
- The importance of protecting digital systems and information
Nothing here is extremely advanced, and that’s actually the point.
The fundamentals are supposed to be understandable before you start dealing with more complex security problems.
One Thing I Took Away
One thing I’ve started to realise while learning cybersecurity is that knowing a tool isn't the same as understanding security.
You can learn how to run a vulnerability scanner.
But understanding why a vulnerability matters, what could happen if it is exploited, how to validate the finding, and how to mitigate it is a different skill.
The same applies to almost every area of security.
The tools change.
The fundamentals remain.
Where I'm Going Next
My interests are currently spread across a few areas:
- Cybersecurity
- Cloud Security
- DevSecOps
- AI Security
I’m especially interested in AI security because modern AI systems introduce a different set of security problems.
Prompt injection, insecure tool use, data leakage, RAG security, agent security and model-related risks are areas I want to explore more deeply.
But before going too far into those topics, I want to make sure the underlying security concepts are solid.
Certifications vs Practical Skills
I don't want to collect certifications just to make a longer list on my resume.
For me, the useful part of a certification is what happens after it.
Can I apply the concepts?
Can I build something?
Can I investigate a problem?
Can I explain what I found?
Can I break something and understand why it broke?
Those are the skills I want to keep developing.
NSE 1 is only a small step, but it's a useful one.
Now the interesting part begins: taking the fundamentals and putting them into practice.
What I'm Learning Next
I’ll be spending more time on practical cybersecurity projects, cloud security, DevSecOps and AI security.
I also plan to document some of the things I build, the problems I run into, and the lessons I learn along the way.
If you're also learning cybersecurity, I'd genuinely like to know:
What was the first security concept, tool, or project that really helped things start making sense for you?
You can find some of my work here:
GitHub: https://github.com/jaisurya93945
LinkedIn: https://www.linkedin.com/in/badathala-jaisurya/
Thanks for reading.
Top comments (0)