Digital Forensics & Incident Response
You work out what happened after a breach, in enough detail that it stands up later.
No degree needed Hard, and unusually consequential — your findings may end up in a legal process.
Practise only on data and systems you own or are authorised to examine. Forensic work touches personal data by nature, and in a real engagement your handling of evidence can decide whether it is admissible. Follow your organisation's process, and never examine a colleague's machine on your own initiative.
Can I actually do this?
Open without a degree, but essentially always entered from a SOC or security analyst role. You need to have watched alerts before you can reconstruct an intrusion from them. The foundational government guidance below is free, and reading it early is not wasted.
Who it suits. People who are methodical under pressure and can resist concluding before the evidence supports it.
Runway. Years. This is a step up from SOC work, not a first job.
Coming from a SOC? That is the route. What you add is reconstructing the whole event rather than closing the ticket. SOC Analyst Security Analyst Systems Administrator
Also advertised as
The route
Four stations, in order. Each one is a thing you finish before the next matters.
-
Station one
Learn it free
Only the best few, deliberately. Every one of these is free to use — the pill on each card says exactly what is and isn't free.
NIST SP 800-86 — integrating forensic techniques into incident response
Free to learn · no certificate
The foundational free government guidance on doing this properly — evidence handling, order of volatility, process. Free from NIST.
Verified 2026-07-28
NIST Cybersecurity Framework
Free to learn · no certificate
The Respond and Recover functions are the frame your work sits inside. Free.
Verified 2026-07-28
OWASP Cheat Sheet Series
Free to learn · no certificate
The logging and monitoring sheets tell you what evidence should have existed. Usually the first finding is that it did not. Free.
Verified 2026-07-28
-
Station two
Attest strategically
The well-known forensics certifications in this field are among the most expensive on this site — training plus exam commonly runs into thousands. We are not naming one because we have not verified current pricing to this project's standard, and because employers in this field frequently fund them. Do not self-fund one as a way in. Get into a SOC first and let the employer pay.
Nothing here is worth paying for
No credential needed
The well-known forensics certifications in this field are among the most expensive on this site — training plus exam commonly runs into thousands. We are not naming one because we have not verified current pricing to this project's standard, and because employers in this field frequently fund them. Do not self-fund one as a way in. Get into a SOC first and let the employer pay.
Checked 2026-07-28
-
Station three
Prove it
A certificate says you passed a test. These say you can do the job.
A timeline you reconstructed
From logs or a disk image in a lab, build what happened and when. The timeline is the deliverable of this job.
A chain of custody you maintained
Show that you handled evidence in a way that would survive challenge. This is what separates forensics from curiosity.
A report written for non-technical readers
Your findings usually go to lawyers, executives or regulators. Practise that register.
-
Station four
Get hired
Search these exact titles
Who hires for this. Incident response consultancies, large in-house security teams, law enforcement, and insurers.
Hiring leans on incidents you have personally worked, which is why the role resists entry straight from study. That is our reading of the field, not a verified hiring statistic.
On salaryWe don't publish salary estimates. Numbers copied between blogs drift from reality, and a wrong number costs you real negotiating power. When we have a verified public source, it goes here with its date.
Where this route continues
- Security Analyst — broader defensive work
- SOC Analyst — sideways move
- Security Analyst — sideways move
- Penetration Tester — sideways move
This page last verified 2026-07-28 · How we verify
NIST SP 800-86, the NIST Cybersecurity Framework page and the OWASP Cheat Sheet Series fetched and READ 2026-07-28.