Skip to content
Oluma Cyber Security Awareness
Access Cybersecurity Resources

Cyber Resources,
accessible to everyone.

Oluma makes cybersecurity more accessible for everyone. We connect aspiring professionals and everyday people with trusted resources, learning opportunities, career pathways, and digital safety guidance, helping bridge the gap between the industry and underserved communities..

Community Driven Digital Safety Aspiring Professionals

Framework Guides
Certification Tracks
Daily Job Updates
$0 To Learn — Always
The platform

Everything you need, in one place.

Learn the foundations, protect your self and family, study for a career, practice for the exam, find the job, and land the role every tool below is open, free, and built for people like you.

Start here

Find where you fit

Two quick self-checks. Whether you're just cyber-curious or already deep in study, get a personalized read in under two minutes, no signup, no email.

Self-test · 60 seconds

Are you built for cybersecurity?

Four quick either-or questions, two at a time. You'll get an honest read on whether the field fits how you're wired — no signup, no email.

Questions 1–2 of 4

Something on your device behaves in a way you don't understand. You…
You've been stuck on a technical problem for two hours with zero progress. That feels…
Answer both to continue

Questions 3–4 of 4

In cyber you'll be learning new tools and threats for your entire career. Your reaction?
Digging into settings, a command line, or unfamiliar software on your own feels…
Answer both to see your read

🟢 Green light — you're wired for this

The traits cyber actually hires for — curiosity, grit, a love of learning, and initiative — are the hard part to teach, and you already have them. Tools, certifications and technical skills are all learnable from here. Don't wait for permission: pick a foundational track and start this week. Oluma's learning is free, forever. Your move.

🟡 Strong potential — a couple of gaps to close

You've got real raw material. One or two of the traits that keep people in cyber for the long haul are still developing — completely normal, and fully buildable. Start small with a low-stakes intro course, notice which parts light you up versus wear you down, and steer hard toward the ones that light you up. Try a free foundational module and watch how it feels.

🔵 Worth exploring — go in with open eyes

Cyber is wide open to career-changers — there's no gatekeeping here. Just know the day-to-day leans hard on self-directed learning and stubborn problem-solving. Before you commit real time or money, try one free intro module. If it pulls you in more than it tires you out, that's your green light. Start with something small and free — no commitment.

Find your lane · 6 questions

Which cybersecurity path fits you?

Already studying cyber? Answer six quick either-or questions, two at a time, and get a starting direction based on how you actually think.

Questions 1–2 of 6

Which sounds more satisfying?
Which mindset feels more like you?
Answer both to continue

Questions 3–4 of 6

A new security tool lands on your desk. You'd rather…
You'd get more of a thrill from…
Answer both to continue

Questions 5–6 of 6

Pick the compliment you'd be prouder of:
At a crime-show marathon, you're the one who…
Answer both to see your path
Technical × Attacker

Offensive Security

You like getting deep in the tech and thinking like an adversary. You'd rather find the hole than patch it.

Roles: Penetration tester · Red teamer · Bug-bounty hunter · Exploit developer

Start here: Networking + Linux + a scripting language (Python), then hands-on web-app hacking.

Cert path: Security+ → PenTest+ / eJPT → OSCP

Technical × Defender

Security Engineering & Architecture

Technical to the core, but you'd rather build and defend than break. You like making things secure by design.

Roles: Security engineer · Cloud security · Application security · DevSecOps

Start here: Cloud (AWS/Azure), automation, and secure-coding fundamentals.

Cert path: Security+ → cloud security (AWS/Azure) → CySA+

People × Attacker

Threat Intel & Investigations

You love the hunt and the story behind an attack — but you lead with analysis and clear communication over deep coding.

Roles: SOC analyst · Threat hunter · Threat-intel analyst · Incident responder

Start here: Log analysis, the MITRE ATT&CK framework, and sharp report-writing.

Cert path: Security+ → CySA+ → GCIH / GCFA later

People × Defender

Governance, Risk & Compliance

You connect security to the business — people, policy, and risk. You're the translator between the tech team and everyone else.

Roles: GRC analyst · Risk analyst · IT auditor · Security-awareness / program lead

Start here: Frameworks (NIST CSF, ISO 27001), risk assessment, and audit basics.

Cert path: Security+ → CC / CISA → CRISC later

Real careers blend these — this is a compass, not a cage. Wherever you landed, Oluma has a free path to get you moving.

Test yourself

Can you outsmart the attacker?

Real-world security scenarios, one decision at a time. Answer, see why it matters, and keep going as long as you like.

EXPERT
SOCIAL ENGINEERING
CHALLENGE 01 / 16
01
REAL-WORLD SCENARIO
Your CEO is traveling overseas and emails you urgently asking you to purchase $2,000 in gift cards for a client dinner. The CEO says they will reimburse you later.
WHAT SHOULD YOU DO?
What is the strongest explanation for this attack?
EXPERT
IDENTITY SECURITY
CHALLENGE 02 / 16
02
REAL-WORLD SCENARIO
At 2 AM, an administrator receives dozens of MFA approval requests. Exhausted, they finally approve one just to make the notifications stop.
WHAT SHOULD YOU DO?
What attack succeeded?
HARD
PHISHING
CHALLENGE 03 / 16
03
REAL-WORLD SCENARIO
You scan a QR code attached to a parking meter and enter your card details on the resulting payment page. Two days later, fraudulent charges appear.
WHAT SHOULD YOU DO?
What attack most likely occurred?
EXPERT
PHISHING
CHALLENGE 04 / 16
04
REAL-WORLD SCENARIO
A cloud-storage notification says a coworker shared an important document. The link opens a convincing Microsoft login page.
WHAT SHOULD YOU DO?
What is the attacker primarily trying to steal?
HARD
MALWARE
CHALLENGE 05 / 16
05
REAL-WORLD SCENARIO
HR receives a file named Resume_2026_Final.pdf.lnk. It looks like a document, but opening it launches hidden commands.
WHAT SHOULD YOU DO?
What trick was used?
EXPERT
BUSINESS EMAIL COMPROMISE
CHALLENGE 06 / 16
06
REAL-WORLD SCENARIO
An attacker enters an existing vendor-finance email conversation and requests that payment be sent to a new bank account.
WHAT SHOULD YOU DO?
Why is this attack especially convincing?
HARD
SUPPLY CHAIN
CHALLENGE 07 / 16
07
REAL-WORLD SCENARIO
A developer installs a package whose name closely resembles a legitimate open-source library. The package secretly sends environment variables to an external server.
WHAT SHOULD YOU DO?
What attack is most likely occurring?
EXPERT
WEB SECURITY
CHALLENGE 08 / 16
08
REAL-WORLD SCENARIO
A user changes an ID in a URL and suddenly gains access to another user's information.
WHAT SHOULD YOU DO?
What vulnerability should developers investigate?
EXPERT
CLOUD SECURITY
CHALLENGE 09 / 16
09
REAL-WORLD SCENARIO
A vulnerable cloud application can be manipulated into requesting cloud instance metadata.
WHAT SHOULD YOU DO?
What could an attacker potentially obtain?
EXPERT
RANSOMWARE
CHALLENGE 10 / 16
10
REAL-WORLD SCENARIO
A company restores encrypted systems from backups, but attackers publish stolen customer data online.
WHAT SHOULD YOU DO?
What tactic was used?
HARD
WIRELESS SECURITY
CHALLENGE 11 / 16
11
REAL-WORLD SCENARIO
Your laptop automatically connects to a familiar-looking free Wi-Fi network at a coffee shop.
WHAT SHOULD YOU DO?
What should you suspect?
HARD
PHYSICAL SECURITY
CHALLENGE 12 / 16
12
REAL-WORLD SCENARIO
Someone follows an employee through a secure door without using a badge.
WHAT SHOULD YOU DO?
What attack is this?
EXPERT
MALWARE
CHALLENGE 13 / 16
13
REAL-WORLD SCENARIO
Security finds no suspicious executable files, but an attacker successfully operates on a server using legitimate system utilities.
WHAT SHOULD YOU DO?
What technique may be involved?
EXPERT
CLOUD SECURITY
CHALLENGE 14 / 16
14
REAL-WORLD SCENARIO
A developer accidentally publishes a cloud access key in a public repository. Automated systems use it almost immediately.
WHAT SHOULD YOU DO?
What happened?
EXPERT
API SECURITY
CHALLENGE 15 / 16
15
REAL-WORLD SCENARIO
A patient changes a prescription ID in an API request and sees another patient's records.
WHAT SHOULD YOU DO?
What API weakness is most likely present?
EXPERT
AI SECURITY
CHALLENGE 16 / 16
16
REAL-WORLD SCENARIO
A company trains an internal AI assistant using public customer feedback. An attacker repeatedly posts false claims about company policies. The model later repeats those false claims.
WHAT SHOULD YOU DO?
What threat should security investigate?
Nicely done

All clear, defender.

You worked through all 16 scenarios. Threats keep evolving — run the set again to sharpen your instincts, or head into the Cert Zone to go deeper.

Enjoy your hub for cyber security resources.

Making cybersecurity resource:knowledge, skills, and opportunities accessible to everyone, so we can build a safer digital world together.

20+ Framework guides 40+ Certification tracks Daily Job updates Verified Sources