You can find plenty of free sec+ study materials to get you started. It is basic, yes, but real cyber security comes from understanding systems, protocols, and best practices and honestly I'm not sure there's a good book that can give you that. I could be wrong, we'll see other posts if they show up, but starting with sec+ material and then reading deeper on things would be my recommendation.
Understanding active directory, Linux permissions and file structure, VPNs, firewalls, different security appliances, hashing, crypto methods/algorithms, handshakes, transmission protocols, VMs, cloud architectures, backup strategies, social engineering, etc - it all plays a part. You could find a number of books and resources about any of those things.
Certs like LPI Linux essentials is pretty good if you're unfamiliar with Linux basics, that's another one to look into where you can find free study material.
I guess what I'm saying is that cyber security is REALLY complicated and will always be tailored to the threats, the assets you're trying to protect, available budget, and systems used. It's why certs are the industry standard of recognition, because there's really not a good way to gauge competency unless you're assessed by another competent person in the field. And you may be AWESOME with an active directory setup but be lost in Linux, or need to work with embedded systems, but be weak in other areas because you've never worked with it, so certs kind of level the field so you can be at least aware of stuff if you've never worked with it.
I would not consider myself an expert in the field but this is my perspective. You can learn for the next 10 years for free and by just experimenting on old hardware and with VMs and a robust LAN.
The cyber landscape is so, so complex. There's an endless number of options and potential vulnerabilities. Defense in depth can't really be taught from a single book, but by identifying areas you'd like to learn more about can take you as far down the rabbit hole as you like.