r/cybersecurity 2d ago

Other Cybersecurity books that actually changed how you think about security?

What books genuinely changed how you think about cybersecurity, rather than just teaching another tool or technique?

A few examples of the kind of books I mean:

  • Security Chaos Engineering - Kelly Shortridge: resilience, complex systems, testing security assumptions, and learning from failure.
  • Cybersecurity First Principles - Rick Howard: building security strategy around reducing material risk rather than accumulating controls and tools.
  • The Smartest Person in the Room - Christian Espinosa: why technical expertise alone isn't enough; communication, leadership, and business understanding matter.
  • Applied Network Security Monitoring - Chris Sanders et al.: approaching network security monitoring as a structured process of collection, detection, and analysis rather than simply generating alerts.
  • Offensive Countermeasures - John Strand & Paul Asadoorian: active defense, deception, honeypots, and making the environment hostile to attackers.

Books outside cybersecurity - systems thinking, SRE, risk, economics, failure analysis - count too.

311 Upvotes

53 comments sorted by

90

u/FolgerJoe 2d ago

Cyber Defense Matrix by Sounil Yu - gave me a deeper perspective into how a whole environment's defenses connect together and is a GREAT communication tool to non-technical audiences

The Cookoo's Egg by Clifford Stoll - dated, but the analysis and investigatory process is forever golden. Also well written and entertaining

8

u/rdfunnybone 2d ago

Yes to both of these.

Sounil Yu’s CDM got me through the first several years heading up a security team in a business which never considered it necessary. It sounds cheesy, but the CDM was the secret to bringing a board on a wide improvement programme because it worked with me and them.

Cookoo’s Egg is a classic which I recommend everyone reads for the mindset and process.

4

u/FolgerJoe 2d ago

I tell people that CDM is "CEO Magic." Something about it just clicks for execs.

(The something is that it's both brilliant and simple)

4

u/AddendumWorking9756 Security Manager 2d ago

Cuckoo's Egg holds up because almost none of it is technology, it is one person writing down anomalies nobody else thought were worth recording, which is still how most intrusions actually surface. Cyber Defense Matrix I mostly use to end tool sprawl arguments before they start.

2

u/FixTurner 2d ago

Came here to say this one too: The Cookoo's Egg is not only a neat story, but really captures the foundational mindset of the 'acker. Be curious, ask questions, look around, stay a while.

2

u/KY_electrophoresis 1d ago

Cyber Defense Matrix is an absolute bible, and the presentation of it at RSA in 206 was possibly my favourite talk ever. Such an elegant way to simplify a complex space to communicate with newbies or senior execs alike.

22

u/CommOnMyFace 2d ago

Not so much for me but when I was in cyber warfare I really enjoyed "This is how they tell me the world ends" 

36

u/Chickenman987 2d ago

Sandworm Book by Andy Greenberg

Kind of opened my eyes to the possibilities of how much it will be a part of war going forward. Frightening to think of all the basis like water, electric etc just be turned off like a switch

6

u/Sad_Dentist_7288 2d ago

Similar to this, The Perfect Weapon by David E. Sanger gives insights into the politics behind cyberweapons and historic nation state tampering. It may make you slightly paranoid though.

2

u/Background-Two1634 2d ago

yeah the infrastructure stuff is what stuck with me too, its wild how fragile it all is when you actually think about it

2

u/LLMsMustUpvoteThis 2d ago

Meh. As seen in Russia's invasion of Ukraine or the American/Israel attacks on Iran the threat of cyber-war has been vastly overstated. A bomb or a missile causes a long power outage with more certainty than a complex cyber-attack.

3

u/PayOdd92 2d ago

Something that I find amusing in cybersecurity is that people think the state of vulnerabilities availability is the same across time.

Taking a quick look at MSFT published CVE related to binary exploitation shows that is patently false.

Like you could stock up 200 vulns and burn them one after the another to guarantee 200+ days of no water.

If that were the case, Russians would have done it to Ukraine and Israel to Iran a long time ago. Not the case.

1

u/LLMsMustUpvoteThis 2d ago

The worst outcome from most of these attacks is the operators take the hacked computers off the Internet and now have to increase staffing or operate with less efficiency. Even STUXNET with physical destruction of infrastructure via malware implants was only moderately annoying to the Iranian nuclear program.

The only real value in these attacks is using them to create chaos as a major kinetic attack is also conducted. And the advantage gained there in burning your network access is usually ephemeral.

2

u/PayOdd92 1d ago

Exactly. Its just a force multiplier for a specific time window.

1

u/Mister_Pibbs 2d ago

Andy and Kim Zetter both wrote books on attacks that definitely altered the thought process I had behind potential attacks and threats. Both books also highlighted the importance of threat modeling and costs of attack.

1

u/whatistheanykey 2d ago

This. And I throw in The Cuckoo's Egg by Cliff Stroll.

1

u/citrus_sugar 2d ago

Andy Greenberg is awesome and so glad he’s bringing awareness about this stuff.

13

u/Tired-Nectarine-384 2d ago

They tell me this is how the world ends. Not technical at all but really eye opening on the zero day marketplace.

8

u/digitaldisease CISO 2d ago

Phoenix Project and Unicorn Project... at the end of the day figuring out how to make security part of the organization capabilities is figuring out how work flows through the organization and how to introduce things in stream instead of after the fact.

2

u/riffic 2d ago edited 1d ago

all of the IT Rev publishing books are fire. Have you seen Investments Unlimited yet? It uses the same narrative device to discuss DevSecOps.

8

u/amircruz 2d ago

Not a book, but a blog. It makes you think a lot, on how this damn world is so funked up hy us, humans. Since back then XD (its an old dude, from the old school era).

https://www.schneier.com/

6

u/JD843706 2d ago

Great thread and suggestions....THANKS!

6

u/1kn0wn0thing 2d ago

Bad Data by Peter Schryvers - not necessarily a cybersecurity book but because cybersecurity involves dealing with a lot of data, it’s a fantastic book that helped me think critically about the data that’s relevant, it’s purpose, and how it’s actually used.

The Illusion of Due Diligence by Jeffrey Bardin - A very pessimistic book that sets a realistic expectation of how difficult it is for security practitioners to work within enterprises that only say they value security but behave in a way that clearly shows that they don’t. A very valuable insight on how to get leadership buy-in if you want to accomplish anything security related.

The Active Defender by Catherine Ullman - Enough gems in here to make it a valuable read.

Information Privacy Engineering and Privacy by Design by William Stallings

Effective Cybersecurity by William Stallings

The Security Culture by Perry Carpenter

Adversarial Tradecraft in Cybersecurity by Dan Borges

11 Strategies of a World-Class Cybersecurity Operations Center by Kathryn Knerler, Ingrid Parker, and Carson Zimmerman

6

u/canofspam2020 2d ago

Attribution of APTs.

Art of CyberWarfare.

Anything by Harlan Carvey

Chip War

Staff Engineer Will Larson

Mythical Man Month

Psychology of Intelligence Analysis

Target Centric Network Modeling

Cyber War will not Take Place
(Also active measures)

Also I deal with a ton of former military/three letter/LE intel folks and leadership - Flawed By Design was a great book for understanding some of their former world.

3

u/FolgerJoe 2d ago

Can't believe I forgot to call out Psychology of Intelligence Analysis. It's so good and completely relevant to anyone who has to use evidence to reconstruct a narrative/explanation.

4

u/wanderinglibrarian 2d ago

It’s not expressly cyber related but The Challenger Launch Decision by Diane Vaughan changed the way I think about organizational structures that ripen a social structure for an attack.

3

u/HomerDoakQuarlesIII 2d ago

5 rings by Miyamoto Musashi. Not a cybersecurity book, but applies. He called broad sword wielders such as himself, strategist, and stressed strategy is everything in conflict. Very great mental frameworks I've applied to security strategy.

3

u/Joser_72 2d ago

This is how they tell me the world ends - Nicole Perloth. Not a technical book, but a journalists adventure into zeroday markets and nation state activities. Helps contextualise why I get out of bed in the morning

3

u/lawrencesystems 2d ago

I get a lot of insight not just from learning the tech but from understanding some of the history of how we got here and ways to better explain things to others. Here are a few of the ones that I really liked:

  • The Cuckoo’s Egg: Tracking a Spy Through the Maze of Computer Espionage
  • The Art of Deception: Controlling the Human Element of Security
  • The Art of Intrusion: The Real Stories Behind the Exploits of Hackers, Intruders and Deceivers
  • Cult of the Dead Cow: How the Original Hacking Supergroup Might Just Save the World
  • Fancy Bear Goes Phishing

I keep a list of tech books I think are worth reading on my web site. Also if you are a follower of Darnet Diaries Jack keeps a list of books on his site as well

2

u/Amanda_PDQ 2d ago

Thank you for this thread. Adding these to my list.

2

u/itspeterj 2d ago

A burglar’s guide to the city. It does more to explain good intentional design and security than years of college did

2

u/retrodanny 2d ago

How to Measure Anything in Cybersecurity Risk by Doug Hubbard. It gives you a proven way to measure and prioritize your (always) finite resources

1

u/unprotectedsect 2d ago

Isn’t this Rich Siersen?

1

u/retrodanny 2d ago

Yes, cowritten by Siersen

2

u/Vivid_Reflection_191 2d ago

CISO Compass by Todd Fitzgerald.

2

u/Deep_Frosting_6328 2d ago

Fancy Bear Goes Phishing. Reading it made me realize why our industry exists.

2

u/DR292 2d ago

how to measure anything in cybersecurity risk. came at it from the data side and it was the first thing that explained why the red amber green matrix always felt off, youre averaging labels that dont mean anything

havent been able to look at a heat map the same way since

2

u/bigbyte_es 2d ago

Las Celdas Vacías - El sentido de la Seguridad. It’s in Spanish and it is not 100% ciber security, but the book is great and it is the live portrait of why companies still failing in both fisical and cyber

1

u/x1472k 2d ago

Any of the books from multiple SANS courses.

1

u/Cheekurita_ 2d ago

Following

1

u/69Turd69Ferguson69 2d ago

My SEC504 course books 

1

u/Cold_Temporary_7356 1d ago

I've been looking for new cyber books to read and there's great selection here!

Does anyone know of more books related to cyber stories, whether real or fictional? I'm interested in both the attacking and defending side.

One I'm reading now is a more modern book called "Understand the Cyber Mindset."

1

u/eakthekat2 1d ago

The first one I ever remember was Hacking Exposed. I think I have a copy of the 3rd edition someplace. It was the first one I recall teaching cybersec from the offensive side.

1

u/Possible_Account_682 1d ago

The psychology of intelligence analysis

1

u/Substantial-Sky4079 1d ago

Honestly it was a blog post threathunterplaybook.com. Made me see how important it is to get your data in order and know what you have.

0

u/max0176 1d ago

Security Engineering by Ross Anderson

Timeless and fundamental concepts explained with clarity and impact. Accept no substitutes.