The cybersecurity bookshelf

Nine shelves, from a first threat model to fiction

What to read, in what order, and what each book actually gives you: foundations and vocabulary, the offensive side, reverse engineering, cryptography, application security, defense and response, the human attack vector, the investigations that read like thrillers, and the novels that got there first.

  1. 01 Article Cybersecurity Books: Foundations The books worth starting with: they give you a threat model, a vocabulary, and the big picture before you open your first tool.
  2. 02 Article Cybersecurity Books: Offensive security Pentesting, exploitation, and red team work: the books after which you have practice, not just vocabulary.
  3. 03 Article Cybersecurity Books: Reverse engineering and malware The hardest part to enter: assembly, operating system internals, and the analysis of malicious code.
  4. 04 Article Cybersecurity Books: Cryptography The topic where reading the wrong book breeds overconfidence: how the primitives work, why they break, and why you do not write your own.
  5. 05 Article Cybersecurity Books: Application security The block for developers: the vulnerabilities you introduce yourself, and the ways not to introduce them.
  6. 06 Article Cybersecurity Books: Defense and response Blue team: monitoring, detection, incident investigation, and building systems that survive a compromise.
  7. 07 Article Cybersecurity Books: The human attack vector Social engineering, phishing, and the psychology of influence: why perimeter spending is bypassed with a single phone call.
  8. 08 Article Cybersecurity Books: Nonfiction investigations Journalism and memoirs: real operations, real consequences, and names on the record.
  9. 09 Article Cybersecurity Books: Fiction Novels where the technology is described accurately enough that a professional does not wince, and which set the language of the industry.

You might also like