Build crawlers that perform at scale without becoming a security liability, then learn to spot and stop the bots targeting your systems. Packed with production-ready code, real-world architectures and practical case studies, this book takes you deep into crawling, fingerprinting, bot detection, WAFs, machine learning and incident response.
SOC 2 doesn’t have to be confusing. This practical handbook walks you through building, documenting and auditing a compliance program from the ground up. Packed with real-world examples, templates and checklists, it gives founders, security teams, engineers and auditors a clear path from first steps to continuous compliance.
OT security protects profitability, ensures resilience, and builds sustainable value. Built for corporate leaders, this 10-page guide provides actionable insights into the financial risk landscape, legal liabilities, compliance, and CAPEX planning.
Unite reliability, safety, and security to achieve operational excellence. Built specifically for plant operations, this 10-page guide provides actionable production risk assessments, management of change steps, and the plant manager's checklist.
Cybersecurity is much more than hacking, as it is often portrayed in movies. At its core, cybersecurity is about protecting people, businesses, governments, and communities from digital threats. Throughout this book, you'll discover how computers communicate, how networks function, how attackers identify vulnerabilities, and how security professionals defend systems against those attacks.
AI coding agents can build, run and break things at machine speed. This book shows you how to contain them safely. From Linux isolation and microVMs to WebAssembly, threat modeling and incident response, you’ll learn how to design production-grade sandboxes that let autonomous agents execute code without putting your systems at risk.
Field-level hardening for DCS/PLC and industrial network setups. Skip the generic IT fluff—get direct, actionable blueprints covering Purdue model network segmentation, asset tracking, countermeasures, and a complete implementation checklist.
Implementing ISO/IEC 27001:2022 is easier with the right guide. Packed with practical steps, ready-to-use templates and real-world examples, this book helps you build, manage and certify an effective Information Security Management System with confidence.
Smart cards power secure payments, digital identity and trusted authentication around the world. This book is a practical guide to building secure applications for ISO/IEC 7816 and ISO/IEC 14443 systems with real code, hands-on examples and proven development practices.
A test-by-test playbook that turns Maester's 676 security checks into risks you understand and fixes you can run.
The firewall attackers actually bypass is human. This practical guide reveals the psychology, tactics, and real-world cases behind phishing, vishing, BEC, and deepfake social engineering, then hands you the frameworks, red team methods, and incident response playbooks to build a genuine human firewall.
Detection keeps getting smarter. So do the systems built to avoid it. Evasion Engineering explores the techniques, architectures and design principles behind stealth in modern computing, from operating systems and networks to cloud environments and machine learning. A practical deep dive for security professionals who want to understand how advanced evasion really works.
AI changes the security game. New attack paths demand new ways of thinking. This practical guide shows you how to build, deploy and defend AI systems with confidence using proven patterns, real code and production-tested techniques. Built for engineers who need security that works in the real world.
Your software is only as secure as the path it takes to production. This book walks you through protecting every stage of the software supply chain, from dependencies and builds to deployment and runtime. Learn practical techniques, proven tools and the mindset needed to stop modern supply chain attacks before they spread.
This book is a workshop where things go wrong on the page, in front of you, and then get fixed in code, with the output that proves the fix worked. There's no need to be a security expert to follow along. We'll be moving from the interpreter to the supply chain, from the token to the human clicking Allow, and from a single tool to a whole host of untrusting servers.