What Books Belong in the Cybersecurity Canon?

TL;DR
A cybersecurity canon should include books that help experienced professionals understand threat motivations, introduce newcomers through compelling fiction, and explain major policy events such as Stuxnet. Rick Howard recommends works including We Are Anonymous, Cryptonomicon, Snow Crash, and Confront and Conceal, while emphasizing that cybersecurity careers require both deep technical ability and clear executive communication.
Transcript
Hi, I'm Tom Field, vice president of editorial with Information Security Media Group. And I'm talking today with Rick Howard. He's the CISO with Palo Alto Networks. Rick, thanks so much for joining me today. Thank you for having me. I c- um, this is gonna be a lot of fun. Well, a number of topics I wanna hit with you, and first I wanna talk about a... Read More
Key Insights
- A cybersecurity canon is a proposed collection of books that experienced professionals should know, newcomers can use to discover the field, and practitioners can confidently recommend to relatives and friends interested in understanding cybersecurity.
- We Are Anonymous is Rick Howard's recommendation for understanding Anonymous culture because author Parmy Olson obtained unusual access to important members associated with major attacks during 2010 and 2011.
- Cryptonomicon is Howard's favorite hacker novel because its multigenerational story connects World War II, the 1990s dot-com period, treasure hunting, mathematics, computer science, cybersecurity, and relationships involving technically minded characters.
- The proposed canon contains about 20 initial candidates, each accompanied by a review on Howard's corporate or personal blog, and the broader security community is invited to recommend additions as the collection is reconsidered annually.
- Snow Crash is included because its dystopian cyberpunk setting combines hacker themes with humor and entertainment, showing that a cybersecurity reading list can contain enjoyable fiction rather than only technical manuals and nonfiction analysis.
- Hacker movie preferences vary by generation, with WarGames favored by older viewers, Hackers associated with a younger generation, and The Matrix appealing to an even younger group in a survey of about 400 people.
- Stuxnet marked a major policy threshold because the United States and Israel used offensive code against Iran's Natanz facility, publicly demonstrating that cyber operations could destroy critical infrastructure in a country without a declared war.
- Cyber threat intelligence professionals need two uncommon capabilities: deep technical expertise sufficient to analyze malware and communication skills sufficient to explain findings to the C-suite. Howard estimated that perhaps 2,000 people worldwide possessed this combination, and they already had jobs.
Install to Summarize YouTube Videos and Get Transcripts
Explore YouTube Video Summarizer or Get YouTube Transcript Extractor
Questions & Answers
Q: What is a cybersecurity canon?
A cybersecurity canon is a proposed set of books that members of the security community broadly agree professionals should read during their careers. Rick Howard argues that it should serve several audiences: experienced practitioners seeking perspective, newcomers who need an engaging introduction, and friends or relatives who want to understand the field without encountering material that practitioners would hesitate to recommend.
Q: Which books does Rick Howard recommend for cybersecurity professionals?
Rick Howard highlights four books from his proposed collection. We Are Anonymous examines Anonymous culture and activity. Cryptonomicon combines computer science, mathematics, and cybersecurity within a long fictional narrative. Snow Crash offers a humorous dystopian cyberpunk story with hacker elements. Confront and Conceal addresses the policy decisions surrounding the offensive cyber operation against Iran's Natanz facility.
Q: Why is We Are Anonymous recommended for security professionals?
We Are Anonymous is recommended because many people do not understand the culture surrounding Anonymous. According to Howard, author Parmy Olson received unprecedented access to some important members connected with major attacks occurring in 2010 and 2011. That access makes the book useful for examining the people, motivations, and culture behind cyber hacktivism rather than viewing incidents only through technical details.
Q: Why is Cryptonomicon a good introduction to cybersecurity?
Cryptonomicon is recommended for newcomers because it uses an engaging fictional story while accurately presenting relevant technical ideas. Howard describes it as a multigenerational narrative spanning World War II and the 1990s dot-com period, with treasure hunting, relationships, mathematics, and technically minded characters. Although it is dense and roughly 1,000 pages long, it illustrates where computer science, cybersecurity, and mathematics intersect.
Q: How were books selected for the proposed cybersecurity canon?
Howard began with about 20 books that he believed deserved consideration rather than declaring a permanent or authoritative canon. He wrote reviews of those selections for his corporate and personal blogs so readers could consult synopses before reading them. The project also asks the security community to propose books, with the collection intended to be revisited every year as opinions and needs develop.
Q: What did the hacker movie survey reveal?
The survey of about 400 people suggested that favorite hacker movies often depend on generation and preferred characters rather than an objective judgment of quality. Howard associates WarGames with older viewers, Hackers with a younger generation, and The Matrix with an even younger one. He also observed that hacker characters evolved over roughly 25 years from being portrayed as villains toward becoming protagonists or heroes.
Q: Why does Rick Howard consider Stuxnet historically important?
Howard considers Stuxnet important because it publicly demonstrated an offensive cyber operation that destroyed critical infrastructure in a country with which the attackers were not formally at war. He says the United States and Israel targeted Iran's Natanz uranium enrichment facility after sanctions and negotiations were not working. The decision placed destructive cyber action among the options available to political leaders elsewhere.
Q: What skills are required for a cyber threat intelligence team?
A cyber threat intelligence team needs people who can perform deeply technical work, including pulling apart malware and understanding its operation, while also communicating effectively with senior corporate leaders. Howard describes this combination as exceptionally rare and estimates that perhaps 2,000 people worldwide had those abilities at the time, with all of them already employed. Recruiting therefore requires compelling and lucrative reasons to change organizations.
Summary & Key Takeaways
-
Rick Howard proposes a cybersecurity canon consisting initially of about 20 books that professionals, newcomers, friends, and family could read without requiring extensive technical knowledge. His suggested collection combines nonfiction about cybercrime, hacktivism, and cyberwar with fiction that tells engaging stories while representing technical concepts accurately enough to illuminate the profession.
-
Howard recommends Parmy Olson's We Are Anonymous for understanding Anonymous and its culture through access to members connected with major attacks in 2010 and 2011. For newcomers, he recommends Neal Stephenson's Cryptonomicon, a dense, roughly 1,000-page story connecting World War II, the 1990s dot-com era, mathematics, computer science, and cybersecurity.
-
The discussion links cybersecurity culture, policy, and workforce development. Hacker films reveal changing public perceptions, while Stuxnet established destructive cyber operations as an option for governments. Howard also describes building a threat intelligence team whose rare members must combine malware analysis and technical depth with an ability to communicate effectively to corporate executives.
Read in Other Languages (beta)
Share This Summary π
Summarize YouTube Videos and Get Video Transcripts with 1-Click
Try YouTube Summary with ChatGPT & Claude or YouTube Transcript Generator
Explore More Summaries from RSAC Cybersecurity π






Summarize YouTube Videos and Get Video Transcripts with 1-Click
Try YouTube Summary with ChatGPT & Claude or YouTube Transcript Generator