Security Engineering cover
Pages
1232
Year
2020
Level
advanced
Read time
31h
Ross Anderson · Wiley · 2020
Reviewed by Ashish Sheth · Updated August 2026

Security Engineering

A Guide to Building Dependable Distributed Systems

4.8 / 5
AMAZON · 265 RATINGS
security
SUBJECTS
Check Price on Amazon →
What you'll come away with
01.
A field-wide map of security that connects code, hardware, and incentives
02.
Why most breaches trace back to economics and human factors, not math
03.
How real protocols fail, told through decades of documented cases
04.
A vocabulary for reasoning about dependable systems at scale
05.
A reference you return to for years rather than read once
Strengths
+Astonishing breadth; few books connect this many parts of security
+Grounded in real-world failures and case studies, not abstractions
+Pioneering treatment of security economics and human factors
+The full third edition is also available free from the author's site
Caveats
Enormous at over 1,200 pages; it is a reference, not a weekend read
Broad rather than a hands-on tutorial for any single skill
Demanding for readers without a solid engineering background
★ 4.8 FROM 265 READERS ON AMAZON
Check Price on Amazon →
Read this if
Engineers and architects who want the deepest, broadest security grounding
Security professionals who want one authoritative reference
Readers interested in why secure systems fail across whole industries
Skip this if
Beginners who want a short, practical first security book
Developers looking only for language-specific secure-coding recipes
Anyone wanting a quick tutorial rather than a deep reference
Head-to-head comparisons
Security Engineering vs Threat Modeling Security Engineering vs The Web Application Hacker's Handbook Security Engineering vs The Developer's Playbook for Large Language Model Security
MORE SOFTWARE SECURITY BOOKS
Frequently asked
Is Security Engineering good for beginners?
Not as a first book. At over 1,200 pages it is a deep, wide-ranging reference that assumes real engineering maturity. Beginners are better served by Alice and Bob Learn Application Security or Web Security for Developers, then coming to Ross Anderson's book once they want to understand security across cryptography, hardware, economics, and human factors.
Is the third edition worth it, and can I read it for free?
Yes on both counts. The 2020 third edition updates the case studies and adds material on newer threats, and Ross Anderson made the full text freely available on his University of Cambridge page. Many readers still buy the print copy as a reference; around 700 Goodreads readers rate the work about 4.2.
How is it different from Threat Modeling by Adam Shostack?
Threat Modeling is a focused, practical guide to one discipline: finding design flaws before you build. Security Engineering is a sweeping reference across the entire field, from protocols and hardware to the economics of security. Read Shostack to run threat-modeling sessions; read Anderson to understand why systems fail at every layer.
Read this next
3 alternatives
Threat Modeling cover
Adam Shostack
Threat Modeling
★ 4.5 · 339 RATINGS
The Web Application Hacker's Handbook cover
Dafydd Stuttard, Marcus Pinto
The Web Application Hacker's Handbook
★ 4.3 · 329 RATINGS
The Developer's Playbook for Large Language Model Security cover
Steve Wilson
The Developer's Playbook for Large Language Model Security
★ 4.6 · 29 RATINGS
Ready?
Check Price on Amazon →