Security Engineering versus The Developer's Playbook for Large Language Model Security.

Both show up on every "best" list. They're not competitors. They're a sequence. Here's which one to read first, and when.

Reviewed by Ashish Sheth · Updated August 2026
Option A
Security Engineering
Security Engineering
Ross Anderson · 2020
READ FULL REVIEW →
Option B
The Developer's Playbook for Large Language Model Security
The Developer's Playbook for Large Language Model Security
Steve Wilson · 2024
READ FULL REVIEW →
Author
Ross Anderson
Steve Wilson
Pages
1232
200
Published
2020
2024
Publisher
Wiley
O'Reilly Media
Level
advanced
intermediate
Amazon Rating
4.8/5 (265)
4.6/5 (29)
Goodreads Rating
4.21/5 (706)
3.71/5 (41)
Security Engineering
Strengths
+ Astonishing breadth; few books connect this many parts of security
+ Grounded in real-world failures and case studies, not abstractions
+ Pioneering treatment of security economics and human factors
+ The full third edition is also available free from the author's site
Caveats
Enormous at over 1,200 pages; it is a reference, not a weekend read
Broad rather than a hands-on tutorial for any single skill
Demanding for readers without a solid engineering background
The Developer's Playbook for Large Language Model Security
Strengths
+ The most practical single book on securing apps built with LLMs
+ Written for developers, so advice maps onto code you are already writing
+ Built on the OWASP Top 10 for LLMs, so the coverage is structured and current
+ Short and focused; you can read it before a launch and act on it
Caveats
A fast-moving field, so some tools and attacks will keep evolving past print
Assumes you already build software; it is not an introduction to AI itself
Broad by design, so a specific attack class may need deeper follow-up reading
The verdict
Read The Developer's Playbook for Large Language Model Security first to build foundations, then move to Security Engineering for advanced concepts.
Security Engineering
Check Price on Amazon →
The Developer's Playbook for Large Language Model Security
Check Price on Amazon →
Frequently asked
Which is better, Security Engineering or The Developer's Playbook for Large Language Model Security?
Read The Developer's Playbook for Large Language Model Security first to build foundations, then move to Security Engineering for advanced concepts.
Is Security Engineering good for beginners?
Not as a first book. At over 1,200 pages it is a deep, wide-ranging reference that assumes real engineering maturity. Beginners are better served by Alice and Bob Learn Application Security or Web Security for Developers, then coming to Ross Anderson's book once they want to understand security across cryptography, hardware, economics, and human factors.
Who should read The Developer's Playbook for Large Language Model Security?
Developers and tech leads who are adding LLM features, chatbots, RAG systems, or agents to a product and want a security baseline before they ship. It assumes you build software but are new to the risks specific to large language models, and it maps each risk onto practical code-level defenses. About 40 Goodreads readers rate it around 3.7.