Security Engineering versus The Web Application Hacker's Handbook.

Both show up on every "best" list. They're not competitors. They're a sequence. Here's which one to read first, and when.

Reviewed by Ashish Sheth · Updated August 2026
Option A
Security Engineering
Security Engineering
Ross Anderson · 2020
READ FULL REVIEW →
Option B
The Web Application Hacker's Handbook
The Web Application Hacker's Handbook
Dafydd Stuttard, Marcus Pinto · 2011
READ FULL REVIEW →
Author
Ross Anderson
Dafydd Stuttard, Marcus Pinto
Pages
1232
912
Published
2020
2011
Publisher
Wiley
Wiley
Level
advanced
advanced
Amazon Rating
4.8/5 (265)
4.3/5 (329)
Goodreads Rating
4.21/5 (706)
4.35/5 (240)
Security Engineering
Strengths
+ Astonishing breadth; few books connect this many parts of security
+ Grounded in real-world failures and case studies, not abstractions
+ Pioneering treatment of security economics and human factors
+ The full third edition is also available free from the author's site
Caveats
Enormous at over 1,200 pages; it is a reference, not a weekend read
Broad rather than a hands-on tutorial for any single skill
Demanding for readers without a solid engineering background
The Web Application Hacker's Handbook
Strengths
+ The most thorough offensive web-security reference in print
+ Written by the creators of Burp Suite, so the methodology is battle-tested
+ Explains the why behind each attack, not just the steps
+ Its testing methodology still holds even as specific tech moves on
Caveats
Published in 2011, so it predates modern single-page-app and API patterns
Long and demanding at 912 pages; not a casual read
No third edition, so newer client-side frameworks fall outside it
The verdict
Security Engineering is the stronger pick overall, but The Web Application Hacker's Handbook may suit you better if you're a aspiring and working penetration testers focused on web applications.
Security Engineering
Check Price on Amazon →
The Web Application Hacker's Handbook
Check Price on Amazon →
Frequently asked
Which is better, Security Engineering or The Web Application Hacker's Handbook?
Security Engineering is the stronger pick overall, but The Web Application Hacker's Handbook may suit you better if you're a aspiring and working penetration testers focused on web applications.
Is Security Engineering good for beginners?
Not as a first book. At over 1,200 pages it is a deep, wide-ranging reference that assumes real engineering maturity. Beginners are better served by Alice and Bob Learn Application Security or Web Security for Developers, then coming to Ross Anderson's book once they want to understand security across cryptography, hardware, economics, and human factors.
Is The Web Application Hacker's Handbook still worth reading in 2026?
For the methodology, yes. It remains the most thorough guide to how web attacks work, and the testing approach still applies. The catch is age: the second edition is from 2011 and there is no newer one, so modern single-page apps, APIs, and frameworks are not covered. Pair it with PortSwigger's current online material.