Security Engineering versus Threat Modeling.

Both show up on every "best" list. They're not competitors. They're a sequence. Here's which one to read first, and when.

Reviewed by Ashish Sheth · Updated August 2026
Option A
Security Engineering
Security Engineering
Ross Anderson · 2020
READ FULL REVIEW →
Option B
Threat Modeling
Threat Modeling
Adam Shostack · 2014
READ FULL REVIEW →
Author
Ross Anderson
Adam Shostack
Pages
1232
624
Published
2020
2014
Publisher
Wiley
Wiley
Level
advanced
intermediate
Amazon Rating
4.8/5 (265)
4.5/5 (339)
Goodreads Rating
4.21/5 (706)
4.07/5 (288)
Security Engineering
Strengths
+ Astonishing breadth; few books connect this many parts of security
+ Grounded in real-world failures and case studies, not abstractions
+ Pioneering treatment of security economics and human factors
+ The full third edition is also available free from the author's site
Caveats
Enormous at over 1,200 pages; it is a reference, not a weekend read
Broad rather than a hands-on tutorial for any single skill
Demanding for readers without a solid engineering background
Threat Modeling
Strengths
+ The definitive treatment of threat modeling from a field founder
+ Gives you repeatable frameworks instead of vague advice
+ Deep and thorough, with plenty of worked examples
+ Applies well beyond software to any system you design
Caveats
Long and dense at 624 pages; it reads like a reference, not a tutorial
Published in 2014, so cloud and modern pipeline examples are thin
Heavier going for developers new to security fundamentals
The verdict
Read Threat Modeling first to build foundations, then move to Security Engineering for advanced concepts.
Security Engineering
Check Price on Amazon →
Threat Modeling
Check Price on Amazon →
Frequently asked
Which is better, Security Engineering or Threat Modeling?
Read Threat Modeling first to build foundations, then move to Security Engineering for advanced concepts.
Is Security Engineering good for beginners?
Not as a first book. At over 1,200 pages it is a deep, wide-ranging reference that assumes real engineering maturity. Beginners are better served by Alice and Bob Learn Application Security or Web Security for Developers, then coming to Ross Anderson's book once they want to understand security across cryptography, hardware, economics, and human factors.
Is Threat Modeling by Adam Shostack still worth reading in 2026?
Yes. The frameworks it teaches, the four-question method, STRIDE, and data flow diagrams, are still the standard vocabulary for threat modeling and have not been replaced. The 2014 examples predate today's cloud and CI/CD tooling, so read it for the durable method and apply that method to your own modern architecture.