相關主題
商品描述
Guiding security leaders and executives who hold the privilege of defending modern organizations, "The CISO Playbook - The Adversarial Mindset" is a leadership-focused blueprint for outmaneuvering adversaries that iterate relentlessly. In an era where attackers view corporate defenders as "dumb, weak, and ineffective" due to organizational drag and over-reliance on static tools, this book empowers leaders to reclaim the initiative by adopting a true adversarial mindset.
Harnessing the concept of Decision Advantage, the book moves beyond treating incidents as isolated technical events by thinking in adversary terms: objectives, constraints, and tradecraft. It bridges the gap between attacker methods and board-level risk, showing how to translate security outcomes into the language of economics, EBITDA, and revenue protection.
Operationalizing lessons from real-world campaigns like SolarWinds, Volt Typhoon, and Operation Aurora, the text connects tradecraft to operational reality. It introduces the unique metric of Time-to-Hazard Neutralization, moving past ticket metadata to focus on the verified removal of risk from the environment.
Spotlighting the rise of the "Artificial Adversary," a central thread details how AI-enhanced human actors and autonomous systems act with malicious intent. From industrialized "vibe hacking" to active scanning and autonomous reconnaissance, the book reveals how AI accelerates the attacker's OODA loop and how CISOs must respond by compressing their own defensive cycles.
Translating theoretical models into repeatable methods, the text provides strategies for terrain engineering, deception, and resilience-centric incident response. Written for CISOs, deputies, and security leaders, it serves those who both brief members of C-Suites and boards and also run outcome-based programs. Instead of remaining a reactive enforcer, readers will find a blueprint for becoming a proactive Enterprise Risk Leader. Navigating this shift ultimately rewards the disciplined observation required to outthink the opponent.
商品描述(中文翻譯)
引導肩負捍衛現代組織這項特權的資安領導者與高階主管,《The CISO Playbook - The Adversarial Mindset》是一份以領導力為核心的藍圖,協助組織智取那些持續反覆演進的對手。在攻擊者因組織內耗與過度依賴靜態工具,而將企業防禦者視為「愚蠢、弱小且無效」的時代,本書將協助領導者採納真正的對抗者思維,重新掌握主動權。
本書運用「決策優勢(Decision Advantage)」概念,不再將資安事件視為孤立的技術事件,而是以對手的角度思考:目標、限制條件與作戰技術。它架起攻擊者手法與董事會層級風險之間的橋梁,說明如何將資安成果轉化為經濟學、EBITDA 與營收保護等高階主管所熟悉的語言。
本書從 SolarWinds、Volt Typhoon 與 Operation Aurora 等真實世界攻擊行動中提煉經驗,將作戰技術與營運現實連結起來。書中介紹獨特的「威脅中和時間(Time-to-Hazard Neutralization)」指標,不再停留於工單中繼資料,而是聚焦於經驗證後,確認環境中的風險已被移除。
本書以「人工智慧對手(Artificial Adversary)」的崛起為核心主軸之一,詳細說明經 AI 強化的人類行動者與自主系統如何以惡意意圖展開行動。從產業化的「vibe hacking(憑感覺的駭客攻擊)」到主動掃描與自主偵察,本書揭示 AI 如何加速攻擊者的 OODA loop,以及 CISO 必須如何壓縮自身的防禦週期以因應。
本書將理論模型轉化為可重複執行的方法,提供地形工程、欺敵與以韌性為核心的事件回應策略。本書寫給 CISO、副手與資安領導者,服務那些既要向 C-Suite 成員與董事會進行簡報,也要負責執行以成果為導向之資安計畫的人員。讀者不必繼續扮演被動反應的執法者,而能依循這份藍圖,成為主動積極的企業風險領導者(Enterprise Risk Leader)。在完成這項轉變的過程中,嚴謹的觀察力將成為洞悉並超越對手的關鍵。
作者簡介
Andres Andreu is currently the Chief Executive Officer (CEO) at Constella Intelligence, a 4X Chief Information Security Officer (CISO), and a renowned cybersecurity leader. He holds prestigious credentials including CISSP and ISSAP and is a Boardroom Certified Qualified Technology Expert (QTE). With a diverse career traversing federal government, corporate sectors, and entrepreneurial ventures in cybersecurity, he is a mentor, start-up advisor, and an acclaimed author.
His government tenure includes a significant impact in lawful intercept technology within federal law enforcement, earning three U.S. Department of Justice awards for his contributions to drug law enforcement. Transitioning to the corporate realm, Andres made a mark at Ogilvy & Mather as a partner and Chief Application Architect, later consulting for high-profile entities like the United Nations. As a founding member and key executive at Bayshore Networks (acquired by Opswat in 2021) and cybersecurity leader at Constella Intelligence, 2U, Inc./edX, and Hearst, his expertise has been pivotal in shaping varying cybersecurity landscapes.
Andreu's leadership and innovative approaches have garnered him accolades such as a Top 100 CISO (C100) by Security Current, Top 50 Information Security Professional, and recognition in leading industry publications. His experience encompasses both offensive and defensive cybersecurity strategies, underpinned by a philosophy that balances executive and employee objectives.
Author of The CISO Playbook, Professional Pen Testing Web Applications, and contributor to 97 Things Every Application Security Professional Should Know, his work extends beyond writing to inventing, with patents in cybersecurity innovations. He is also an active member of the Forgepoint Capital Cybersecurity Advisory Council.
A Cuban immigrant and proud American citizen, Andres balances his professional achievements with a happy marriage and four wonderful kids. He is an international level certified Judo coach with USA Judo and an artist. Andreu's multifaceted career and personal achievements highlight his profound impact on the cybersecurity field and beyond.
Hector Monsegur, known globally online as "Sabu," is one of the most infamous names in the history of hacking. As the driving force behind the legendary hacking collective LulzSec, an offshoot of Anonymous, he spearheaded high-profile breaches against Sony Pictures, PBS, Fox.com, and multiple government systems. His campaigns during the early 2010s redefined the scale and spectacle of cyber intrusions, making him a symbol of the hacker underground and a pivotal figure in the evolution of digital security.
After his arrest in 2011, Monsegur shocked the world by cooperating with U.S. federal authorities, helping to disrupt major planned cyberattacks and prevent untold damage. This unexpected turn gave him rare insight into both sides of the cybersecurity battlefield - the tactics of hackers and the mechanisms of law enforcement. His transformation from blackhat to security insider is a story of redemption and reinvention, steeped in controversy, credibility, and unmatched real-world experience.
Today, Hector is Chief Research Officer at SafeHill, a cutting-edge cybersecurity research firm dedicated to protecting organizations from the kinds of threats he once unleashed. SafeHill's services include elite penetration testing and its flagship threat exposure management platform, SafeHill SecureIQ, which enables businesses to identify, prioritize, and eliminate vulnerabilities before attackers can exploit them. Under his leadership, SafeHill is quickly earning a reputation as a disruptive force in the cybersecurity industry.
Beyond his work at SafeHill, Monsegur is an accomplished co-author, adjunct professor, and sought-after keynote speaker. He brings his signature edge and authenticity to classrooms, conferences, and boardrooms alike, training professionals and students to think like hackers while defending like strategists. His experience bridges underground hacking culture and enterprise-level security operations, making him one of the few experts who truly understands the full spectrum of cyber risk.
作者簡介(中文翻譯)
Andres Andreu 目前擔任 Constella Intelligence 的執行長(CEO),曾四度擔任資訊安全長(CISO),也是享有盛譽的資安領導者。他擁有 CISSP 與 ISSAP 等備受推崇的專業認證,並取得董事會認證的合格技術專家(Qualified Technology Expert, QTE)資格。他的資安職涯橫跨聯邦政府、企業界與創業領域,除了擔任導師與新創企業顧問之外,也是備受肯定的作者。
他在政府部門任職期間,曾在聯邦執法機關的合法攔截技術領域帶來重大影響,並因對毒品執法工作的貢獻,三度獲得美國司法部頒發的獎項。轉戰企業界後,Andres 在 Ogilvy & Mather 擔任合夥人兼首席應用程式架構師,嶄露頭角;之後也曾為 United Nations 等知名組織提供顧問服務。作為 Bayshore Networks 的創始成員與核心主管(該公司於 2021 年被 Opswat 收購),以及 Constella Intelligence、2U, Inc./edX 和 Hearst 的資安領導者,他的專業能力對不同資安環境的發展發揮了關鍵作用。
Andreu 的領導能力與創新方法為他贏得多項殊榮,包括 Security Current 評選的百大資訊安全長(Top 100 CISO,C100)、前 50 名資訊安全專業人士(Top 50 Information Security Professional),並獲多家領先業界出版物報導。他的經驗涵蓋攻擊型與防禦型資安策略,並以兼顧高階主管與員工目標的理念為基礎。
他著有《The CISO Playbook》、《Professional Pen Testing Web Applications》,並參與撰寫《97 Things Every Application Security Professional Should Know》。除了寫作之外,他也投身發明創新,擁有多項資安技術專利。他同時也是 Forgepoint Capital Cybersecurity Advisory Council 的活躍成員。
Andres 是古巴移民,也是以身為美國公民為榮的美國人;在專業成就之外,他也擁有幸福的婚姻與四名可愛的孩子。他是獲 USA Judo 認證、具國際級資格的柔道教練,也是一名藝術家。Andreu 多元的職涯與個人成就,彰顯了他對資安領域及更廣泛社會所帶來的深遠影響。
Hector Monsegur 在網路世界以「Sabu」聞名,是駭客史上最聲名狼藉的人物之一。作為傳奇駭客組織 LulzSec(Anonymous 的分支)的幕後推手,他主導了針對 Sony Pictures、PBS、Fox.com 以及多個政府系統的高知名度攻擊。2010 年代初期,他所發起的行動重新定義了網路入侵的規模與話題性,使他成為地下駭客圈的象徵,也是數位安全演進過程中的關鍵人物。
Monsegur 於 2011 年遭到逮捕後,與美國聯邦當局合作,震撼了全世界。他協助瓦解多起重大、有計畫的網路攻擊,並避免造成難以估量的損害。這場出乎意料的轉變,讓他得以深入了解資安戰場的兩個面向——駭客的戰術,以及執法機關的運作機制。他從黑帽駭客轉變為資安圈內人士的歷程,是一段充滿爭議、可信度考驗與無可比擬實戰經驗的救贖與重塑故事。
如今,Hector 擔任 SafeHill 的首席研究官(Chief Research Officer)。SafeHill 是一家尖端資安研究公司,致力於保護組織免受他過去曾發動的類型之威脅。SafeHill 提供的服務包括頂尖滲透測試,以及旗艦級威脅暴露管理平台 SafeHill SecureIQ。該平台能協助企業在攻擊者加以利用之前,找出、排定優先順序並消除漏洞。在他的領導下,SafeHill 很快便在資安產業中建立起顛覆性力量的聲譽。
除了在 SafeHill 的工作之外,Monsegur 也是一位傑出的共同作者、兼任教授與廣受邀請的主題演講者。他將獨特的銳利觀點與真實風格帶入教室、會議及董事會議室,訓練專業人士與學生像駭客一樣思考,同時以策略家的方式進行防禦。他的經驗橫跨地下駭客文化與企業級資安營運,使他成為少數真正理解完整網路風險光譜的專家之一。