July Newsletter
The CyberCanon Project: The cybersecurity professional’s first source for curated, timeless, and must-consume wisdom.
In this edition:
A summary of the latest book reviews posted on the CyberCanon website.
Hall of Fame Book Review Recommendations
CyberCanon Speaker’s Bureau
Where to donate
How to send book recommendations
Our Vision
In the chaotic flood of cybersecurity content, CyberCanon is your signal in the noise—the cybersecurity professional’s first stop for must-consume wisdom. We curate timeless, expert-reviewed books that shape the field and go beyond fleeting trends. Think of us as the Hall of Fame for Cybersecurity Books—no fluff, just what matters.
Latest Book Review: Cyber Recon: My Life in Cyber Espionage and Ransomware Negotiation by Kurtis Minder
Book Review By Jonathan Cote
As I continue to deepen my cybersecurity knowledge this year, threat intelligence and threat actor engagement are two areas that have sparked my interest whenever they have been briefly covered in books, articles, or conference talks. So, when Richard Stiennon posted about a new book called “Cyber Recon,” it looked intriguing, and the next thing I knew, a copy was in my hands before the official release date. (Bonus: Richard wrote the foreword, which itself serves as an excellent review of the book.)
A couple of months later, I got the opportunity to meet Kurtis at both Black Hat and DEF CON, where he signed my copy and introduced me to Jon DiMaggio (of Analyst1’s Ransomware Diaries), who is one of the cyber professionals profiled in the book. Both are genuinely down-to-earth and approachable, doing incredible work that comes with significant personal risk. Definitely take the opportunity to listen to either of them speak if you get the chance. Kurtis was recently on a Defendify virtual session, and it’s clear he’s the real deal, calmly explaining threat actor negotiation techniques and answering questions with very thoughtful responses.
At the beginning of the book, it was no surprise to learn that the CyberCanon Hall of Famer, “The Cuckoo’s Egg,” was a favorite book of Kurtis when he was still in school. At his first job at an ISP, he found himself approaching the kind of hacking described by the author and main character, Cliff Stoll. AND by looking through system logs on the first day of his promotion, he found an intruder he believed to be his recently fired boss, which marked the first of many communications with threat actors.
He also built honeypots early in his career, which he said weren’t yet known as such. This also seemed to be inspired by the techniques in “The Cuckoo’s Egg.” These initial experiences appeared to set the tone for his career, which has been heavily influenced by engagement with threat actors, ultimately leading to direct negotiations with ransomware groups.
“Cyber Recon” captures those experiences with candor and strong storytelling, as a small part memoir, and a large part field guide for anyone who wants to “fight the good fight.” In his own words, Minder describes “Cyber Recon” as both entertaining and educational, stating, “It is for those who want to fight the bad guys, learn their methods, become their confidants, and turn the tide.” That’s pretty accurate. The book walks through cyber espionage stories, threat actor conversations, and negotiation case studies, and never feels like a textbook.
One of my favorite touches is that at the end of each chapter, he highlights peers and contributors, giving them the spotlight through short summaries and QR codes to video interviews. It’s a subtle but powerful show of humility, and that community spirit runs deep throughout the book.
If there’s one theme that defines “Cyber Recon,” it’s emotional intelligence. Minder argues that high emotional intelligence is central to good cyber threat intelligence and essential in ransomware negotiations. Understanding your adversary as a human being is key to being a good negotiator.
These adversaries work for organizations that are often run just like businesses. The “employees” behind the keyboard are frequently not evil masterminds, but instead, are just people in struggling economies doing what their system rewards. And, often, even protected by their local governments!…..
Hall of Fame Book Review Recommendation: The Perfect Weapon: War, Sabotage and Fear in the Cyber Age by David Sanger
Book Review By U.S. Army Major General (Retired) John Davis
I recommend “The Perfect Weapon” for average citizens who have little to no sophisticated understanding of the digital age in which we live but who are interested in what’s going on in the often mysterious, even ominous, world of cyber. I had a special interest in reviewing this book because I lived through most of the events that David Sanger, the author, wrote about; first as a senior U.S. military officer who spent the last decade of my career in cyber related assignments from 2006-2015, and then as the federal Chief Security Officer for one of the world’s largest enterprise cybersecurity companies from 2015 until present. While I may disagree with some of the details in his book because of my personal experiences, I believe that Sanger’s description is “close enough” to paint an accurate overall picture of what’s been happening in the cyber world for at least a decade and a half. More importantly, I believe that Sanger brings to life in a very powerful way many of the key challenges that we all face.
These challenges include the issues we face as a nation, as an international community of responsible nations, as an international industrial community that’s transforming into a totally digital model, and as people who are becoming increasingly dependent on (and vulnerable to) a world where everything and everyone are increasingly connected. These issues touch on our collective national and economic security as well as our public safety and welfare. Nothing is more important than understanding that the promise and opportunity of the digital age has a counterbalance in threats and dangers that can be existential if left unmanaged. “The Perfect Weapon” helps bring to light a better understanding of the technology race between cyber for good and evil, which until recently has been largely contained in the shadows.
“The Perfect Weapon” provides us with a substantial level of detail regarding most of the major cyber and cyber related events in recent history. It is a good summary for anyone wanting to understand what’s been happening in the shadows of the cyber world. This includes the activities of Russia, China, Iran and North Korea over the past decade plus. It also provides unique insight into the development of cyber programs in the U.S. military as well as other nations such as Israel. Furthermore, it discusses major events that intersect the public and private sectors, like the ones Snowden disclosed, and resulted in a rift between the U.S. government and various corporate entities.
There are four themes in “The Perfect Weapon” that I found especially useful and illuminating. The first theme focuses on identifying the appropriate level of increasing transparency from governments about what’s going on in cyberspace. This includes giving perspective on emerging threats as well as what governments are doing about them. The second theme is about the role of offensive and defensive cyber activities and how that is changing in today’s environment due to innovation in automation and software-based advanced analytics. The third theme is about cyber activities potentially escaping the “grey zone” through escalated actions and subsequently entering the traditional world via the use of force to trigger an armed conflict. Finally, the last theme touches on the need for a strategic partnership between government and industry in order to achieve a more effective way to leverage the benefits of the digital age, while still managing the serious risks that are growing by the day.
The first theme about the need for greater transparency is well past due in my opinion, but there has been progress recently. There should be no expectation of total transparency, but there must be greater transparency than ever before. A lack of transparency breeds uncertainty and increases the chance of misinterpretation, miscalculations and mistakes that can lead to escalation. More transparency leads to better stability, increased trust and the chance for cooperation, as has been the case for non-proliferation, countering terrorism, anti-piracy and other examples of international efforts of mutual interest, even with countries like Russia and China.
CyberCanon Speaker’s Bureau
Our roster of speakers includes Hall of Fame authors and leaders who have shaped the field through real-world executive experience.
Check out our new site and consider booking a CyberCanon speaker for an upcoming event:
Do you have a CyberCanon-worthy book recommendation?
We are always seeking books for the CyberCanon committee to review. If you have one to nominate, leave a comment below or send an email to suggest-a-book@cybercanon.org.




I'd love to see a review of Locked Up by Zach Lewis and nominate it for the hall of fame!