// Comparison

How Cybersecurity Really Works vs Practical Vulnerability Management: Which Should You Read?

Two cybersecurity books on Foundations, compared honestly: who each is for, what each does best, and which to read first.

Beginner
4/52021
How Cybersecurity Really Works

A Hands-On Guide for Total Beginners

Sam Grubb

Sam Grubb's gentle, exercise-driven introduction for non-specialists who need a working mental model of attacker behaviour and basic defence.

Intermediate
4/52020
Practical Vulnerability Management

A Strategic Approach to Managing Cyber Risk

Andrew Magnusson

A working security engineer's guide to building a vulnerability management program from open-source tools on a real budget, covering scanning, prioritization, automation, and reporting end to end.

Read this if

Non-engineers who need the field demystified. Grubb is the gentlest serious introduction in print: malware, phishing, network attacks, defenses, all explained in plain language without dumbing down.
Security engineers and small-team leads who need to stand up a vulnerability management practice without an enterprise tooling budget. Magnusson writes from inside real SOC2-compliance and firewall-to-consulting experience, not from a vendor's playbook.

Skip this if

Engineers, IT people, or anyone who already understands how the internet works. The book assumes nothing; for technical readers it'll feel slow.
Readers at organizations with mature, well-staffed vulnerability management already in place, or who want deep technical exploitation detail; this is program and process design, not an exploitation manual.

Key takeaways

  • The chapter on threat modeling for individuals (not companies) is the one most teachers steal from: how to think about your own digital risk.
  • The hands-on labs at the end of each chapter make the book usable for actual classroom teaching, not just self-study.
  • Strikes the rare balance between respects-the-reader and explains-what-an-IP-address-is. Most beginner books fail one or the other.
  • Treats vulnerability management as a program to run, not a scan to schedule — intelligence, prioritization, and reporting matter as much as the scanner.
  • Built entirely around free and open-source tooling, so the advice works on a startup or small-team budget, not just an enterprise one.
  • Prioritization gets real treatment: not every finding deserves the same response, and the book gives a concrete framework for triage.

How they compare

How Cybersecurity Really Works and Practical Vulnerability Management are both rated 4/5 in our catalog. Pick by topic preference and reading style rather than by rating.

How Cybersecurity Really Works is pitched at beginner level. Practical Vulnerability Management is pitched at intermediate level. Read the easier one first if you're not yet comfortable with the topic.

How Cybersecurity Really Works and Practical Vulnerability Management both cover Foundations, Defensive, so reading them in sequence reinforces the same material from different angles.

Keep reading

Related topics