// Comparison

Network Security Through Data Analysis vs Le Security Operations Center au cœur de la cybersécurité: Which Should You Read?

Two cybersecurity books on Defensive, compared honestly: who each is for, what each does best, and which to read first.

Intermediate
4/52017
Network Security Through Data Analysis

From Data to Action

Michael Collins

Michael Collins on building situational awareness from network telemetry: collection architecture, statistical baseline-setting, and the analytic patterns that turn raw flows into detection.

Intermediate
4/52026
Le Security Operations Center au cœur de la cybersécurité

La nécessaire constante évolution du SOC

Thomas Le Bourlot

Thomas Le Bourlot, nine years into operationalizing SOCs, delivers a systemic approach to the Security Operations Center that combines technology and governance, from supervision fundamentals through cloud, AI, and SOC-as-a-service models.

Read this if

Detection engineers and SOC analysts who've graduated from "what alert is this" to "is this alert worth triaging at all." Collins is the quantitative-detection text the field needed.
Analysts, managers, and anyone involved in a SOC who wants a complete, progressive view: attack types, tooling (SIEM, EDR, SOAR) and how they complement each other, then the central role of human teams (CSIRT, red/blue/purple teams) and their collaboration.

Skip this if

Beginners with no NSM background, or readers who only do log-based detection. The book leans heavily on flow data and statistical thinking; pair with The Practice of Network Security Monitoring (Bejtlich) first if you're new to the discipline.
Readers looking for a hands-on configuration manual for a specific SIEM or EDR product; this book treats SOC organization and governance as a system, not product-by-product setup.

Key takeaways

  • Detection engineering at scale is a statistical problem; the book teaches the framing every modern SOC eventually reinvents.
  • Flow-data analytics (NetFlow / IPFIX / sFlow) catch lateral movement that packet-based detection misses; the book is the cleanest treatment in print.
  • Time-series anomaly detection can be done well with off-the-shelf tooling and clear thinking; the chapters on baseline calibration are the practical core.
  • No dedicated SOC book existed in this catalog until now, filling a real gap for blue-team and analyst careers.
  • Treats the human factor and collaborative models as just as decisive as the tooling for SOC effectiveness.
  • Gives a forward-looking view of the modern SOC: cloud, artificial intelligence, and as-a-service models, not just the status quo.

How they compare

Network Security Through Data Analysis and Le Security Operations Center au cœur de la cybersécurité are both rated 4/5 in our catalog. Pick by topic preference and reading style rather than by rating.

Both books target intermediate-level readers, so the choice is about topic, not difficulty.

Network Security Through Data Analysis and Le Security Operations Center au cœur de la cybersécurité both cover Defensive, Detection, so reading them in sequence reinforces the same material from different angles.

Keep reading

Related topics