// Comparison

The Practice of Network Security Monitoring vs Le Security Operations Center au cœur de la cybersécurité: Which Should You Read?

Two cybersecurity books on Defensive, compared honestly: who each is for, what each does best, and which to read first.

Intermediate
5/52013
The Practice of Network Security Monitoring

Understanding Incident Detection and Response

Richard Bejtlich

Richard Bejtlich's NSM playbook: how to deploy collection sensors, validate that you actually see what you think you see, and build detection workflows around open-source tools.

Intermediate
4/52026
Le Security Operations Center au cœur de la cybersécurité

La nécessaire constante évolution du SOC

Thomas Le Bourlot

Thomas Le Bourlot, nine years into operationalizing SOCs, delivers a systemic approach to the Security Operations Center that combines technology and governance, from supervision fundamentals through cloud, AI, and SOC-as-a-service models.

Read this if

Every SOC analyst and detection engineer. Bejtlich's foundational text on NSM: collect-everything, alert-on-narrow, investigate-broadly. Defines the vocabulary the modern detection field still uses.
Analysts, managers, and anyone involved in a SOC who wants a complete, progressive view: attack types, tooling (SIEM, EDR, SOAR) and how they complement each other, then the central role of human teams (CSIRT, red/blue/purple teams) and their collaboration.

Skip this if

Readers wanting current SIEM tooling specifics. The book pre-dates EDR-as-default and modern cloud-native telemetry; the principles transfer, the tooling specifics don't.
Readers looking for a hands-on configuration manual for a specific SIEM or EDR product; this book treats SOC organization and governance as a system, not product-by-product setup.

Key takeaways

  • Detection without prevention is a strategic choice, not a fallback; Bejtlich was years ahead in arguing the case and the book remains the clearest argument.
  • The four data types (full content, session, transactional, statistical) are still the right framework for thinking about detection coverage.
  • Most SOC failures are organizational and procedural, not tooling; the book's chapters on workflows, runbooks, and analyst growth are still the best in print.
  • No dedicated SOC book existed in this catalog until now, filling a real gap for blue-team and analyst careers.
  • Treats the human factor and collaborative models as just as decisive as the tooling for SOC effectiveness.
  • Gives a forward-looking view of the modern SOC: cloud, artificial intelligence, and as-a-service models, not just the status quo.

How they compare

We rate The Practice of Network Security Monitoring higher (5/5 against 4/5 for Le Security Operations Center au cœur de la cybersécurité). For most readers, that means The Practice of Network Security Monitoring is the primary pick and Le Security Operations Center au cœur de la cybersécurité is a useful follow-up.

Both books target intermediate-level readers, so the choice is about topic, not difficulty.

The Practice of Network Security Monitoring and Le Security Operations Center au cœur de la cybersécurité both cover Defensive, Detection, so reading them in sequence reinforces the same material from different angles.

Keep reading

Related topics