Security builder & leader

How Much Should an Information Security Book Cost?

As a reader and author of information security books, I wonder how much should such books cost and whether we can expect the price of electronic infosec books to drop?

Factors That Might Drive Down the Cost of Books

Most information security authors don’t write technical for the money, because technical books rarely generate significant revenue through royalties. However, writing a book allows the author to spread knowledge and also to benefit from the recognition one receives for the publication. From this perspective, the author might chose to forgo royalties for the book if that would increase the reader base.

Moreover, many sources of information compete for the reader’s attention. There’s a plethora of insightful infosec materials available freely on the web in the form of blogs and articles; many of them are written by the same person who would write a book. As the result, some readers may avoid paying for a book in favor of receiving similar web content for free. Might we find ourselves in a situation where the readers will even be paid for the time they would devote to reading the book?

Several Book-Pricing Examples

Richard Bejtlich pointed out that not all books, nor reading practices, are created equal. We might read some information security books for fun, to learn a specific skill set or to obtain a high-level perspective on the topic. We also treat some books as a reference, rarely reading them from cover to cover, but periodically dipping into their contents to answer specific questions. Different types of books might differ in how they are priced. Here are a few examples:

The Value of a Technical Book

To understand what value a book might bring despite the broad availability of free content on the web, consider the how Kevin Kelly defined a book:

A book is a self-contained story, argument, or body of knowledge that takes more than an hour to read. A book is complete in the sense that it contains its own beginning, middle, and end.

The value that a technical book brings is in bringing together a set of related concepts into a story and argument or a theme that helps the reader understand the concepts.

For instance, this blog contains lots of information security posts, which I publish one day at a time. I leave it up to the reader to figure out how the postings are related together. If I unified related articles from the blog to focus on a particular topic, fixed any inconsistencies in my arguments and added appropriate transition text, I could publish the resulting volume as a book. There would be some value that readers would derive from my taking the time to organize the concepts in this manner, and they may be willing to pay for that benefit.

What Does The Future Hold?

The authors’ desire to be recognized, the low royalties from technical books and the increasing availability of free on-line content, and the low incremental cost of distributing an e-book will drive the price of infosec e-books down. The publishers’ actions to protect their business model will resist this trend and might be strong enough to prevent a significant drop in prices.

As an author, I would prefer to use a publisher to distribute printed copies of the book at prices that allow the publisher to cover costs and derive profit from the marketing and distribution activities of the book. I would prefer to have the electronic version of the book distributed for a very low cost.

About the Author

Lenny Zeltser is a cybersecurity executive with deep technical roots, product management experience, and a business mindset. As CISO at Axonius, he leads the security and IT program, focusing on trust and growth. He is also a Faculty Fellow at SANS Institute and the creator of REMnux, a popular Linux toolkit for malware analysis. Lenny shares his perspectives on security leadership and technology at zeltser.com.

Learn more →