“Would You Like to Write a Book About That?” – How One Talk Became a Book and a Company

“What you talked about in your session is very interesting. Would you like to write a book about it?”

Without thinking twice I said “yes, of course”. Because you don’t say no to a major publisher, right? I had no idea what I was walking into.

It all started with an article I wrote following research I did during an unusual penetration test, which was accepted to Black Hat in Las Vegas in 2009. It was a very long process that demanded deep research, and preparing the talk and delivering it successfully was no small challenge either. So I thought that once I finished the talk I could rest, because I had arrived. I did not imagine that I had not reached the end – it was only the beginning.

As I came off the stage, two people from Syngress Publishing approached me – a very well-known publisher of hacking books. After we talked a little, we arranged to continue and settle the details: how long the book would take (a year), how many chapters, the writing pace per chapter (a month, including proofing).

“I’ve got this”, I told myself. Then I got into it.

As someone who writes a lot of articles and security findings reports for clients, I said to myself at first that this would be easy. After I got into the thick of it I realised the scale of the investment. At the time I was in a salaried job, and writing a book unambiguously meant leaving it.

It is not easy to leave a comfortable salaried job: a good salary, status, financial security. Suddenly all sorts of things came into my head.

  • I would have to resign. Unusual, and frightening.
  • Bad timing. We were waiting for a daughter to be born. Wait with this. Why now?
  • We had just bought a flat. What about the mortgage? How do you move from a fixed salary to variable income with no promise of anything?
  • And maybe nobody would be interested. Maybe I would not know how to write. Maybe I would invest a year and tear myself apart for nothing.
  • And who guarantees I would even finish? I had no experience of this. So I would genuinely be stepping into the unknown with no promise of success.

Was all of it worth it to realise the dream? Frightening. A lot was on the scales.

Why I went ahead anyway

I had an enormous amount of knowledge that just wanted to get out. What was I going to do, keep it inside? I wanted to fly with it. To keep researching, to put all of the knowledge down on paper, and to leave a mark – something that would stay in the world and gather what I had accumulated on the subject, because otherwise it would just sit in my head. I also had a strong need to help, to let other security people defend against the problem I had researched. I had to contribute. To share. To create. Whatever I wrote would stay forever. I would have a book of my own.

And I was flattered that the publisher approached me. They came to me – usually it is the other way round. I could always find a salaried job again. And besides, if not now, when?

That meant becoming self-employed. And if I was setting out on my own, I needed a framework – so I founded AppSec Labs. It worked out; it pushed me into it. So because of the book, I also founded a company. Looking back today, after we have run penetration tests for the biggest names in the industry, I understand that this is my calling. But that is a story for another post.

It nearly broke me, and I hit the target

Saturdays, holidays, late nights. But I met the deadline. Every month I produced a chapter, and chapter by chapter I learned to be more efficient and got fewer notes back from my editor. I was fortunate that my technical editor was Michael Howard from Microsoft, author of Writing Secure Code – the bible of our field when it comes to secure coding.

But in the end I did it. I set a target and I met it.

I would recommend to anyone standing in front of an important decision not to be afraid. Analyse everything, and if there is a direction, go for it. Believe in yourself – anything is possible. And even if you did not succeed, nothing has happened.

Was it worth it? Unequivocally yes.

The book is Managed Code Rootkits: Hooking into Runtime Environments (Syngress, 2010).


I first shared a version of this as a LinkedIn post on 2023-01-12. It is republished here, lightly edited, so it is easier to find and reference. — Erez Metula