Home / Blog / “Would You Like to Write a Book…
Engagements and Process
“Would You Like to Write a Book About That?” – How One Talk Became a Book and a Company
Two people from Syngress came up to me as I came off the Black Hat stage in 2009. Saying yes meant leaving a salaried job, with a mortgage and a baby on the way. AppSec Labs exists because of that decision.
“What you talked about in your session is very interesting. Would you like to write a book about it?”
Without thinking twice I said “yes, of course”. Because you don't say no to a major publisher, right? I had no idea what I was walking into.
It all started with an article I wrote following research I did during an unusual penetration test, which was accepted to Black Hat in Las Vegas in 2009. It was a very long process that demanded deep research, and preparing the talk and delivering it successfully was no small challenge either. So I thought that once I finished the talk I could rest, because I had arrived. I did not imagine that I had not reached the end - it was only the beginning.
As I came off the stage, two people from Syngress Publishing approached me - a very well-known publisher of hacking books. After we talked a little, we arranged to continue and settle the details: how long the book would take (a year), how many chapters, the writing pace per chapter (a month, including proofing).
“I've got this”, I told myself. Then I got into it.
As someone who writes a lot of articles and security findings reports for clients, I said to myself at first that this would be easy. After I got into the thick of it I realised the scale of the investment. At the time I was in a salaried job, and writing a book unambiguously meant leaving it.
It is not easy to leave a comfortable salaried job: a good salary, status, financial security. Suddenly all sorts of things came into my head.
- I would have to resign. Unusual, and frightening.
- Bad timing. We were waiting for a daughter to be born. Wait with this. Why now?
- We had just bought a flat. What about the mortgage? How do you move from a fixed salary to variable income with no promise of anything?
- And maybe nobody would be interested. Maybe I would not know how to write. Maybe I would invest a year and tear myself apart for nothing.
- And who guarantees I would even finish? I had no experience of this. So I would genuinely be stepping into the unknown with no promise of success.
Was all of it worth it to realise the dream? Frightening. A lot was on the scales.
Why I went ahead anyway
I had an enormous amount of knowledge that just wanted to get out. What was I going to do, keep it inside? I wanted to fly with it. To keep researching, to put all of the knowledge down on paper, and to leave a mark - something that would stay in the world and gather what I had accumulated on the subject, because otherwise it would just sit in my head. I also had a strong need to help, to let other security people defend against the problem I had researched. I had to contribute. To share. To create. Whatever I wrote would stay forever. I would have a book of my own.
And I was flattered that the publisher approached me. They came to me - usually it is the other way round. I could always find a salaried job again. And besides, if not now, when?
That meant becoming self-employed. And if I was setting out on my own, I needed a framework - so I founded AppSec Labs. It worked out; it pushed me into it. So because of the book, I also founded a company. Looking back today, after we have run penetration tests for the biggest names in the industry, I understand that this is my calling. But that is a story for another post.
It nearly broke me, and I hit the target
Saturdays, holidays, late nights. But I met the deadline. Every month I produced a chapter, and chapter by chapter I learned to be more efficient and got fewer notes back from my editor. I was fortunate that my technical editor was Michael Howard from Microsoft, author of Writing Secure Code - the bible of our field when it comes to secure coding.
But in the end I did it. I set a target and I met it.
I would recommend to anyone standing in front of an important decision not to be afraid. Analyse everything, and if there is a direction, go for it. Believe in yourself - anything is possible. And even if you did not succeed, nothing has happened.
Was it worth it? Unequivocally yes.
The book is Managed Code Rootkits: Hooking into Runtime Environments (Syngress, 2010).
I first shared a version of this as a LinkedIn post on 2023-01-12. It is republished here, lightly edited, so it is easier to find and reference. — Erez Metula
Keep reading
More from the blog
Engagements and Process
Learn Mode and Enforce Mode Are Sold in the Same Breath. They Are Not the Same Thing.
An agent that scans, finds and proposes, with a human deciding, is where the field should go. An agent that writes and…
Read itEngagements and Process
I Run a Company of Pentesters, and I Watch AI Bots Doing Their Job
Faster, cheaper, and far more of it. The question is not whether AI replaces pentesters - it is which pentesters survive, and…
Read itEngagements and Process
“Just Send Me a Quote and We’ll See” – Why I Don’t Work That Way
A prospective client asked for a price before telling me what the systems do. In security testing, a quote without a scope…
Read itTell us what the system does and what worries you.
If a penetration test is not what you need yet, we will say so.