Shipping costs will be calculated based on this address throughout the site.
Select your country
Americas
Argentina
Brazil
Canada
Chile
Colombia
Costa Rica
Dominican Republic
Ecuador
El Salvador
Mexico
Peru
U.S.A.
Uruguay
Europe
Austria
Belgium
Croatia
Czech Republic
Denmark
Finland
France
Germany
Greece
Hungary
Ireland
Italy
Latvia
Malta
Netherlands
Norway
Poland
Portugal
Serbia
Slovakia
Slovenia
Spain
Sweden
Switzerland
United Kingdom
Rest of the world


The CISO Playbook: The Adversarial Mindset
Andres Andreu (Author) · CRC Press · Hardcover
Guiding security leaders and executives who hold the privilege of defending modern organizations, “The CISO Playbook - The Adversarial Mindset” is a leadership-focused blueprint for outmaneuvering adversaries that iterate relentlessly. In an era where attackers view corporate defenders as “dumb, weak, and ineffective” due to organizational drag and over-reliance on static tools, this book empowers leaders to reclaim the initiative by adopting a true adversarial mindset.
Harnessing the concept of Decision Advantage, the book moves beyond treating incidents as isolated technical events by thinking in adversary terms: objectives, constraints, and tradecraft. It bridges the gap between attacker methods and board-level risk, showing how to translate security outcomes into the language of economics, EBITDA, and revenue protection.
Operationalizing lessons from real-world campaigns like SolarWinds, Volt Typhoon, and Operation Aurora, the text connects tradecraft to operational reality. It introduces the unique metric of Time-to-Hazard Neutralization, moving past ticket metadata to focus on the verified removal of risk from the environment.
Spotlighting the rise of the “Artificial Adversary,” a central thread details how AI-enhanced human actors and autonomous systems act with malicious intent. From industrialized “vibe hacking” to active scanning and autonomous reconnaissance, the book reveals how AI accelerates the attacker’s OODA loop and how CISOs must respond by compressing their own defensive cycles.
Translating theoretical models into repeatable methods, the text provides strategies for terrain engineering, deception, and resilience-centric incident response. Written for CISOs, deputies, and security leaders, it serves those who both brief members of C-Suites and boards and also run outcome-based programs. Instead of remaining a reactive enforcer, readers will find a blueprint for becoming a proactive Enterprise Risk Leader. Navigating this shift ultimately rewards the disciplined observation required to outthink the opponent.
Do you have a question about the book? Login to be able to add your own question.


