Books, OMG, Books: Commence with Reading
Meghan Jacquot (Security Engineer · Carnegie Mellon University Software Engineering Institute)
ShmooCon XX (Final) · Day 2 · Belay It
Overview
In "Books, OMG, Books: Commence with Reading," Meghan Jacquot delivers a compelling argument for the vital role of book clubs in fostering continuous learning, community building, and personal resilience within the dynamic field of cybersecurity. Far from a mere social gathering, Jacquot demonstrates how structured reading and discussion, encompassing both technical non-fiction and thought-provoking fiction, can serve as a powerful engine for skill development, knowledge retention, and sustained professional engagement beyond the transient nature of conferences. The talk highlights the unique benefits of communal learning, where diverse perspectives converge on a shared text, deepening understanding and encouraging practical application of security concepts.

Key moments
- 0:50 Why start/join a book club? Community and learning.
- 2:05 Benefits: camaraderie, continuous learning, diverse perspectives.
- 2:55 How to run a book club: examples of different formats.
- 3:55 Practical discussion questions for book club meetings.
- 5:05 Example book lists: alternating narrative and technical.
- 5:55 Current book club reads and how to join.
- 6:10 Defcon Book Club: Fiction reads and upcoming selections.
Books, OMG, Books: Commence with Reading
Speakers: Meghan Jacquot, Security Engineer, Carnegie Mellon University
Conference: ShmooCon
YouTube: https://www.youtube.com/watch?v=5YHcw-qj094
Overview
In "Books, OMG, Books: Commence with Reading," Meghan Jacquot delivers a compelling argument for the vital role of book clubs in fostering continuous learning, community building, and personal resilience within the dynamic field of cybersecurity. Far from a mere social gathering, Jacquot demonstrates how structured reading and discussion, encompassing both technical non-fiction and thought-provoking fiction, can serve as a powerful engine for skill development, knowledge retention, and sustained professional engagement beyond the transient nature of conferences. The talk highlights the unique benefits of communal learning, where diverse perspectives converge on a shared text, deepening understanding and encouraging practical application of security concepts.
Jacquot, a security engineer with Carnegie Mellon University's Software Engineering Institute (SEI), draws upon her extensive experience running multiple book clubs to illustrate their tangible impact. She posits that in a field where knowledge quickly becomes obsolete, the discipline of reading and discussing current and foundational texts is indispensable. More profoundly, she emphasizes that these clubs extend the sense of camaraderie and shared purpose experienced at conferences, transforming individual learning into a collective endeavor that strengthens the cybersecurity community as a whole.
This presentation is particularly relevant for cybersecurity professionals at all stages of their careers, from those just starting out to seasoned veterans. It offers a practical framework for structured self-improvement, advocating for an approach that integrates both the hard skills gleaned from technical manuals and the softer skills of critical thinking, empathy, and resilience often found in narrative works. By showcasing how book clubs can tackle complex technical topics, explore historical security incidents, and even delve into the human elements of technology, Jacquot provides a roadmap for cultivating a more knowledgeable, connected, and resilient security workforce.
Background
▶ Watch: Why start/join a book club? Community and learning. (0:50)
The cybersecurity landscape is characterized by its relentless pace of change, with new threats, vulnerabilities, and defensive technologies emerging constantly. This dynamic environment places immense pressure on professionals to engage in continuous learning, often through self-study, online courses, or conference attendance. However, as Meghan Jacquot points out, conferences, while invaluable for networking and concentrated learning, are "points in time" – their sense of community and intellectual stimulation often dissipates once the event concludes. This leaves a gap in ongoing engagement and structured learning opportunities.
Furthermore, the nature of cybersecurity work can sometimes be isolating. While collaboration is common, individual research and problem-solving are also significant components, which can lead to professionals feeling disconnected from a broader support system. The challenge, then, is to bridge the gap between episodic learning events and sustained professional development, while simultaneously fostering a resilient and supportive community.
Jacquot's solution, rooted in her own successful initiatives, is the book club. She highlights that these are not merely social gatherings but intentional platforms designed to address these specific challenges. By bringing together individuals "literally on the same page" through shared reading, book clubs facilitate deeper discussions, expose participants to diverse perspectives shaped by different backgrounds and experiences, and create a sustained sense of camaraderie. The speaker runs two distinct types of clubs: one focused on fiction, particularly science fiction and cyberpunk novels, meeting largely over Discord and annually in person at DEF CON; and another dedicated to non-fiction, often pairing technical books with narrative accounts of real-world events. This dual approach underscores the belief that both technical acumen and a broader understanding of human factors, societal implications, and historical context are crucial for well-rounded security professionals. The existence of reading guides in some books further streamlines the process of generating meaningful discussion questions, reducing the organizational overhead for club leaders.
Key Findings
▶ Watch: How to run a book club: examples of different formats. (2:55)
Meghan Jacquot's talk distills the multifaceted benefits of cybersecurity book clubs into three overarching themes, each representing a core finding on how these communities enhance professional development and personal growth. These themes are not just theoretical constructs but are illustrated with concrete examples of books and their real-world application.
- Keep the Receipts: The Imperative of Digital Forensics and Incident Response (DFIR)
This theme emphasizes the critical importance of meticulous data collection, evidence preservation, and systematic investigation in the realm of cybersecurity. Jacquot explains that many non-fiction security narratives, such as Cuckoo's Egg, effectively teach principles of digital forensics and incident response (DFIR) by recounting real-world investigations. These books showcase how investigators piece together puzzles, trace adversaries, and establish irrefutable proof of events. The finding here is that by engaging with these narratives, professionals can internalize the methodologies for "keeping the receipts"—maintaining logs, preserving artifacts, and documenting every step of an incident—which is fundamental for successful breach analysis and attribution. The recurring nature of this theme across various investigative thrillers and historical accounts underscores its foundational role in cybersecurity.
- Use It or Lose It: Cultivating and Applying Technical Skills
Jacquot stresses that merely reading technical information is insufficient; practical application is paramount for true learning and skill retention. This finding highlights the necessity of setting personal learning goals and actively practicing new techniques. Technical books, particularly those that include exercises or accompanying online resources, serve as invaluable tools for this purpose. The speaker herself uses Post-it notes to flag sections in technical books that she intends to revisit and practice. This theme underscores that book clubs can provide a supportive environment for members to commit to practicing new skills, discussing challenges, and collaboratively troubleshooting. The immediate feedback and diverse viewpoints within a group can significantly accelerate the learning curve and ensure that theoretical knowledge translates into actionable capabilities.
- Building Community and Resilience: The Human Element of Cybersecurity
The final, and perhaps most profound, finding revolves around the human aspect of the cybersecurity profession. Jacquot argues that book clubs, particularly those exploring fiction, frequently delve into themes of struggle, survival, resilience, and community support in the face of adversity. Whether it's pushing back against inequities or striving for survival in challenging environments (metaphorically or literally, as in terraforming narratives), these stories resonate with the personal and professional struggles faced by security practitioners. The finding is that by engaging with these narratives, members learn to identify and leverage their support systems, sharing "sorrows and troubles" to divide their burden and magnifying "joys" through collective celebration. This fosters a strong sense of community and resilience, counteracting professional isolation and burnout, and extending the collaborative spirit of conferences into an ongoing, supportive network.
Together, these findings present a holistic view of book clubs as powerful mechanisms for continuous professional development, encompassing technical mastery, practical application, and vital community support, all of which are essential for thriving in the cybersecurity domain.
Technical Deep Dive
▶ Watch: Practical discussion questions for book club meetings. (3:55)
While Meghan Jacquot's talk is fundamentally about the methodology and benefits of book clubs, it delves into specific technical domains and learning approaches through the lens of the books discussed. The "Technical Deep Dive" section of this article focuses on how these book clubs facilitate the acquisition and application of critical security skills, particularly under the "Keep the Receipts" and "Use It or Lose It" themes.
Keep the Receipts: Digital Forensics and Incident Response Narratives
The concept of "Keep the Receipts" directly pertains to the technical discipline of Digital Forensics Incident Response (DFIR). Jacquot highlights books that, through narrative, illustrate the meticulous process of investigating security incidents. A prime example mentioned is **Clifford Stoll's *The Cuckoo's Egg***. This seminal non-fiction work, often considered one of the original DFIR books, recounts Stoll's real-life investigation into a hacker breaking into computer systems at Lawrence Berkeley National Laboratory in the late 1980s.
- Forensic Methodology: Stoll's narrative details the painstaking process of tracking an intruder across networks, analyzing system logs, preserving evidence, and correlating seemingly disparate data points to build a comprehensive picture of the attack. This includes setting up traps, monitoring network traffic, and collaborating with law enforcement across international boundaries. The book serves as a practical, albeit historical, guide to the principles of evidence collection, chain of custody, and attack attribution.
- Data Integrity and Preservation: The core message from such books is the absolute necessity of maintaining data integrity and preserving all relevant artifacts during an investigation. Any modification or loss of data can compromise the entire forensic process and hinder the ability to understand "how and why it happened."
- Tracing and Puzzle Solving: Jacquot emphasizes the "tracing back that puzzle" aspect. This refers to the technical skill of reconstructing attack timelines, identifying attacker methodologies, and understanding the scope of a breach, all of which are central to effective DFIR. Other books like Dark Wire, Tracers in the Dark, and This Is How They Tell Me the World Ends further reinforce these themes, providing modern contexts for digital investigations involving cryptocurrency, cybercrime, and nation-state activities.
By discussing these narratives, book club members gain a deeper, contextual understanding of DFIR principles, learning from real-world successes and challenges without having to experience a major incident firsthand.
Use It or Lose It: Practical Application of Technical Knowledge
This theme directly addresses the hands-on aspect of technical skill development. Jacquot advocates for actively engaging with technical material, not just passively consuming it. She illustrates this with her personal practice of using Post-it notes to flag sections in technical books for later practice or deeper exploration.
Two specific books are highlighted for their practical, actionable content:
- **Michael Bazzell's *OSINT Techniques***:
- Open Source Intelligence (OSINT): This book is a detailed guide to gathering information from publicly available sources. Jacquot notes that it is "chock full of details about how to protect your personal security" and provides step-by-step instructions.
- Personal Security and Digital Footprint: The book focuses on practical applications of OSINT for individuals, teaching them how to assess and reduce their own digital footprint. This includes techniques for finding leaked personal information, understanding online exposure, and implementing countermeasures.
- Operational Security (OPSEC): Bazzell's work extends into operational security (OPSEC) for individuals, guiding readers on how to manage their online presence, privacy settings, and data sharing to minimize risks. Jacquot mentions that he "literally walks you through step by step all these different things to do."
- Continuous Updates and Training: The book's relevance is maintained through new volumes published "every other year," indicating its dynamic nature in a constantly evolving OSINT landscape. Bazzell also conducts trainings for organizations like the Police Academy and FBI, underscoring the book's practical utility for law enforcement and intelligence professionals. His companion book, Privacy, further deepens the focus on personal data protection.
- Book Club Relevance: Discussing OSINT Techniques in a book club allows members to share findings, test methodologies, and collectively brainstorm strategies for improving personal and organizational security posture.
- **Simon Singh's *The Code Book***:
- Cryptography and Ciphers: This book explores the history of cryptography, from ancient ciphers to modern encryption. Jacquot mentions that it includes a series of "10 Cipher Challenges" which Singh presented for anyone to complete.
- Hands-on Cryptanalysis: While the challenges were solved within a year of the book's publication (and thus no longer carry prizes), they remain an excellent resource for hands-on practice in cryptanalysis and understanding cryptographic principles. Engaging with these challenges allows readers to apply theoretical knowledge of ciphers and codes in a practical problem-solving context.
- Historical Context: Beyond the technical puzzles, The Code Book provides crucial historical context for the development of secure communication, illustrating the continuous battle between code-makers and code-breakers. This context is invaluable for understanding the foundational principles that underpin modern cybersecurity.
- Collaborative Learning: In a book club setting, members can work through these cipher challenges together, sharing different approaches and insights, which enhances the learning experience and builds a deeper appreciation for cryptographic concepts.
The technical deep dive facilitated by these book clubs is not about developing new exploits but about rigorously applying existing knowledge, refining investigative skills, and mastering tools and methodologies essential for effective cybersecurity defense. The communal aspect of the book club provides accountability and diverse perspectives, transforming solitary reading into a powerful, collaborative learning experience.
Demo / Proof of Concept
▶ Watch: Current book club reads and how to join. (5:55)
Meghan Jacquot's talk did not feature a traditional live technical demonstration of an exploit, tool, or new security architecture. Instead, the "demo" or "proof of concept" presented was the model of the book club itself and the tangible evidence of its efficacy in fostering continuous learning and community.
The speaker effectively demonstrated the concept of how book clubs function as a dynamic learning environment through several key elements:
- Reading Lists and Curricula: Jacquot presented extensive reading lists from her various book clubs, showcasing a diverse range of topics from classic science fiction like The Moon is a Harsh Mistress to technical deep dives such as Cryptonomicon and OSINT Techniques. These lists, spanning several years, serve as a living "proof of concept" that a structured reading program can be sustained over time and cover a broad spectrum of relevant subjects. The thematic grouping of books (e.g., DevOps, Hardware, DFIR) further illustrated how learning objectives can be met through curated reading.
- Discussion Frameworks: The speaker shared examples of guiding questions used in her book clubs, such as "Did you like it?", "Would you recommend it?", "Did you learn something?", "Who is the audience?", and "How could it be better?". These questions demonstrate a structured approach to critical analysis and self-reflection, proving that book clubs move beyond passive reading to active engagement and deeper understanding.
- Speaker's Personal Engagement: Jacquot's personal anecdotes, like using Post-it notes to flag sections in technical books for practice ("use it or lose it"), served as a mini-demonstration of how individuals actively apply the lessons learned. Her enthusiasm and commitment to the book clubs acted as a powerful endorsement of their value.
- Call to Action and Engagement Tools: The inclusion of QR codes and physical bookmarks for her Defcon book club and other groups served as a direct "proof of concept" for audience engagement. These tools facilitated immediate participation, allowing attendees to join existing communities and experience the benefits firsthand. This practical invitation underscored that the book club model is not just theoretical but readily accessible and actively thriving.
In essence, the entire presentation served as a conceptual demonstration: a detailed explanation of how book clubs work, what they achieve, and why they are a valuable, sustainable model for professional development and community building in cybersecurity. The evidence provided through reading lists, discussion prompts, and direct invitations affirmed the viability and success of this approach.
Defensive Implications
▶ Watch: Defcon Book Club: Fiction reads and upcoming selections. (6:10)
The insights shared by Meghan Jacquot, while focused on community and learning, carry significant defensive implications for cybersecurity professionals and organizations. By embracing the book club model and the principles it promotes, defenders can enhance their capabilities across multiple critical areas:
- Continuous Learning and Skill Refreshment: The rapidly evolving threat landscape necessitates constant learning. Book clubs provide a structured and social mechanism for security teams to stay current with new techniques, historical contexts, and foundational principles. By regularly engaging with technical books (e.g., on OSINT, DFIR, cryptography), defenders ensure their knowledge base remains relevant and sharp. This proactive learning reduces the risk of being caught off guard by emerging threats or overlooking established best practices.
- Enhanced Digital Forensics and Incident Response (DFIR) Readiness: The "Keep the Receipts" theme directly impacts DFIR capabilities. Discussing narratives like The Cuckoo's Egg or modern investigative books helps teams internalize the importance of meticulous logging, evidence preservation, and systematic incident investigation. This fosters a culture where data integrity is paramount, leading to more effective post-incident analysis, quicker containment, and stronger legal defensibility. Understanding the historical context of DFIR also provides valuable lessons for adapting to novel attack vectors.
- Improved Operational Security (OPSEC) and Personal Privacy: Books like Michael Bazzell's OSINT Techniques offer actionable guidance for reducing an individual's and, by extension, an organization's digital footprint. By applying these lessons, defenders can:
- Minimize Attack Surface: Identify and mitigate publicly available information that could be leveraged by adversaries for targeting.
- Strengthen Personal Security: Implement better privacy controls and practices to protect personal data, which often has implications for professional security (e.g., preventing social engineering attacks).
- Educate End-Users: Security professionals who master these techniques are better equipped to educate their colleagues and organizational users on best practices for online privacy and security, reducing the overall human attack surface.
- Cultivating a Culture of Practice ("Use It or Lose It"): The emphasis on actively practicing learned skills is crucial. Book clubs can encourage defenders to take theoretical knowledge from technical manuals and apply it through hands-on exercises, labs, or even CTF challenges. This proactive skill development ensures that abilities like cryptanalysis, network analysis, or malware analysis remain sharp and readily deployable during an incident. It also fosters a mindset of continuous improvement and practical experimentation within security teams.
- Strengthened Community and Resilience Against Burnout: Cybersecurity is a high-stress field prone to burnout. The "Building Community and Resilience" theme is a direct defensive measure against this. A strong, supportive professional network, cultivated through book clubs, provides:
- Peer Support and Mentorship: A platform for sharing challenges, seeking advice, and mentoring less experienced members.
- Knowledge Sharing: Diverse perspectives on security problems, leading to more innovative solutions and a broader understanding of complex issues.
- Psychological Resilience: A sense of belonging and shared purpose, which is vital for maintaining morale and preventing professional isolation. A resilient team is better equipped to handle prolonged incidents and adapt to high-pressure situations.
In summary, adopting the book club ethos within cybersecurity teams can lead to more knowledgeable, skilled, and resilient defenders. It transforms passive learning into active engagement, strengthens the collective security posture, and builds a supportive community essential for navigating the complexities of modern cyber threats.
Key Takeaways
- Book clubs are a powerful, sustainable mechanism for continuous learning and community building in the dynamic field of cybersecurity, extending engagement beyond temporary conferences.
- Structured reading and discussion foster deeper understanding and diverse perspectives on both technical and socio-technical challenges, enhancing critical thinking and problem-solving skills.
- Non-fiction narratives, particularly those focused on real-world investigations, are invaluable for teaching Digital Forensics and Incident Response (DFIR) principles, emphasizing the critical importance of "keeping the receipts" through meticulous data collection and evidence preservation.
- Actively applying technical knowledge ("use it or lose it") is paramount for skill retention and development, with books like OSINT Techniques and The Code Book providing practical guides and challenges for hands-on practice in areas like Open Source Intelligence (OSINT), Operational Security (OPSEC), and cryptography.
- Engaging with both technical and fiction works strengthens personal and professional resilience, cultivating a supportive community that helps members navigate struggles, share joys, and build robust support systems against professional isolation and burnout.
- Book clubs offer a practical, low-cost method for security professionals to enhance their defensive capabilities, including improved DFIR readiness, stronger OPSEC, and a more knowledgeable, connected, and resilient workforce.
About the Speaker(s)
Meghan Jacquot is a dedicated Security Engineer affiliated with Carnegie Mellon University's Software Engineering Institute (SEI). Her professional interests extend beyond traditional security engineering, as evidenced by her passion for maturity models and resilience in cybersecurity.
Jacquot is a fervent advocate for community building and continuous learning, topics that form the core of her ShmooCon talk. She is actively involved in running multiple successful book clubs, showcasing her commitment to fostering intellectual growth and camaraderie within the security community. One of her notable initiatives is a fiction-focused, science fiction/cyberpunk book club known as the "Defcon book club," which meets regularly on Discord and hosts an annual in-person gathering at DEF CON. She also leads a non-fiction book club that pairs technical works with narrative accounts, reflecting her belief in a holistic approach to security education. Her enthusiasm for books and collaborative learning is a central aspect of her professional identity.
Reviews
Dr. Zero (Offensive Security Researcher) — STRONG ACCEPT
While not a deep technical presentation in the typical sense, this talk delivers a highly practical and well-structured framework for continuous learning and community building within the cybersecurity field. The speaker's genuine passion for fostering engagement through curated technical and narrative book clubs is evident. It provides concrete methodologies and extensive reading lists that genuinely encourage deeper, ongoing engagement with relevant security topics, making it a valuable contribution to personal and professional development in our dynamic domain.
Heather Calloway (CISO) — STRONG ACCEPT
Meghan Jacquot delivers a highly relevant and actionable talk on the strategic value of book clubs for continuous learning, community building, and resilience in cybersecurity. She provides a clear model for how structured reading and discussion, encompassing both technical and narrative works, directly enhances critical skills like DFIR, OSINT, and OPSEC, while simultaneously fostering a supportive environment that combats professional isolation and burnout. This approach offers a pragmatic, low-cost method for CISOs and security leaders to build more knowledgeable, skilled, and resilient teams, directly impacting the operational effectiveness and sustainability of security programs.