What do you think?


Security Chaos Engineering: Sustaining Resilience in Software and Systems
Cybersecurity is broken. Year after year, attackers remain unchallenged and undeterred, while engineering teams feel pressure to design, build, and operate "secure" systems. Failure can't be prevented, mental models of systems are incomplete, and our digital world constantly evolves. How can we verify that our systems behave the way we expect? What can we do to improve our systems' resilience? In this comprehensive guide, authors Kelly Shortridge and Aaron Rinehart help you navigate the challenges of sustaining resilience in complex software systems by using the principles and practices of security chaos engineering. By preparing for adverse events, you can ensure they don't disrupt your ability to innovate, move quickly, and achieve your engineering and business goals.
428 pages, Paperback
Published May 9, 2023
Ratings & Reviews
Friends & Following
Create a free account to discover what your friends think of this book!
Community Reviews
Displaying 1 - 4 of 4 reviews
September 17, 2026
It was interesting for me to be familiar with Security Chaos Engineering (SCE). Authors give me new insight about security. Instead of seeking to stop failure from ever occurring, the goal in resilience and chaos engineering is to handle failure gracefully. It means that security is not a solid work but it is a continuous and live concept.
“Security Chaos Engineering (SCE) is a sociotechnical transformation that drives value to organizations through an ability to respond to failure and adapt to evolving conditions with speed and grace.”
Throughout this book, you will learn philosophies, practices, and principles that will help you achieve outcome-driven security and transform toward resilience. By the end of the book, you will understand how to sustain resilience in your software and systems so your organization can thrive despite the presence of attackers. You will learn how to adapt to adversity and maintain continuous change as the world evolves around you and your systems. You’ll discover that security can escape the dark ages and enter the enlightenment era by embracing empiricism and experimentation.
Who Should Read This Book?
If your responsibility is to design, develop, build, deploy, deliver, operate, recover, manage, protect, or secure systems that include software, then this book is for you. This book is for humans involved in software and systems engineering across titles and focal areas.
“Security Chaos Engineering (SCE) is a sociotechnical transformation that drives value to organizations through an ability to respond to failure and adapt to evolving conditions with speed and grace.”
Throughout this book, you will learn philosophies, practices, and principles that will help you achieve outcome-driven security and transform toward resilience. By the end of the book, you will understand how to sustain resilience in your software and systems so your organization can thrive despite the presence of attackers. You will learn how to adapt to adversity and maintain continuous change as the world evolves around you and your systems. You’ll discover that security can escape the dark ages and enter the enlightenment era by embracing empiricism and experimentation.
Who Should Read This Book?
If your responsibility is to design, develop, build, deploy, deliver, operate, recover, manage, protect, or secure systems that include software, then this book is for you. This book is for humans involved in software and systems engineering across titles and focal areas.
September 1, 2023
Excellent guide for software engineers to design and build realistic resilient systems. Shortridge and Rinehart engrain security as subset of software quality with many sample chaos experiments and opportunities to rethink and revise practitioner mental models -even a modularity model from park and recreation services. The beginning quote from Faust tells you how deep chaos engineering goes. Loved it!
October 30, 2024
An excellent book that challenges traditional views on implementing secure IT systems. The author aims to shift the discussion from security to resilience, bringing a new perspective to software design and implementation. The focus is especially on application design, development, and testing. Recommended reading for cybersecurity professionals and those interested in the topic.
September 17, 2025
Interesting book. I think any security professional should read this book. I'm personally tired of compliance-based security that just focuses on policies, written procedures and checklists; this book provides an excellent framework to build security instead to just tell our teams what to do.
Displaying 1 - 4 of 4 reviews





