Top 50 Cybersecurity Journalists Every PR Pro Should Know
Author

Date Published

Cybersecurity is one of the fastest-moving, highest-stakes beats in all of journalism. A single data breach can wipe billions off a company's market cap overnight, a ransomware attack can cripple national infrastructure, and zero-day vulnerabilities have a way of turning quiet Fridays into all-hands emergencies. The reporters who cover this world are sharp, technically fluent, deeply sourced, and famously skeptical of spin. For any PR professional trying to earn coverage in the cybersecurity space — whether for a threat intelligence platform, a security software startup, or an enterprise cybersecurity brand — knowing who these journalists are is the non-negotiable first step.
This guide compiles the top 50 cybersecurity journalists you need on your media radar, organized by outlet tier and coverage focus. Beyond the list itself, you'll find practical guidance on how to approach these reporters with pitches that actually get read, and how to build the kind of long-term media relationships that generate consistent, credible coverage for your clients. Whether you're new to tech PR or a seasoned media relations specialist, bookmark this page — it's the cybersecurity media map you'll come back to again and again.
Why Cybersecurity Journalists Matter for PR
Cybersecurity coverage carries enormous weight. A feature in Wired, The Record, or Dark Reading doesn't just drive website traffic — it signals to investors, enterprise buyers, regulators, and partners that a company is a serious, credible player. For B2B cybersecurity brands especially, earned media placements in the right publications often do more for pipeline generation than any paid campaign. That's because the people making security procurement decisions — CISOs, IT directors, risk officers — are active readers of exactly these outlets.
But the cybersecurity media landscape is also uniquely demanding. These journalists are inundated with vendor pitches, alert to marketing language masquerading as news, and deeply committed to protecting their sources and their credibility. Getting your story in front of the right reporter, framed in the right way, requires both a strong media list and a smart outreach strategy. That's precisely where knowing these 50 names gives you a competitive edge.
How to Use This Media List Effectively
A media list is only as valuable as the strategy behind it. Before you start sending pitches, spend time reading each journalist's recent work. Note which topics they've been gravitating toward, what angles they prefer, and how they typically frame vendor stories versus pure news. Cybersecurity reporters tend to specialize further within their beat — some focus on nation-state threats and geopolitics, others on consumer privacy, ransomware groups, enterprise vulnerabilities, or regulatory policy.
Organize this list in a living CRM or media database, tagging each journalist by beat focus, outlet tier, and engagement history. When a news hook emerges, you'll be able to move quickly, targeting exactly the right reporters rather than blasting a generic pitch to everyone. Speed and specificity are your two greatest assets in cybersecurity PR.
The Top 50 Cybersecurity Journalists
We've organized this list into three tiers based on outlet reach and editorial influence. Tier 1 covers nationally and globally syndicated publications with massive readership. Tier 2 focuses on specialist trade publications that carry deep authority with technical buyers and security professionals. Tier 3 highlights newsletter writers, podcast hosts, and emerging voices who are building highly engaged, niche audiences that are increasingly influential in the security community.
Tier 1: Nationally Syndicated & High-Authority Outlets
These journalists write for publications with broad mainstream reach alongside deep technical credibility. A placement here can shape public narratives, attract investor attention, and put a brand on the map for audiences well beyond the security community.
- Kim Zetter – Independent / Wired contributor. One of the most respected names in cybersecurity journalism, known for authoritative long-form investigations on cyberwarfare and critical infrastructure threats. Author of Countdown to Zero Day.
- Lorenzo Franceschi-Bicchierai – TechCrunch. Focuses on hackers, data breaches, and surveillance. Consistently breaks original stories with deep sourcing in the security research community.
- Joseph Cox – 404 Media (co-founder). Previously at Motherboard/VICE. A leading voice on privacy, surveillance, data brokers, and hacking. Known for groundbreaking investigations.
- Zack Whittaker – TechCrunch (Security Editor). Covers data breaches, vulnerabilities, and security policy. One of the most prolific and widely read security reporters in the US tech press.
- Brian Krebs – KrebsOnSecurity (independent). Arguably the most influential cybercrime journalist alive. His deep-dive investigations on fraud rings, breaches, and cybercriminal ecosystems set the agenda for the entire beat.
- Lily Hay Newman – Wired. Covers security, privacy, and surveillance with a sharp focus on consumer-facing threats and policy implications. Excellent for stories that bridge technical depth with public impact.
- Andy Greenberg – Wired. Senior writer covering cybersecurity, hacking, and geopolitics. Author of Sandworm and Tracers in the Dark. A must-know for nation-state and espionage-adjacent stories.
- Matt Burgess – Wired UK. UK-based security and privacy correspondent. Strong focus on surveillance, spyware, and European policy.
- Catalin Cimpanu – Recorded Future News (The Record). Prolific reporter covering malware, vulnerabilities, and cybercriminal operations. Formerly at ZDNet and Bleeping Computer.
- Kevin Collier – NBC News. Covers cybersecurity for one of the largest broadcast news organizations in the US, making him a key contact for mainstream-audience security stories.
- Raphael Satter – Reuters. Investigative reporter focused on espionage, hacking, and disinformation. Reuters' global reach makes placements here exceptionally high-value.
- Frank Bajak – Associated Press. AP's cybersecurity and technology reporter. AP stories syndicate to thousands of outlets worldwide.
- Byron Tau – The Wall Street Journal. National security and surveillance reporter. Key contact for government, defense, and enterprise security angles.
- Robert McMillan – The Wall Street Journal. Technology and security reporter with particular focus on corporate breaches and enterprise risk.
- David Sanger – The New York Times. National security correspondent covering cyberwarfare, government hacking operations, and geopolitical cyber conflict at the highest editorial level.
- Nicole Perlroth – Former New York Times cybersecurity reporter, now author and advisor. Author of This Is How They Tell Me the World Ends. Though no longer daily reporting, her influence on the beat remains significant.
- Caitlin Durkovich / Maggie Miller – Politico. Politico's security and cyber policy desk is essential for regulatory, legislative, and government-focused cybersecurity stories.
- Tim Starks – The Washington Post. Covers cybersecurity policy and government cyber operations. Previously at Politico; now one of the key Post voices on the beat.
- Ellen Nakashima – The Washington Post. Veteran national security reporter covering cyberwarfare, intelligence, and government surveillance. Deep sourcing inside the US government.
- Shannon Vavra – The Record. Former Cyberscoop reporter covering threat intelligence and nation-state operations.
Tier 2: Trade & Specialist Security Publications
These outlets are required reading for CISOs, security analysts, and IT decision-makers. Coverage here signals deep technical legitimacy and reaches buyers directly. For cybersecurity brands, these placements often drive more qualified inbound than any mainstream feature.
- Kevin Townsend – SecurityWeek. Prolific contributor covering enterprise security, vulnerabilities, and security research. A reliable, high-volume contact for news-driven stories.
- Ionut Arghire – SecurityWeek. Covers malware, data breaches, and threat intelligence. Strong technical focus with fast turnaround on breaking news.
- Lindsey O'Donnell-Welch – Decipher (Duo Security). Former Threatpost editor. Covers enterprise security, vulnerabilities, and the security community with strong editorial standards.
- Dark Reading Editorial Team (including Kelly Jackson Higgins, Executive Editor) – Dark Reading. One of the most widely read enterprise security trade publications. Kelly has been shaping the security editorial agenda for over a decade.
- Bill Brenner – CSO Online. Focuses on CISO perspectives, security operations, and enterprise risk. Essential contact for leadership-focused security narratives.
- Steve Zurier – SC Media. Covers the full spectrum of enterprise security, from compliance to cloud security to threat detection.
- Jai Vijayan – Dark Reading. Covers cybersecurity threats, vulnerabilities, and security research with a technical depth that resonates with practitioner audiences.
- Eduard Kovacs – SecurityWeek. One of the site's most prolific reporters, covering ICS/SCADA security, vulnerabilities, and threat actor activity.
- Pierluigi Paganini – Security Affairs (founder) and contributor to Infosecurity Magazine. Widely read across the European security community and beyond.
- Phil Muncaster – Infosecurity Magazine. UK-based reporter covering the full breadth of enterprise and consumer security. Strong reach into European CISO audiences.
- Alex Scroxton – Computer Weekly (UK). Security and cloud reporter with deep reach into UK enterprise IT decision-makers.
- Danny Palmer – ZDNet. Covers cybersecurity with a focus on ransomware, phishing, and enterprise threats. Widely read by IT professionals globally.
- Charlie Osborne – ZDNet. Security and privacy journalist with particular focus on data breaches and financial cybercrime.
- Tonya Riley – CyberScoop. Covers cybersecurity policy, government cyber programs, and the intersection of technology and national security.
- Christian Vasquez – CyberScoop. Focuses on critical infrastructure security, OT/ICS threats, and federal cybersecurity policy.
- Jonathan Greig – The Record. Covers ransomware attacks, cybercriminal groups, and incident response. Fast, accurate, and deeply read by security practitioners.
- Suzanne Smalley – The Record. Covers US government cyber policy, CISA, and the regulatory landscape. Key contact for compliance and policy stories.
- AJ Vicens – CyberScoop / Recorded Future News. Covers threat intelligence and state-sponsored hacking operations.
- Sean Lyngaas – CNN (formerly CyberScoop). One of the most prominent cybersecurity reporters to make the leap to a major broadcast news organization. Invaluable for mainstream-audience security stories.
- James Coker – Infosecurity Magazine. Regular contributor covering enterprise security news, threat reports, and industry research findings.
Tier 3: Newsletters, Podcasts & Emerging Voices
The most influential security conversations today don't always happen in traditional publications. These writers, podcasters, and independent voices command fiercely loyal audiences of practitioners, researchers, and decision-makers. Their reach may be smaller in raw numbers but their influence per reader is often higher than any mass-market outlet.
- Risky Biz (Patrick Gray) – Host of the Risky Business podcast, one of the most listened-to shows in the security community. Guest spots here carry significant credibility among practitioners.
- Adam Janofsky – The Record / ISMG. Covers cybersecurity business, funding, and the security industry itself — valuable for company announcements and market analysis stories.
- Carly Page – TechCrunch. Rising voice in cybersecurity journalism covering data breaches, ransomware, and vulnerability disclosures with strong investigative instincts.
- Recorded Future Analyst Team (Insikt Group) – While primarily analysts rather than journalists, their published threat intelligence reports are widely cited by reporters and shape media narratives. Building relationships here can drive significant secondary coverage.
- Krebs on Security Newsletter subscribers / Graham Cluley – Independent blogger and podcaster. Graham's newsletter and Smashing Security podcast have a devoted following among security professionals who trust his balanced, accessible take on news.
- Corin Faife – The Verge. Covers privacy, surveillance, and the policy dimensions of security with a sharp eye for consumer impact stories.
- Axios Codebook Team (including Sam Sabin) – Axios. The Codebook newsletter delivers concise, smart cybersecurity briefings to a senior policy and business audience. Placement here reaches decision-makers who are time-constrained but highly influential.
- Thomas Brewster – Forbes. Investigations reporter covering surveillance, privacy, and law enforcement use of technology. Known for high-impact exclusives that generate significant pickup.
- Naomi Nix – The Washington Post. Covers tech policy, platform regulation, and cybersecurity with a focus on societal and political impact.
- Chris Bing – Reuters. Cybersecurity and intelligence reporter covering nation-state hacking, ransomware, and US national security cyber policy.
How to Pitch Cybersecurity Journalists (Without Getting Ignored)
Knowing the names is the foundation. Knowing how to approach them is what separates a successful cybersecurity PR strategy from an expensive exercise in email delivery. Security reporters are among the most pitch-fatigued journalists in any beat, partly because every vendor in the industry wants their attention and partly because they can smell a superficial story from a hundred yards away.
The most effective pitches in this space share a few common characteristics. They lead with data, not adjectives. If your client has conducted original research — proprietary threat data, breach statistics, survey findings from security practitioners — that is genuinely newsworthy. Generic commentary on trends that everyone already knows is not. Reporters covering this beat want access to primary sources, exclusive data, and expert voices who can say something specific and technically grounded, not boilerplate quotes about the "evolving threat landscape."
Timing is also critical. Cybersecurity reporters move fast on breaking news, and if your client has a relevant perspective on an active incident — a major breach, a newly disclosed vulnerability, a regulatory announcement — your window for reactive commentary is often less than 24 hours. Having pre-approved messaging and pre-built relationships with reporters makes that speed possible. Trying to build those relationships in the middle of a news cycle is a losing strategy.
Finally, respect the beat's culture around responsible disclosure. If your pitch involves vulnerabilities or threat intelligence, know the norms around coordinated disclosure and make sure your client does too. Nothing damages a PR relationship with a security reporter faster than pushing them to publish something irresponsibly or before defensive measures are in place.
Building Long-Term Relationships with Security Reporters
The cybersecurity media community is smaller and more interconnected than it might appear. Reporters talk to each other, follow each other's work, and share notes on which PR contacts are worth their time. That means your reputation in this space compounds — positively and negatively — faster than in almost any other vertical.
The PR professionals who build the strongest relationships with security journalists do so by operating as genuine resources rather than pitch machines. That means sending a reporter a tip on a story that has nothing to do with your clients because it's genuinely interesting and you know they'll care about it. It means connecting them with a credible expert source even when there's no client angle. It means being transparent about what your clients can and can't speak to, rather than overpromising and underdelivering.
Industry events like DEF CON, Black Hat, RSA Conference, and the various regional BSides events are invaluable for in-person relationship building. These gatherings concentrate the security journalism community in a single place, and a genuine conversation over coffee at DEF CON is worth more than six months of cold email outreach. If your clients are speaking, exhibiting, or releasing research at these events, treat them as relationship-building platforms first and media opportunity platforms second.
For brands operating in adjacent tech sectors — fintech platforms with security implications, AI companies navigating privacy regulations, or crypto projects dealing with smart contract vulnerabilities — cybersecurity media relations intersects heavily with sector-specific PR. SlicedBrand's work across fintech PR, crypto PR, and AI PR regularly intersects with cybersecurity coverage, because security is no longer a standalone category — it is woven into every major technology story of the moment. The same applies to greentech and legaltech brands, where data protection, regulatory compliance, and cyber risk are increasingly central narratives.
Final Thoughts
Cybersecurity is one of the most competitive and consequential beats in technology journalism. The reporters on this list are smart, well-sourced, and deeply protective of their credibility — which is exactly what makes earning their coverage so valuable. A placement with Brian Krebs, Andy Greenberg, or the team at Dark Reading doesn't just generate clicks; it generates trust, and trust is the scarcest commodity in the cybersecurity market.
Building the relationships and the story infrastructure to earn that coverage takes time, expertise, and a genuine understanding of how the security media ecosystem works. For cybersecurity brands looking to accelerate that journey, having an experienced tech PR partner who already knows these reporters and understands the nuances of security storytelling makes an enormous difference. The right pitch, to the right journalist, at the right moment is the difference between a missed opportunity and a story that defines your brand for years.
Ready to Get Your Cybersecurity Brand in the Right Headlines?
SlicedBrand is an award-winning global tech PR agency with the media connections and strategic storytelling expertise to earn you coverage that counts. Let's build your cybersecurity media strategy together.
Talk to a PR ExpertAbout the Author

Slicedbrand Team
SlicedBrand is led by an award-winning team. We are responsible for some of the world’s most successful PR campaigns and continuously secure top-tier coverage across all verticals, from the leading business publications to tech powerhouses, to drive increased brand awareness.
More in Cybersecurity PR

Cybersecurity Industry Overview: The State of Security PR

Application Security PR: How AppSec Platforms Win With the Right Communication Strategy

API Security PR: The Complete Guide to API Protection Communication

Passwordless PR: How to Communicate Passwordless Authentication to the Market

Multi-Factor Authentication PR: How MFA Platforms Win Trust and Market Share

Identity Management PR: How IAM Platforms Win Trust, Coverage, and Market Share