
A cybersecurity story can move from a technical issue to a reputational crisis in a matter of hours. For founders, marketing and communications leaders, knowing who covers the cybersecurity market before that moment arrives isn’t optional. It’s the difference between shaping the narrative and reacting.
For most cybersecurity companies, growth ultimately depends on trust. Security isn’t just a technical problem; it’s a trust problem: customers, partners, and regulators need to believe you can protect what matters before they’ll do business with you at all. The reporters on this list don’t just cover breaches and vulnerabilities. Their coverage shapes whether the market sees a company as credible or exposed.
We’ve put together a curated list (in no particular order) featuring top U.S.-based reporters shaping how the industry talks about cyber policy, enterprise breaches, privacy, cybercrime, national security, artificial intelligence, and vulnerability management.
1. Eric Geller, Cybersecurity Dive
Operating out of Washington, D.C., senior reporter Geller focuses on government reactions to new technologies, federal cybersecurity policy, and the safeguarding of critical infrastructure. His reporting is highly valuable for decision-makers in public-sector tech, healthcare security, infrastructure, and regulated industries. He stands out for his skill in converting intricate federal policies into actionable insights for executives, making his reporting vital to read prior to meeting with regulators.
Serving as the security editor, New York-based Whittaker tracks data breaches, cybercrime, privacy, and the various security challenges facing tech firms. For leaders of startups and scaleups, his articles offer a pragmatic perspective on how a technical mishap can evolve into corporate, legal, and public relations challenges. He possesses a unique ability to swiftly and lucidly bridge the gap between technical details and corporate outcomes, frequently delivering the initial clarity on a breach’s true significance ahead of the broader industry.
Satter, a Reuters journalist based in D.C., reports on digital espionage, surveillance, disinformation, and cybersecurity. He links technical cybersecurity incidents to broader national security issues and global politics. For executives facing complex government oversight or nation-state threats, his insights are vital. He regularly demonstrates how weaknesses in infrastructure can swiftly transform into international diplomatic emergencies. Ultimately, his reporting reminds global enterprises that protecting client trust and satisfying state regulators are interconnected imperatives.
4. Lily Hay Newman, WIRED
Newman, a New York-based senior writer, specializes in digital privacy, information security, and hacking. Her reporting highlights emerging attack surfaces and the human impact of security failures, making her coverage highly relevant for businesses focused on AI security, privacy, threat intelligence, and software infrastructure. Newman’s work stands out for bringing a human angle to deeply technical subjects, constantly reminding readers that vulnerabilities pose real risks to real people—the precise framing needed to build public trust in how companies communicate about security.
Based in San Francisco, Goodin reports on hardware hacking, passwords, encryption, botnets, computer espionage, and malware. His coverage stands out for its exceptional rigor, as few journalists require as much technical proof before publishing a story. Consequently, his work serves as an excellent benchmark to evaluate whether your company’s security assertions and media pitches can truly survive intense scrutiny. For founders and practitioners who want to grasp the inner mechanics of an attack rather than just the final outcome, his deeply detailed reporting provides vital insights and highlights the exact depth of evidence necessary for a technical pitch.
6. Sam Sabin, Axios
Sabin, operating out of the San Francisco Bay Area, tracks the intersections of business and policy within the cybersecurity sector for Axios. Her reporting encompasses emerging market trends, software vulnerabilities, governmental strategies, and artificial intelligence, offering critical perspectives for executives navigating cyber regulations, secure development, and AI governance. Rather than focusing solely on technical components, she contextualizes cybersecurity through market dynamics and regulatory frameworks, allowing leaders to better anticipate how evolving governance affects competitive positioning.
Operating out of Naperville, Illinois, veteran technology journalist Vijayan offers more than 25 years of experience in cybersecurity reporting. He focuses on cloud security, identity security, ransomware, nation-state risks, critical infrastructure, software supply chain vulnerabilities, and the broader security challenges linked to AI. Vijayan provides immense value to readers through his profound institutional knowledge; he possesses a rare capacity to frame current security incidents within two decades of historical context. This comprehensive perspective makes his coverage essential for security executives looking to grasp both immediate events and their structural importance.
8. James Rundle, The Wall Street Journal
Rundle is a New York-based journalist who covers privacy, national cyber policy, and the cybersecurity industry for The Wall Street Journal. By connecting technical shifts with strategic priorities like corporate risk, artificial intelligence, regulation, and cyber investment, his reporting provides an enterprise-focused look at how security decisions impact the C-suite. Rundle stands out by treating cybersecurity as a boardroom and financial issue rather than just a technical one, making his work a key indicator of how the market values and trusts a security program.
Operating out of Washington, D.C., Starks is a senior reporter for CyberScoop dedicated to covering the cybersecurity landscape. His extensive coverage delves into digital crime, public policy, law enforcement, and government affairs. This specialized lens delivers significant value to enterprises navigating highly regulated markets or pursuing public sector accounts. What distinguishes Starks’ journalism is his deep network within law enforcement and government agencies, providing a level of policy nuance that remains unmatched across the industry.
10. Sean Lyngaas, CNN
Based in the Washington area, Lyngaas reports on cybersecurity for CNN, covering significant cyberattacks, ransomware, digital espionage, infrastructure threats, and government responses. He possesses a strong instinct for scale, reliably identifying which incidents will transition from trade publications into mainstream national news. Following his coverage provides valuable intelligence for communications teams aiming to anticipate which developments will have a major public impact.
Three Cybersecurity Newsletters to Follow
Newsletters have moved from the margins of media strategy to the center of it. They give journalists and industry experts room to investigate complex stories, analyze technical developments, and speak directly to niche, high-value audiences. For cybersecurity leaders, that makes them an early-warning system: important conversations often surface here well before they reach mainstream business media.
1. Zero Day by Kim Zetter
In her newsletter, Zero Day, independent investigative journalist Kim Zetter reports on critical infrastructure, vulnerabilities, election security, surveillance, nation-state espionage, and cyberattacks. What renders her newsletter indispensable is her remarkable background: over the past two decades, Zetter has uncovered some of the most impactful cybersecurity stories, which directly enriches her independent reporting.
With a focus on topics like ransomware, cybercrime, security policy, vulnerabilities, nation-state operations, and modern tech risks, Risky Business delivers multiple newsletters tailored for security experts, such as the analytical Seriously Risky Business and the news-centric Risky Bulletin. Its core advantage lies in its expert perspective: because the reporting is produced by and for security practitioners, it bypasses basic summaries to deliver immediate, practical value to defenders and leadership teams alike.
3. Return on Security by Mike Privette
Return on Security tracks the cybersecurity sector through a distinctive commercial lens, analyzing mergers and acquisitions, venture funding, market categories, AI security, and sector strategy. Its unique value lies in this business-centric approach: it stands out as one of the rare resources monitoring cybersecurity via market dynamics and capital flows, offering crucial insights for anyone tracking industry direction and investor confidence.
Follow First, Pitch Second
Follow each reporter and newsletter closely, map their specific interests, engage on LinkedIn, and initiate outreach only when your company can offer timely evidence, original research, a differentiated perspective, or access to a credible expert.
At Kite Hill, we help cybersecurity and B2B technology companies turn complex expertise into clear, compelling narratives. From proactive thought leadership to rapid-response media strategy, we build integrated communications programs that strengthen executive visibility, establish credibility, and build the trust companies need to scale with customers, partners, and regulators.
Ready to sharpen your cybersecurity story and reach the audiences that matter? Let’s connect.
– Olivia Ly, Senior Account Executive
