If you want to find out what’s happening in the world, you probably turn to your favorite news outlet. Maybe it’s your local paper or something more widely circulated, like the Washington Post or the New York Times. But if you want to find out what is happening on a day-to-day basis with cybersecurity governance and policy, you’ll need to have a stash of bookmarked blogs at the ready.
The experts behind the 22 blogs listed below break news, offer detailed commentary, and summarize important security details. The granular-level analyses these IT security blogs provide give a great amount of context and detail you can’t find in the mainstream press.
1. Andrew Hay Blog
Andrew Hay is a former research director at OpenDNS, and he has an extensive background in cybersecurity. His blog, which dates back to July 2006, is updated consistently with news and happenings in the security community.
2. InformationWeek’s Dark Reading
With a tag line that states “Connecting the information security community,” you know Dark Reading is worth the bookmark. Catch up on the latest breaches and hacks, cloud security updates, authentication and privacy happenings, and much more.
3. Data Breach
Data Breach writes loads of articles around risk management, compliance, fraud, and information security. (They published 46 articles in November alone!)
4. F-Secure News from the Lab
This blog was started over 11 years ago to “monitor the Mydoom worm's DDoS attack on sco.com.” They recently moved websites, but continue to blog regularly about malware and security concerns.
5. Fortinet Security Blog
Fortinet, a network security company, has a great (and regularly updated) blog. We suggest you take a look at their top 5 threat predictions for 2016.
6. Hacker News
Hacker News is a “daily news source for IT professionals, webmasters and bloggers.” It focuses on cybersecurity news from the “best IT sources around the world.”
7. Krebs on Security
Brian Krebs is a former investigative journalist who breaks news on all of the major breaches. He explains breaches in layman's terms and does a great job of researching how the attackers get in. (By the way, this is one of my personal favorites!)
8. Naked Security Blog
Sophos, a security hardware and software company, hosts the Naked security blog. It is a “threat newsroom” that covers security news, opinion pieces, advice, and research.
9. Paul's Security Weekly
Paul's Security Weekly is a live web show (on Thursdays at 6 p.m. EST) that details the “latest information security news, research, hacker techniques, vulnerabilities, and technical how-tos.”
10. Politico Morning Cybersecurity
Politico Morning Cybersecurity is a daily summary of news surrounding the cybersecurity industry. It specializes in cybersecurity legislation, government cybersecurity, the latest cybersecurity research and reports, and quick bytes of security news.
11. Project Zero
This blog consists of updates from Google's dedicated “zero-day team” of security analysts, who focus on finding undisclosed vulnerabilities.
12. SANS AppSec Blog with Frank Kim
The SANS Institute is a well-known IT security and training firm, of which Frank Kim is the chief information security officer. His blog covers secure software development lifecycles (SDLC), vulnerabilities, and more.