ZenGRC

69 Information Security Blogs You Should Be Reading

The article presents a curated list of 69 essential information security blogs, highlighting notable examples such as Cloudwards, Information Security Buzz, Inside Cybersecurity, and The Security Ledger, which offer professionals up-to-date news, expert analysis, technical advice, and aggregated content to help them stay informed in the rapidly evolving cybersecurity field.

Information security blogs provide industry professionals with up-to-date information to help them stay knowledgeable in a rapidly evolving field. With the abundance of information available, it can be challenging to separate valuable insights from less reliable sources. The following is a curated list of some of the most informative, interesting, and unique information security blogs to help keep professionals informed.

News and News Aggregator Information Security Blogs

  • Cloudwards: Focuses on cloud sharing, privacy, and information security concerns. Offers reviews, comparisons, articles, and "Top 5" lists to help users find the best cloud storage, web hosting, and VPN services.

  • Information Security Buzz: An aggregator that brings together various areas of the information security community. Features original content from contributors, including vendor announcements, industry research, forecasts, and technical advice.

  • Inside Cybersecurity: Provides in-depth articles about the latest news and trends in cybersecurity. Some content is behind a paywall, but a free trial is available.

  • Last Watch Dog: Created by Pulitzer-winning journalist Byron Acohido, this webzine delivers analysis, news videos, and guest essays on global cybersecurity topics.

  • Michael Kaiser on HuffPo: Michael Kaiser, Executive Director of the National Cyber Security Alliance, writes about cybersecurity and information security from a societal perspective.

  • SC Magazine: Offers in-depth, unbiased business and technical information for cybersecurity professionals, with both US and UK perspectives.

  • Security Bloggers Network: Aggregates content from over 300 security blogs into a single feed, with plans for more focused sub-categories.

  • The Security Ledger: Functions more like an online newspaper, providing up-to-the-minute news on security-related topics, including IoT, threats, thought leadership, podcasts, and white papers.

  • Tech Wreck InfoSec Blog: Aggregates posts from lesser-known sources, highlighting newly released security updates and interesting information.

  • Wired’s Threat Level: Wired magazine's dedicated security news page, updated daily with topics ranging from political aspects of information security to app security issues.

Industry Must-Read Information Security Blogs

  • WISP Blog: The official blog of Women in Security and Privacy, offering a female perspective on working in the security industry.

  • Dark Reading: Challenges readers to think critically about security, providing strong viewpoints, reporting, and hands-on experience from seasoned professionals.

  • Graham Cluley: One of the original information security professionals, Cluley shares insights from his extensive experience in the industry.

  • IT Security Guru: A community-driven blog featuring daily news, product reviews, white papers, and guest posts from weekly gurus.

  • Kevin Townsend’s IT Security: Offers a UK perspective with analysis and opinion pieces backed by facts from a small group of independent writers.

  • Krebs on Security: Brian Krebs, a self-made security expert, discusses security issues in an accessible yet technical manner.

  • Schneier on Security: Bruce Schneier's long-standing blog covers a wide range of security topics, including algorithms and white papers.

  • Security Through Education: Focuses on the human side of information security, emphasizing the importance of education and social engineering awareness.

  • TaoSecurity: Richard Bejtlich's blog promotes network security monitoring and offers insights into digital threat detection and response.

  • Security Weekly: A multimedia site providing videos, podcasts, and articles for the security community, recognized for its award-winning podcast.

  • ThreatPost: A spinoff of Kaspersky Labs, this blog covers consumer hacking concerns, black hat hacking, IoT, and cryptography news.

Corporate Information Security Blogs

  • Avast Blog: Features short, easily digestible posts on security topics, ideal for busy professionals.

  • BH Consulting IT Security Watch: Focuses on issues facing CISOs and CIOs, with an emphasis on European markets and topics like risk assessment and cloud forensics.

  • Cisco Security Blog: Covers a wide range of topics from enterprise networks to healthcare privacy, reflecting the perspectives of an industry leader.

  • Cloudbric: Provides consumer-focused updates on security issues, making it a useful resource for sharing information with employees.

  • eLearn Security: Shares updates on webinars, games, trivia, and other engaging security content.

  • Google Security Blog: Offers updates on security trends and addresses consumer concerns related to Google products and devices.

  • Horne Cyber Executive Insights & Horne Cyber Attack Surface: These two blogs cater to different audiences, with Executive Insights focusing on audit and C-suite topics, and Attack Surface delving into technical issues like ransomware.

  • Lohrmann on Cybersecurity & Infrastructure: Examines cybersecurity from a regulatory perspective, also covering cloud computing and mobile devices.

  • Sophos Naked Security: An award-winning blog offering news and opinion pieces, recognized for its comprehensive coverage since 2010.

  • Tripwire’s The State of Security: Features news, trends, and insights across the information security landscape, appealing to a broad audience.

  • The Veracode Blog: While product-focused, it also provides valuable information on application security and related issues.

  • Proofpoint Security Blog: Highlights Proofpoint's unique approach to combating phishing through education and filtering, with articles supporting its multi-tiered strategy.

Consultant and Consultant Firm Information Security Blogs

  • Cyber.uk: Dr. Jessica Barker's blog covers topics from cybercrime to regulatory impact, focusing on sociological aspects of cybersecurity.

  • …And You Will Know Us by the Trail of Bits: The consulting firm's blog updates readers on new developments, tools, and insights in the security environment.

  • Corero: Specializes in DDoS issues, covering topics relevant to gaming, finance, and enterprise sectors.

  • CyberArk: Offers clear, professional information on audit, compliance, security, and risk management.

  • Dr. Eric Cole: A repository of writings from a recognized expert, providing unique insights into infosecurity trends.

  • Flyingpenguin: A consulting firm with a diverse team, offering a unique and informal perspective on information security.

  • Lenny Zeltser on Information Security: Discusses the intersection of business and security, with topics ranging from IT trends to technical malware advice.

  • NoticeBored: Written by Gary Hinson, this blog makes information security engaging and fun, with a conversational tone.

  • PerezBox: Tony Perez's blog focuses on website security, business operations, and personal reflections, organized by topic.

  • Privacy Ref: Advises on creating a culture of privacy, emphasizing people skills and social engineering over software solutions.

  • Private WiFi: Offers consumer-focused advice on protecting personal information, with content categorized by how-to guides, news, and features.