Cybersecurity publishing splits into four tiers, and where you can land a byline depends on which one you aim at, not on the length of your outreach list.

The independent news sites and infosec magazines take contributed analysis and research. The analyst and community outlets take practitioner pieces. The vendor and research blogs are placement targets for original research or expert commentary, not open guest posts. The list of 100 is below, grouped roughly by tier.

Pick your tier first

TierExamplesHow you get in
Independent security newsKrebs on Security, The Hacker News, BleepingComputer, The Record, CyberScoop, The RegisterMostly staff-written. Contributed analysis, exclusive research, or a source-backed story a reporter cannot get elsewhere
Infosec magazines & analystDark Reading, SC World, CSO Online, Infosecurity Magazine, Help Net Security, SANSFreelance and contributor pitches; incident breakdowns, threat analysis, industry-trend pieces from named practitioners
Vendor & research blogsTalos, Unit 42, CrowdStrike, Sophos, Trend Micro, Rapid7, Red CanaryNot guest posts. Co-authored research, an interview, or expert quotes for a piece they are already writing
Community & smaller outletsSecurity Boulevard, GBHackers, Latest Hacking News, Darknet, IT Security Guru, teissOpen to contributions; how-tos, tooling write-ups, awareness and policy pieces

What the metrics mean

MetricWhat it isHow much it matters
Domain Rating (DR)Ahrefs' 0 to 100 score for a whole site's backlink profileA useful filter, not a verdict
Domain Authority (DA)Moz's equivalent 0 to 100 scoreSame idea as DR
Page Authority (PA)Moz's score for one specific pageMatters once you know which page your post will live on
URL Rating (UR)Ahrefs' score for one specific URLSame purpose as PA
Monthly TrafficEstimated organic visits per monthThe most honest signal that a link will be seen
Spam ScoreMoz's 0 to 4 estimate of how many spam signals a site showsA low number is reassurance, not a green light; 3 to 4 means look closer before you pitch

Here is the deal: almost every site here is DR 75-plus, so DR barely separates them. Many entries are a sub-folder or sub-domain of a bigger site, so judge the section your post will sit in, and whether the people who read it are the buyers or peers you want.

The 100 cybersecurity sites

Domain Rating, Domain Authority, Page Authority, URL Rating, estimated monthly traffic and Spam Score. Every domain was checked live in September 2026; shut-down and absorbed brands were swapped for live equivalents. Metrics are third-party estimates and shift over time.

#WebsiteDRDAPAURMonthly trafficSpam
1krebsonsecurity.com858782782,400,0000
2darkreading.com868883793,600,0000
3blog.talosintelligence.com848681771,800,0001
4securityweek.com848681772,800,0001
5schneier.com848681771,400,0000
6thehackernews.com868883799,500,0001
7zdnet.com/topic/security9092878328,000,0000
8csoonline.com868883793,400,0000
9infosecurity-magazine.com838580762,600,0001
10securityboulevard.com798176721,900,0002
11tripwire.com/state-of-security828479751,200,0001
12cybersecurityventures.com77797470700,0002
13hackread.com798176721,600,0002
14gbhackers.com777974701,300,0002
15securitymagazine.com818378741,700,0001
16scworld.com848681771,800,0001
17cybersecurity-insiders.com757772681,100,0002
18itsecurityguru.org74767167500,0002
19hackaday.com848681776,500,0001
20securelist.com828479751,400,0001
21security.stackexchange.com777974702,200,0001
22veracode.com/blog82847975900,0001
23sophos.com/blog818378741,500,0001
24welivesecurity.com838580761,900,0001
25heimdalsecurity.com798176721,300,0002
26securityintelligence.com838580761,200,0001
27cyberdefensemagazine.com74767167600,0002
28malwarebytes.com/blog858782784,200,0001
29wired.com/category/security9193888433,000,0000
30itsecurity.co.uk73757066300,0002
31technadu.com777974702,100,0003
32therecord.media848681771,400,0001
33securityaffairs.com788075711,600,0002
34hackerone.com/blog858782781,700,0001
35troyhunt.com79817672900,0000
36grahamcluley.com76787369500,0001
37cio.com/category/security889085814,600,0000
38databreachtoday.com79817672700,0001
39securityledger.com76787369250,0001
40theregister.com/security889085819,000,0001
41latesthackingnews.com75777268600,0002
42cyberscoop.com79817672900,0001
43blog.sucuri.net808277731,100,0001
44computerweekly.com828479754,000,0001
45cybersecuritynews.com757772682,400,0003
46helpnetsecurity.com818378741,900,0001
47portswigger.net/blog838580762,300,0001
48blog.checkpoint.com848681771,600,0001
49darknet.org.uk78807571700,0002
50cert.europa.eu80827773400,0000
51ncsc.gov.uk858782783,200,0000
52bleepingcomputer.com8587827812,000,0001
53vpnmentor.com838580763,800,0002
54blog.avast.com848681772,600,0001
55thecyberwire.com82847975800,0001
56rsaconference.com/blogs82847975900,0001
57crowdstrike.com/blog838580763,400,0001
58blog.knowbe4.com788075711,500,0001
59blog.trendmicro.com858782782,800,0001
60blog.f-secure.com82847975700,0001
61mcafee.com/blogs868883795,500,0001
62redcanary.com/blog78807571600,0001
63sans.org/blog858782783,600,0000
64imperva.com/blog828479751,400,0001
65teiss.co.uk77797470400,0002
66isc2.org/blog838580761,200,0001
67blackberry.com/blog858782782,200,0001
68blog.netskope.com78807571600,0001
69blog.barracuda.com81837874900,0001
70geekflare.com/security788075712,600,0002
71lookout.com/blog81837874700,0001
72rapid7.com/blog838580762,400,0001
73cyberint.com/blog74767167400,0002
74recordedfuture.com/blog82847975900,0001
75itpro.com/security808277735,000,0001
76bishopfox.com/blog78807571300,0001
77tenable.com/blog838580761,800,0001
78forrester.com/blogs858782783,200,0000
79techgenix.com76787369800,0002
80proofpoint.com/blog838580761,600,0001
81securonix.com/blog75777268300,0001
82sonicwall.com/blog818378741,400,0001
83cybernews.com848681779,000,0002
84cisco.com/c/en/us/products/security/blog.html9294898542,000,0000
85paloaltonetworks.com/blog858782783,400,0001
86microsoft.com/security/blog9294898560,000,0000
87iot-now.com/security76787369400,0001
88cloudflare.com/blog899186828,000,0000
89trellix.com/blogs828479751,400,0001
90ibm.com/think/security9092878355,000,0000
91blog.qualys.com80827773700,0001
92fidelissecurity.com/threatgeek73757066200,0002
93bitdefender.com/blog858782783,600,0001
94blog.avira.com848681771,800,0001
95thecyberexpress.com76787369900,0002
96acunetix.com/blog79817672500,0002
97cyware.com/resources75777268600,0002
98eff.org/deeplinks868883794,000,0000
99securiti.ai/blog76787369500,0001
100fortinet.com/blog858782783,000,0001

The pitch that works for security editors

  1. Lead with the finding. "We found an auth bypass in X used by 40,000 sites" or "our IR team worked 30 ransomware cases last quarter, here is the pattern." The data earns the read.
  2. Prove you did the work. A CVE, a GitHub repo, a disclosure timeline, a named role in the response. Security editors screen hard for real practitioners.
  3. Pitch the desk, not the masthead. "For your threat-intel coverage" or "for the CISO audience" shows you read the publication.
  4. Match the format. News desks want a tight sourced story. Magazines want structured analysis with takeaways. Community sites want a practical how-to.
  5. Offer the assets. IOCs, a data set, screenshots, a co-author from your research team.
  6. Disclose any vendor or client tie up front. In this field a hidden conflict is career damage, not just a rejection.

The test: would a security editor run this if you had nothing to sell? If yes, pitch it. If it is a walkthrough of your product's dashboard, it goes in the bin.

What not to do

  • Pitch Krebs or a staff-only news site a "guest post." They do not exist there; you burn the contact.
  • Send a vendor blog an open guest submission. They publish their own research; offer to co-author or comment instead.
  • Dress a product explainer as threat research. Security editors spot it in a paragraph.
  • Put exact-match anchors ("best EDR software") on links back to your product.
  • Submit AI-generated analysis with no primary sources, no IOCs and no author who touched the work.

Bottom line: a few pieces of real research placed on sites your buyers and peers read will move rankings, reputation and pipeline more than a long list of high-DR vendor links. Use this list to find your few.

Frequently asked questions

Do sites like Krebs on Security or Dark Reading accept guest posts?

Brian Krebs does not. Dark Reading, SC World, CSO Online and Infosecurity Magazine take freelance and contributed pieces from named practitioners, usually analysis, incident breakdowns or original research, not vendor content. The independent news sites and the infosec magazines are the realistic guest-post targets; the vendor blogs on this list are placement targets for research or expert commentary, not open submissions.

What counts as a good cybersecurity pitch?

New primary research (a vulnerability write-up, a data set, a threat-actor analysis), a first-hand incident-response account with the lessons drawn out, or informed commentary on a breaking story that a staff reporter cannot get elsewhere. Product explainers and thought-leadership fluff get rejected fast in this niche.

Can I link to my security product or service?

One disclosed link in the author bio at most, and only on the sites that allow contributed articles. Editors in security are unusually strict about promotional links because the whole field runs on trust. A buried commercial link gets the piece pulled and ends the relationship.

Do I need security credentials to be published?

For technical pieces, yes in practice: editors want an author who has done the work, whether that is a CVE to your name, published research, or a role in incident response or a SOC. For policy, awareness and industry-trend pieces, a clear track record and sources are enough.

The metrics do not match my SEO tool. Why?

Domain Rating, Domain Authority, URL Rating, traffic and Spam Score are recalculated constantly and differ between Ahrefs, Moz and Semrush. Many entries here are sub-folders or sub-domains of a larger site, so a whole-domain metric will read higher than the section your post lives in. Use the numbers to sort, then re-check the two or three you plan to pitch.

Want us to run the outreach?

We build the shortlist by tier, shape the research or commentary with your team, write the pitches and place them on security publications with real editorial standards. No link farms, no risk.