Asset 20 8 2
Does AI recommend your business? Run the free check →

Join 15,000 business owners, marketers and entrepreneurs. The Sunday newsletter you'll be annoyed only arrives once a week.

Cybersecurity blogs that accept guest posts include several leading security news sites that run columns from practitioners. Well-known names that take outside writers include Dark Reading, Infosecurity Magazine and SecurityWeek, alongside hundreds of smaller cybersecurity blogs. Pick sites whose readers match your topic, read each site's current guidelines and pitch one specific idea.

Cybersecurity is a niche where expertise is everything. Security vendors, managed service providers, consultancies, training companies and software businesses all want to reach security teams and the business leaders who fund them, and security sites are where those readers keep up.

Security editors are quick to spot a vendor pitch dressed up as an article. They want posts that teach readers something useful, written by people who do the work, and they cut product mentions hard.

This page sits alongside my free list of websites that accept guest posts, which covers sites across every niche.

Which cybersecurity blogs accept guest posts?

These are long-running cybersecurity publications that are known for running work from contributors, freelancers or guest writers. Each one works differently, so treat this as a starting point:

  • Dark Reading: a long-running security news site that runs commentary from industry practitioners.
  • Infosecurity Magazine: a security publication that publishes opinion and analysis from experts.
  • SecurityWeek: a security news site with columns written by people who work in the field.
  • Help Net Security: a long-established security news site that runs contributed articles from experts.
  • The Hacker News: a widely read security news site that publishes expert insight pieces.
  • Security Boulevard: a security community site that publishes and shares blogs from practitioners.

Most of the sites above want contributed columns from practitioners, not marketing copy, and some ask contributors to avoid naming their own products. Guidelines change, and some sites pause submissions for months at a time, so read each site's current pitch or write for us page before you send anything.

Should you aim for the big names or smaller cybersecurity blogs?

The famous cybersecurity titles are worth a pitch if you have real expertise and patience, but they get far more pitches than they can use, and many only work with writers they already know. Smaller cybersecurity blogs with a loyal readership are often the better first step. They reply faster, they're more open to new writers, and a post on a focused site that your buyers read can do more for you than a line on a huge site they never visit.

Whichever you choose, judge a site on its readers and how it looks after them, not on one metric. A site that still publishes, edits with care and has real people commenting is worth more than a bigger site that publishes anything.

Threat news, practical defence or security leadership?

Security sites write for different readers:

  • Threat and news sites want analysis of attacks, vulnerabilities and trends.
  • Practical defence sites want how-to posts on hardening systems, detection and response.
  • Leadership sites want posts on strategy, risk, compliance and building a security team.
  • Small business sites want plain advice on staying safe without a security department.

Security vendors do best with practical defence and leadership posts that teach without selling. Managed service providers and trainers fit well on small business sites.

What do cybersecurity editors want?

Real expertise and accuracy. Security editors want writers who work in the field: analysts, engineers, researchers and security leaders. Technical detail needs to be correct, sources named and nothing published that could help an attacker.

They also want neutrality. A post that compares approaches fairly, or explains a problem without pushing one product, is far more likely to run than one that ends with a sales pitch.

Free guest post or sponsored post on a cybersecurity blog?

Free contributed columns are common on security news sites, if you have real expertise and keep the vendor angle out. Many also run labelled sponsored content or webinars. Sponsored posts are faster and more predictable for vendors launching a product or report.

How do you check a cybersecurity blog before you pitch?

  • Read the three newest posts. Is the site still publishing, and who writes for it?
  • Find the current guidelines. Look for a write for us, contribute or pitch page, and check its date.
  • Check the authors. Named practitioners with real job titles show a security site editors and readers respect.
  • Find a name. A real editor you can email beats a form that never replies.
  • Ask if posts are permanent. Some sites prune old content in clean-ups.

There's more in how to check backlink quality and my guide to high DA guest posting sites. Security overlaps with tech and business, so my technology blogs that accept guest posts and business blogs that accept guest posts pages are useful places to widen your search.

How should you pitch a cybersecurity blog?

Lead with what readers will learn. "What small firms can learn from the latest wave of invoice fraud attacks" is a pitch. "A cybersecurity article" is not. Say what you do and why you know the subject.

Keep links useful. A link to research, a detailed guide or a free tool is easy to approve. A link to a product page will usually be removed, if the post runs at all.

Offer original data if you have it. Findings from your own research, incident work or surveys give a security editor a reason to choose your post.

Can you place a cybersecurity post on my blog?

Sometimes, when it has a marketing or business angle: marketing a security company, explaining security to small business owners, or building trust with customers. lilachbullock.com is a marketing blog that's been publishing since the dial-up days, with thousands of indexed articles, and my readers are business owners, marketers and entrepreneurs, mostly in the USA and the UK. Technical security writing suits the sites above better. Guidelines are on my cybersecurity page.

How placing a post on my blog works

  1. Email [email protected], or start on my write for me page, with your target URL, topic and niche.
  2. I reply with whether it fits and which format I'd pick: a new sponsored post or a link insertion into an existing, indexed article.
  3. You send the article, or I choose the right existing article for your link.
  4. I edit, publish and send you the live URL.

Accepted posts usually go live within 24 to 48 hours of everything being agreed. Placements are permanent. I invoice by PayPal, and if you're an agency, I never contact your client.

If you're weighing up where to place a post, how buying a guest post on my blog works explains what you get and what I turn down.

Placing a cybersecurity post? Email [email protected] with your target URL, topic and niche, or start on my write for me page. Agencies and repeat buyers are welcome.

Frequently asked questions

Which cybersecurity blogs accept guest posts?

Well-known examples that take outside writers include Dark Reading, Infosecurity Magazine, SecurityWeek, Help Net Security, The Hacker News and Security Boulevard. Check each site's current guidelines before you pitch, because they change.

Do cybersecurity news sites accept guest posts?

Many run contributed columns from practitioners. Read each site's guidelines first, because most ban product promotion in contributed pieces.

What should I pitch a cybersecurity blog?

Pitch a useful, accurate post that teaches readers something, written by someone who works in security, with no hard sell.

Can I place a cybersecurity guest post on lilachbullock.com?

Sometimes, if it has a marketing or business angle. Email your target URL, topic and niche and I'll tell you if it fits.