Expert TipTraining & Awareness

Security Newsletters Worth Subscribing To

A curated shortlist of practitioner-quality security publications — from broad weekly digests to deep technical writing — that are worth your inbox space.

Updated 21 Jun 2026

Why Newsletters Matter for ISO 27001

Staying current with the threat landscape and emerging controls is not optional — ISO 27001 Clause 6.1 (risk assessment) requires that risks are identified and reviewed on an ongoing basis, and Clause 7.2 (competence) requires that people involved in the ISMS maintain the knowledge needed to do their jobs effectively. Reading practitioner-quality security writing is one of the lowest-cost ways to meet both obligations.

The list below is short by design. Each entry has to justify its place in your inbox.


The Shortlist

tl;dr sec

Rating: ⭐⭐⭐⭐⭐ — Excellent

Probably the best broad security newsletter available. Covers tooling, research, job moves, and conference talks across the full security spectrum. Weekly cadence, well-curated, high signal-to-noise ratio. Worth subscribing to even if you only skim the headlines.

Format: Weekly digest
Best for: Security generalists, practitioners staying across the field
URL: tldrsec.com

SANS NewsBites

Rating: ⭐⭐⭐⭐ — Good

Curated security news twice weekly with short practitioner commentary on each item. SANS editors are experienced and the commentary adds context that raw news aggregators miss. Less tactical than tl;dr sec but very reliable.

Format: Bi-weekly curated digest with commentary
Best for: Keeping track of major incidents, vulnerabilities, and policy developments

Risky Business Newsletter / Podcast

Rating: ⭐⭐⭐⭐ — Very Good

Patrick Gray's newsletter complements the long-running Risky Business podcast. Particularly good at contextualising security news — explaining *why* something matters, not just *what* happened. The podcast is also worth your time for longer-form analysis.

Format: Newsletter + weekly podcast
Best for: Context and analysis on security news; good for senior practitioners and decision-makers
URL: risky.biz

Schneier on Security

Rating: ⭐⭐⭐⭐ — Good

Bruce Schneier writes about security thinking, policy, cryptography, and the broader societal implications of technology. Less operational than the others, but valuable for developing the right mental models — especially relevant for organisations where security intersects with legal, regulatory, or privacy concerns.

Format: Irregular blog posts and newsletter
Best for: Security thinking, policy, and privacy; less day-to-day operational
URL: schneier.com

Latacora Security Blog

Rating: ⭐⭐⭐⭐⭐ — Excellent for SaaS & Startups

Deeper technical and security-engineering writing from a firm that does security programmes for startups and SaaS companies. Articles like "The PGP Problem" and their cryptography and product security posts are some of the best practitioner writing available. Infrequent but high quality — read the archives.

Format: Irregular long-form blog posts
Best for: Engineering teams, SaaS founders, anyone building or reviewing technical security controls

Cloud Security Alliance Newsletter / Blog

Rating: ⭐⭐⭐⭐ — Useful

CSA covers cloud governance, cloud risk, and cloud control frameworks. Directly relevant if your ISMS relies heavily on cloud infrastructure (which most SaaS organisations do). Their research papers and guidance are referenced by auditors and are worth knowing about, even if you don't read everything.

Format: Newsletter + research publications
Best for: SaaS, cloud governance, cloud risk management, and control frameworks

How to Use These for ISO 27001

Reading practitioner security content creates direct evidence for several ISO 27001 requirements:

ISO 27001 Clause / ControlHow staying current helps
6.1 — Risk assessmentUnderstanding the threat landscape informs risk identification
7.2 — CompetenceDemonstrates continuous professional development
A.5.7 — Threat intelligenceThese newsletters are a lightweight threat intelligence feed
A.6.3 — Information security awarenessSharing relevant articles with the team counts as awareness activity
9.3 — Management reviewRecent threat landscape developments are a standard agenda item

Practical tip: Save particularly relevant articles to your management review notes folder, or reference them in risk assessment updates. It is a low-effort way to show that your ISMS reflects current conditions.

Related Modules

Standard Controls
Risk Register

Related Controls / Clauses

6.1
7.2
A.5.7
A.6.3
9.3

26 practitioner guides — included free with your workspace

27 Launchpad generates your full compliance toolkit from a 10-minute setup: policies, risk register, legal register, controls, and AI-assisted document review.