Why Newsletters Matter for ISO 27001
Staying current with the threat landscape and emerging controls is not optional — ISO 27001 Clause 6.1 (risk assessment) requires that risks are identified and reviewed on an ongoing basis, and Clause 7.2 (competence) requires that people involved in the ISMS maintain the knowledge needed to do their jobs effectively. Reading practitioner-quality security writing is one of the lowest-cost ways to meet both obligations.
The list below is short by design. Each entry has to justify its place in your inbox.
The Shortlist
tl;dr sec
Rating: ⭐⭐⭐⭐⭐ — Excellent
Probably the best broad security newsletter available. Covers tooling, research, job moves, and conference talks across the full security spectrum. Weekly cadence, well-curated, high signal-to-noise ratio. Worth subscribing to even if you only skim the headlines.
SANS NewsBites
Rating: ⭐⭐⭐⭐ — Good
Curated security news twice weekly with short practitioner commentary on each item. SANS editors are experienced and the commentary adds context that raw news aggregators miss. Less tactical than tl;dr sec but very reliable.
Risky Business Newsletter / Podcast
Rating: ⭐⭐⭐⭐ — Very Good
Patrick Gray's newsletter complements the long-running Risky Business podcast. Particularly good at contextualising security news — explaining *why* something matters, not just *what* happened. The podcast is also worth your time for longer-form analysis.
Schneier on Security
Rating: ⭐⭐⭐⭐ — Good
Bruce Schneier writes about security thinking, policy, cryptography, and the broader societal implications of technology. Less operational than the others, but valuable for developing the right mental models — especially relevant for organisations where security intersects with legal, regulatory, or privacy concerns.
Latacora Security Blog
Rating: ⭐⭐⭐⭐⭐ — Excellent for SaaS & Startups
Deeper technical and security-engineering writing from a firm that does security programmes for startups and SaaS companies. Articles like "The PGP Problem" and their cryptography and product security posts are some of the best practitioner writing available. Infrequent but high quality — read the archives.
Cloud Security Alliance Newsletter / Blog
Rating: ⭐⭐⭐⭐ — Useful
CSA covers cloud governance, cloud risk, and cloud control frameworks. Directly relevant if your ISMS relies heavily on cloud infrastructure (which most SaaS organisations do). Their research papers and guidance are referenced by auditors and are worth knowing about, even if you don't read everything.
How to Use These for ISO 27001
Reading practitioner security content creates direct evidence for several ISO 27001 requirements:
| ISO 27001 Clause / Control | How staying current helps |
|---|---|
| 6.1 — Risk assessment | Understanding the threat landscape informs risk identification |
| 7.2 — Competence | Demonstrates continuous professional development |
| A.5.7 — Threat intelligence | These newsletters are a lightweight threat intelligence feed |
| A.6.3 — Information security awareness | Sharing relevant articles with the team counts as awareness activity |
| 9.3 — Management review | Recent threat landscape developments are a standard agenda item |
Practical tip: Save particularly relevant articles to your management review notes folder, or reference them in risk assessment updates. It is a low-effort way to show that your ISMS reflects current conditions.