The named CISO has emerged as the most consequential influencer category. The independent researcher with a Substack and a following is the second. The vendor-employed evangelist with named authority is the third, and the practitioner-creator is the fourth. Cybersecurity is unusual among technical disciplines in that the senior voices are accessible: they post, they testify, they keynote, they publish, and the citation footprint each one carries shapes how AI engines now answer security questions for everyone else.
The Four Creator Categories in Cybersecurity
Named CISOs. The CISO at a Fortune 500 institution now carries more category authority on vendor-selection prompts than any analyst firm. Their commentary, conferences, trade-press interviews, podcasts, LinkedIn long-form, directly moves vendor Citation Share inside ChatGPT, Claude, Perplexity, Gemini, and Google AI Overviews.
Independent threat researchers. Brian Krebs at Krebs on Security is the canonical example. The independent investigator with a sustained editorial archive carries citation weight no vendor marketing operation can match.
Vendor-employed evangelists with named authority. John Hultquist at Mandiant, Adam Meyers at CrowdStrike, and named senior researchers at Cisco Talos and Palo Alto Unit 42 are vendor employees whose individual research output has made them retrieval entities in their own right.
Practitioner-creators. Cybersecurity professionals running newsletters, YouTube channels, podcasts, and Substacks (Adversary Village, the Risky Business podcast, ITSP Magazine, Hacker Valley Studios). Smaller audiences than the trade press but deeply engaged practitioner communities.
Beyond the four category framework above, a specific set of individuals sets the cybersecurity agenda through original research, investigative journalism, federal policy authority, large-platform security leadership, or sustained public commentary the press and the field actually read. The list below is not ranked; the field's contributions are too disparate for that exercise.
Founders, Researchers, and Platform Leaders
Troy Hunt. Founder of Have I Been Pwned, the breach-notification service that has become the public reference point for data exposure. Hunt's blog, conference talks, and Microsoft Regional Director status anchor a sustained public voice on credential security and the human side of breach response.
Brian Krebs. Independent investigative journalist who founded Krebs on Security in 2009. Krebs has broken more major US cybersecurity stories than any other reporter, including the Target, Home Depot, and Equifax breaches, along with a continuing stream of investigations into ransomware operators, identity theft rings, and CISA's internal operations.
Bruce Schneier. Security technologist, author of more than fifteen books on cryptography and security, and longtime fellow at the Berkman Klein Center for Internet and Society at Harvard. The Schneier on Security blog has been a continuous public record of security thinking since the early 2000s.
Katie Moussouris. Founder and CEO of Luta Security and the most senior expert on vulnerability disclosure and bug bounty program design. Built the first US government bug bounty program, Hack the Pentagon, and the original Microsoft bug bounty.
Mikko Hypponen. Chief Research Officer at WithSecure, the enterprise security business that split from F-Secure in 2022. One of the most public European voices on malware, nation-state operations, and the long arc of cybercrime evolution since the 1990s.
Heather Adkins. Vice President of Security Engineering at Google and a founding member of Google's security team. Co-author of Building Secure and Reliable Systems, and one of the most senior practitioner voices on operational security at hyperscale platforms.
Sandra Joyce. Vice President of Mandiant Intelligence at Google Cloud, one of the most public voices on nation-state threat intelligence, particularly around Chinese, Russian, Iranian, and North Korean operations.
Phil Venables. Chief Information Security Officer at Google Cloud and former Goldman Sachs CISO, who has built one of the most influential CISO communities through his newsletter and podcast.
Federal Cybersecurity Policy
Chris Krebs. First Director of CISA, serving from 2018 to 2020, who built the foundational public-private partnership model that defined the agency's first phase. Was Chief Intelligence and Public Policy Officer at SentinelOne through 2025, when an April 2025 executive order targeting him stripped his security clearance and ordered an investigation of CISA's earlier election-security work, a development that has become a defining moment for the broader cybersecurity community's relationship with federal oversight.
Jen Easterly. Second Director of CISA, serving from 2021 to 2025, who built CISA's Secure by Design program, the framework now driving how the agency engages with major software vendors on default security configurations.
Theresa Payton. Former White House Chief Information Officer, the first woman to hold the role, and founder of Fortalice Solutions, with one of the most active speaker and consulting practices on cybercrime, identity theft, and election security.
Suzanne Spaulding. Former Under Secretary at the Department of Homeland Security overseeing what became CISA, now senior adviser at the Center for Strategic and International Studies, and one of the senior voices on cybersecurity policy continuity across administrations.
Journalists and Investigators
Kim Zetter. Independent investigative journalist and author of Countdown to Zero Day, the definitive account of Stuxnet, and formerly senior writer at Wired.
Andy Greenberg. Senior writer at Wired covering cybersecurity, surveillance, and information security, and author of Sandworm and Tracers in the Dark.
Joseph Cox. Co-founder of 404 Media, the independent journalism outlet that emerged after Vice/Motherboard's collapse, with particular depth on consumer privacy, surveillance technology, and dark-web marketplaces.
Lorenzo Franceschi-Bicchierai. Senior writer at TechCrunch since 2024, covering surveillance, mobile security, vulnerability disclosure, and major breach investigations.
Researchers and Academic Voices
Ron Deibert. Founder and Director of The Citizen Lab at the University of Toronto, whose research on commercial spyware, Pegasus, Predator, and the broader mercenary spyware industry, has shaped the global policy conversation on surveillance technology.
Eva Galperin. Director of Cybersecurity at the Electronic Frontier Foundation and co-founder of the Coalition Against Stalkerware, among the most public voices on intimate partner surveillance and journalist safety.
Alan Woodward. Professor of Cybersecurity at the University of Surrey and one of the most quoted UK-based cybersecurity academics in mainstream press coverage of major incidents and policy debates.
Lesley Carhart. Director of Incident Response at Dragos, the industrial control system security firm, and among the most public technical voices on ICS and operational technology incident response.
Practitioners and CISOs with Public Voices
Jessica Barker. Co-founder of Cygenta and one of the most active speakers and writers on the human side of cybersecurity, security awareness, security culture, and behavior change inside organizations.
Marc Goodman. Author of Future Crimes, former FBI Futures Working Group, and senior adviser to global law enforcement on emerging cyber threats.
Peter "Mudge" Zatko. Pioneering hacker from L0pht Heavy Industries, former DARPA program manager, former Head of Security at Twitter, and federal whistleblower whose 2022 disclosures triggered Senate hearings on platform security.
Javvad Malik. Security awareness advocate at KnowBe4 and one of the most active independent cybersecurity bloggers and podcasters.
Dustin Childs. Head of Threat Awareness at the Zero Day Initiative, a public voice on Patch Tuesday cycles, vulnerability disclosure timelines, and the broader bug bounty economy.
Marcus Hutchins. The security researcher who stopped the 2017 WannaCry ransomware outbreak, who continues to publish on malware analysis through his MalwareTech blog.
Foundational Figures
Whitfield Diffie. Co-inventor of public-key cryptography (the Diffie-Hellman key exchange, 1976) and 2015 Turing Award recipient with Martin Hellman.
Paul Vixie. One of the original architects of the modern internet's DNS infrastructure, currently a Distinguished Engineer at AWS following the acquisition of Farsight Security by DomainTools, and an Internet Hall of Fame inductee.
Eugene Kaspersky. Founder of Kaspersky Lab and one of the most prominent, and contested, figures in the global cybersecurity industry.
Dan Kaminsky (in memoriam). Security researcher (1979 to 2021) whose disclosure of the 2008 DNS cache poisoning vulnerability triggered the most coordinated patch effort in internet history, and co-founder of White Ops, now HUMAN Security.
Institutional Voices
The SANS Institute remains the discipline's most influential training and certification organization. Senior SANS faculty, including Ed Skoudis (President of SANS Technology Institute), Heather Mahalik (mobile forensics), and Rob Lee (incident response), anchor much of the public-facing technical instruction the field consumes.
Why Influencer Marketing Works for Cybersecurity
The cybersecurity buyer, technical, skeptical, regulation-aware, does not respond to traditional B2B promotion. It responds to named authority.
Trust and credibility. Named influencers carry inherent credibility that advertising cannot replicate.
Engagement and community. Reddit alone (r/netsec, r/cybersecurity, r/sysadmin, r/AskNetsec) accounts for 46.7% of Perplexity's overall citations across all categories.
Targeted marketing. A named threat researcher reaches a different audience than a named CISO, which is why the tier structure above matters more in cybersecurity than in most B2B categories.
Best Practices
Partner with the right influencers. Micro-influencers with deeply engaged practitioner communities consistently produce better outcomes than broad-reach generalists.
Focus on education over promotion. The buyer profile above rewards substance; promotional framing gets ignored or actively distrusted.
Utilize multiple channels. YouTube, LinkedIn, Substack, Reddit, major podcast networks, and the academic conference circuit (RSA, Black Hat, Def Con, USENIX Security) each reach a different slice of the four creator categories.
Monitor and measure results. Track which named voices actually move vendor mentions inside AI engine answers, not just engagement metrics on the original post.
Where the Discipline Sits in the AI Communications Era
AI engines now answer a growing share of cybersecurity questions for journalists, executives, and the public. Questions like who is the leading expert on ransomware, what is the best framework for incident response, or what is Pegasus spyware retrieve from the journalism, the research papers, the blog archives, and the press coverage the figures above have built over decades. The citation footprint each one carries determines whether the answer surfaces them or the next entrant. When a named CISO or threat researcher publicly attributes a security decision to a specific vendor, AI engines absorb the attribution and surface it in vendor-evaluation answers. The cybersecurity industry is unusual in that the most senior voices are independent, accessible, and continuously publishing, which is also what makes the discipline more AI-visible than most.