Recomputed on every load

Who covers what in cyber security

By Nick Forshteyn · CISO AI
Figures as at 29 September 2026

We read and tag every cyber security story we can find. Across 919 of them from 26 outlets, the interesting result is not what gets covered. It is how differently each subject is covered: across its 71 stories, malware is 53.5% one outlet, while AI security, at 174 stories, is split across 20 outlets with none holding more than 19.5%.

How this is measured. Every story CISO AI holds, published between 30 August 2026 and 28 September 2026: 919 in total from 26 outlets, counting the 46 publishers whose stories arrive through the financial wire as one. 1 outlet silent for more than a week and far longer than its usual gap is marked as last seen and cannot carry a headline claim. Each is summarised and tagged by topic when it arrives, and a story usually carries several tags, so topic shares sum past 100%. Counts are of stories, not words. These figures are computed when you load the page, so they move as the archive grows. The limitations are set out at the end, and they matter.

Some subjects have an owner. Others have nobody.

For each topic we count how many distinct outlets covered it and what share the leading outlet holds. Topics with fewer than 8 stories are excluded, because below that one extra story swings the percentage wildly. The two topics named above clear a higher bar again — 25 stories and 3 outlets — because a headline claim should not turn on a sample small enough for one outlet's back catalogue to move.

TopicStoriesOutletsLeading outletIts share
AI security 174 20 The Hacker News 19.5%
data breach 127 14 Financial press wire 37%
vulnerability 120 17 The Hacker News 48.3%
cryptocurrency 114 4 Financial press wire 92.1%
patch management 83 15 The Hacker News 43.4%
incident response 81 14 Financial press wire 53.1%
vulnerability management 76 15 The Hacker News 30.3%
blockchain security 72 3 Financial press wire 95.8%
Stories per topic, for the 8 largest topics. A story usually carries several tags, so topics overlap and the counts deliberately do not sum to 919.

malware is mostly The Hacker News. Of its 71 stories, that one outlet wrote 38, and only 14 outlets covered the subject at all. Skip that publication and you miss 53.5% of it.

AI security is the opposite. At 174 stories it is spread across 20 outlets, with the largest, The Hacker News, holding just 19.5%. No single publication is a reliable way to follow it.

Concentration is not the same as volume

The 7 largest outlets still publishing, The Hacker News, Financial press wire, Infosecurity Magazine, Dark Reading, The Register, The Record, CyberScoop, produced 709 of the 919 stories, or 77.1% of everything. That sounds like a concentrated market, and by raw output it is. The topic table shows why that is misleading: the outlets that dominate the total are not the ones that own every subject.

The Hacker News: 214 stories (23.3%) Financial press wire: 179 stories (19.5%) Infosecurity Magazine: 86 stories (9.4%) Dark Reading: 85 stories (9.2%) The Register: 54 stories (5.9%) The Record: 52 stories (5.7%) CyberScoop: 39 stories (4.2%) 19 other outlets: 210 stories (22.9%) 77.1% top 7 outlets
Share of all 919 stories, by outlet. Outlets that have stopped publishing are counted under "other". Recomputed on every load, so the split moves as the archive grows.

The practical version: a reader following one masthead is not getting a smaller version of the whole picture. They are getting a picture with specific, predictable holes in it, and which holes depends entirely on which masthead.

What this means if you are trying to keep up

If you follow a single source, choose it for what you need to see rather than for general reputation. The Hacker News carries 19.5% of AI security; Financial press wire carries 37% of data breach; The Hacker News carries 48.3% of vulnerability.

If you would rather not maintain a reading list, that is what the weekly briefing is for: every one of these 919 stories is summarised in plain language, and each topic above has its own page, including AI security, data breach, vulnerability, cryptocurrency.

Limitations, which are real

  • These are the outlets we ingest, not the whole press. Topic shares describe this corpus. A different feed list would produce different percentages.
  • Tagging is model-generated. Topics are assigned automatically when each story is summarised. It is consistent, which is what matters for comparing topics against each other, but it is not a human taxonomy and it will disagree with one at the margins.
  • Counts are of stories, not significance. A one-paragraph advisory and a three-thousand-word investigation count the same here.
  • Outlets join the corpus over time. A source we started reading recently carries only the stories published since it joined, so its share understates its actual output, and comparisons against long-standing sources favour the incumbents. Shares converge as the archive grows.
  • The window is still filling. Feeds deliver stories dated days earlier, so recent counts rise for a while after the fact. That is also why this page is computed rather than published: a figure written into a page was wrong within hours.
  • Outlets stop. A feed that goes dark keeps its stories in the archive. An outlet silent for more than 7 days and more than 3 times its own usual gap between stories is labelled with the date it was last seen wherever this page names it, and is not allowed to carry a headline claim, but its past stories still count in the totals.
  • The financial wire is one outlet here. It delivers each story under the original publisher's name; counting those as separate outlets inflated the outlet count and made cryptocurrency look more fragmented than the press actually is. Leak-site trackers are excluded altogether: a listing is not a story.
  • Cite it with the date you read it, shown above, since the numbers move as the archive grows.

Comments

No comments yet.

To comment, confirm your email once. We send a sign-in link; no password to remember.

Your name appears with your comment; your email never does. By continuing you accept our terms and privacy policy.