Blogs, Newsletters & Written Intelligence
Related: Intelligence Sources.
Where podcasts capture cyber's principals thinking out loud, written sources are where they argue a thesis, and the written layer is denser, more citable, and more useful as raw material for the book and the LinkedIn campaign. The written-intelligence stack runs from a handful of primary thinkers (whose essays are closest to the book's own thesis) down through investigative reporting, policy commentary, trade press, and the deal-research shops whose valuation reports calibrate comps.
The stack: depth vs. timeliness
Written sources trade off two things — how deep/durable the analysis is versus how fast/fresh it moves. Primary research (founder-operator essays, valuation reports) is deep but slow; trade press and aggregators are fast but shallow; investigative journalism sits in between, deep on a single story. Knowing where a source sits tells you whether to mine it for the book or skim it for the feed.
The primary thinkers
Venture in Security (Ross Haleliuk) is among the most important written sources for the business of cybersecurity, and the closest existing body of work to the book's own thesis. Haleliuk writes about startup-building, business models, go-to-market, and venture economics with an operator's specificity; he is the author of Cyber for Builders: The Essential Guide to Building a Cybersecurity Startup, co-hosts Inside the Network, and also publishes in TechCrunch, Forbes, and VentureBeat. The standout posts to mine — and to cite in the book's venture/GTM chapters — include "19 (+1) traction channels for growing a cybersecurity startup" (the founder GTM playbook), "Time to trust: why cybersecurity startups must shorten it" (see 07d), "Solving problems when nobody will admit they have one," "4 ways cybersecurity startups can boost adoption and shorten time to value," "Investing in cybersecurity: challenges, opportunities, and tools for cyber VCs," and his recurring market-map and unicorn-founder studies.
The business-of-cyber analyst bench — the written sources whose beat is this book's subject, and the closest external work to The Business of Cyber Security: - Strategy of Security (Cole Grolmus) — weekly first-principles analysis of the cyber market as a business system: market maps, consolidation economics, category structure. The single best external complement to the book's thesis; a source for framing and the "is cyber one market or many?" question. - Software Analyst Cyber Research / SACR (Francis Odum, 60k+ followers) — the deepest published company-financial work on public and private cyber names (CrowdStrike's path to $100B, Palo Alto's platformization economics, Zscaler/Okta/SentinelOne). Read Odum on RPO/cRPO and segment disclosures as the forward read before reported revenue (see Unit Economics); the closest match to Public Trading Comps. - The Security Industry / IT-Harvest (Richard Stiennon) — the industry's census-taker, tracking 3,750+ vendors vendor-by-vendor; author of the annual Security Yearbook. His signature, thesis-testing finding: the total vendor population keeps rising every year despite record M&A — the empirical check on any consolidation claim (reconciled on 02d: value concentrates while the vendor count grows at the modular edge). - Return on Security (Mike Privette) — the cyber funding/M&A metrics newsletter; maintains running deal and financing data and the discipline of as-of-dating every figure. The standard to hold Deals and Valuation to.
Stratechery (Ben Thompson) is the strategic-analysis backbone — Aggregation Theory, the integration↔modularity pendulum, distribution-as-power. The Business of Cyber Security explicitly borrows that lens (see Overview and the book thesis). Thompson is strongest on the AI-platform dynamics now reshaping cyber: who aggregates demand, where modularity reopens, and why bundling (Microsoft) is the standing threat to every point product. Stratechery is a source for frameworks rather than deal facts.
Schneier on Security (Bruce Schneier, since 2004) is the durable security-and-policy voice — strongest on cryptography, surveillance, AI-and-trust, and the public-policy framing that increasingly drives regulatory demand (see Regulation). TaoSecurity (Richard Bejtlich) brings a detection-and-strategy lens with a military-history sensibility — useful for understanding the blue-team buyer and the doctrine behind SecOps spend.
Investigative & breaking sources
Krebs on Security (Brian Krebs) is the premier investigative source; Krebs breaks cybercrime and breach stories that frequently become the demand narrative behind a category's growth and, occasionally, the catalyst behind a deal. The Record (Recorded Future's newsroom) is the best-resourced security newsroom for nation-state and policy stories. These are deep but event-driven — read them when they publish, and watch for stories that move a sub-segment's demand thesis (a wave of breaches in a vertical → an underwriting/regulation/vendor tailwind; see Threat as a Leading Indicator).
Trade press & aggregators
The daily trade-press layer is where deals, funding rounds, and exec moves first surface before they reach the comps and earnings pages: SecurityWeek, CSO Online, Cybersecurity Dive, Dark Reading, The Record, Help Net Security, and — specifically for the channel — MSSP Alert and Channel Futures (the source layer for MSSP and channel intelligence). Skim these daily; their function in the stack is early detection, not analysis. Every funding or M&A item they break is a candidate row for Deals & Comps — each verified against a primary source (company PR, SEC/8-K) before recording, following source-and-date discipline.
Deal & market research
The valuation and deal-research shops are the quantitative backbone of the comps work: Kroll, Solganick & Co., First Analysis, Finro, and Windsor Drake publish cyber valuation and M&A reports that calibrate the multiples on Valuation and Comps Methodology. The RBC weekly research Atul receives is the institutional-grade complement — comps, M&A updates, and sector analysis — and is the highest-priority private input to keep the public-comps pages honest. (Named market-intelligence and deal-database competitors are deliberately excluded from this roster.)
| Layer | Sources | What it yields | How to use it |
|---|---|---|---|
| Primary thesis | Venture in Security, Stratechery, Schneier, TaoSecurity | Durable frameworks & GTM/economics arguments | Mine for the book + LinkedIn POV |
| Investigative | Krebs, The Record | Demand narratives; occasional deal catalysts | Read on publish; watch demand signals |
| Trade press | SecurityWeek, CSO, Cybersecurity Dive, Dark Reading, MSSP Alert | Early detection of deals/funding/moves | Skim daily; verify before recording |
| Deal research | Kroll, Solganick, First Analysis, Finro, Windsor Drake, RBC (private) | Valuation/comps calibration | Calibrate 11/12 |
Updated 2026-08-16 18:13 UTC · © El Dorado Capital · el-doradocapital.com · Market intelligence for informational purposes only; not investment advice.