Editorial standards
Last reviewed: 27 August 2026
These are the rules we hold ourselves to. They exist so you can judge our work rather than take it on trust.
Sourcing
- We link to the primary source — the advisory, the filing, the paper, the vendor bulletin — wherever one exists. A story about a CVE should let you reach the CVE.
- We say where information comes from. “According to” is not a substitute for a link when a link is available.
- We distinguish what is confirmed from what is claimed. A vendor’s account of its own incident is reported as the vendor’s account.
- We say what is not known. An unanswered question stated plainly is more useful than a confident guess.
- We do not republish press releases as reporting.
Labelling what you are reading
Different pieces do different jobs, and you should not have to infer which. Reporting, analysis, opinion, explainer, tutorial, interview and industry contribution are distinct editorial formats and are labelled as such.
Opinion is labelled as opinion. Contributions written by people outside the publication are labelled as contributions and carry the author’s affiliation.
Subject tags — ransomware, cloud, GRC — describe what a piece is about. They are kept separate from what kind of piece it is.
Recommendations
The publication makes explicit recommendations in one place: Decision Desk. Those pieces state the recommendation, the reasoning, the conditions under which the answer changes, the alternatives considered, and their sources. Every one of those parts is required.
Nothing elsewhere on the site should be read as a recommendation from CISO Times, and we try never to write as though it were.
Disclosure
- If we have a commercial interest in something we are writing about, we say so on the page, above the article, before you read it.
- Where a Decision Desk item touches a decision we or an associated business monetise, we are required to name at least two credible third-party alternatives. This is enforced when the site is built, not left to memory.
- Sponsored or paid placement, if we ever accept it, is labelled as such and is never presented as editorial. We do not accept payment for coverage or for a favourable conclusion.
- Affiliate arrangements, if any, are disclosed on the page that carries them.
Use of AI
We do not publish machine-generated text as though a person wrote it.
Where an AI tool has materially assisted a piece — drafting, summarising, translating — a named human editor is accountable for reviewing and verifying it, and that review is recorded against the piece. The byline is a person, and that person answers for the content.
We do not use AI to generate quotes, sources, statistics or images presented as real.
Corrections
We correct the record rather than quietly editing it.
Material factual errors — anything that changes the meaning of a piece — are corrected in place and marked with a correction note explaining what was wrong and when it was fixed. The note stays. We do not remove a correction once the embarrassment has passed.
Minor fixes — spelling, a broken link, a formatting fault — are made without a note.
Substantive updates to a developing story are dated, so you can tell what was known when.
We do not delete published articles to make a problem go away. If something cannot stand, it is corrected, updated, or marked as withdrawn with the reason given.
Reporting an error
Write to info@cisotimes.com with the page address and what you believe is wrong. If you can point at a source, it will be dealt with faster.
We aim to acknowledge within three working days, and to correct or explain our position within ten. Reporting an error does not require you to identify yourself or your employer.
If you are reporting a security vulnerability in the website rather than an error in an article, use our vulnerability disclosure policy instead.
Right of reply
If we report on your organisation and you believe the piece is materially wrong or omits something that changes it, tell us. Where the point stands we will correct it. Where it does not, we will say so and why. We do not remove accurate reporting on request.