Write for CISO Times
We publish practitioner writing about carrying more than one framework at once — what overlaps, what genuinely diverges, and what that costs in practice. We also publish work on security operations, data protection, governance, resilience and the practical side of running security programmes.
Before you write
- 400–4000 words, in plain English. Expand every acronym once.
- Original and unpublished. Not on your own blog, not on LinkedIn, not adapted from a vendor post.
- Specific. "How we mapped DORA's ICT incident thresholds onto an existing NIS2 register" — not "the importance of compliance".
- Our subjects. Information security, data protection and governance — ISO 27001, NIS2, DORA, PCI DSS, GDPR, business continuity, cloud and endpoint security, and the ground between them.
- No selling. We do not publish pieces that exist to point at a product, ours or anyone's. Tell us in the disclosure box if you have a commercial interest in the subject.
- Paste it as text. This form takes no attachments. If it needs a diagram, say so and we will ask for it.
We review every confirmed submission. If we want to publish it, we will contact you about edits before anything appears on the site.