Reading List & People to Follow

The books, newsletters, blogs, podcasts, and practitioners CSOH members keep coming back to. Vendor-neutral, opinionated, and aging fast โ€” please send PRs to add what's missing or correct what's stale.

A close-up of a stack of open books with pages fanned out, capturing a study atmosphere
Photo by Pixabay on Pexels

ยท ยท Vendor-neutral ยท View source on GitHub

The honest version: Lists like this are obsolete the moment they're published. Books get superseded, people change jobs and platforms, newsletters go quiet, podcasts wrap up. We're keeping this short on purpose โ€” only what we'd actually re-recommend right now. If a name's missing or stale, open a PR or issue and we'll update it.

On social handles: we list which platform each person is most active on but skip exact handles unless they're stable and well-known. Search the name on the platform โ€” well-known practitioners surface in the first result. This page ages slower that way.

๐Ÿ“– On this page

  1. Books
  2. Newsletters
  3. Blogs (vendor research & individual)
  4. Podcasts
  5. People to follow on X / Bluesky / LinkedIn
  6. Papers, frameworks & canonical reads
  7. Contribute or correct

The 6 ways CSOH members consume cloud security content

Each medium covers a different gap in your learning. Click a tile to jump to its picks.

Recommended reading-time split Suggested allocation of weekly cloud security reading across the six media types. Recommended weekly reading-time split (~3 hrs/week) ~3 hrs per week Newsletters ยท 15% (skim Mon AM) Blogs ยท 25% (deep dives, when relevant) Podcasts ยท 20% (commute / chores) Books ยท 15% (one chapter at a time) People (X/LI) ยท 12.5% (signal, not noise) Papers ยท 10% (one a month is plenty) "3 hours" sounds small but it's the average our members report sustaining without burning out.
Aim for breadth over volume. Three hours intentionally split across formats beats ten hours of doom-scrolling X.
A well-stocked bookshelf filled with various books in a library setting
Photo by cottonbro studio on Pexels

Books

Grouped by topic. None of these are required reading; pick the one that maps to whatever you're working on this quarter.

Each book title links to its Open Library entry โ€” pick up the cover, ISBN, and your preferred bookseller from there.

Cloud security foundations

Identity & IAM

Containers & Kubernetes

AppSec & DevSecOps

Detection & incident response

Risk, leadership, and the meta-game

Newsletters

If you read three things a week, make these three things. All free, all email-based. Each card links to the subscribe page; the GitHub Actions workflow generates the preview screenshots after merge.

tl;dr sec

Clint Gibler. The single most-cited security newsletter in our community. AppSec-leaning but cloud-heavy. Weekly.

NewsletterAppSecWeekly

Cloud Security Newsletter

Marco Lancini. The cloud-specific weekly. Curated, technical, no fluff.

NewsletterCloudWeekly

Last Week in AWS

Corey Quinn. Not security-only, but if you work in AWS at all this catches you up faster than the AWS What's New feed.

NewsletterAWSWeekly

Detection Engineering Weekly

Zack Allen. If detection is your day job.

NewsletterDetectionWeekly

Risky Business News

Catalin Cimpanu. Short, daily, broad security headlines with sharp commentary.

NewsletterNewsDaily

Resilient Cyber

Chris Hughes. Strategy, leadership, supply-chain angle.

NewsletterStrategySupply Chain

Blogs

Vendor research blogs (the good ones)

Not all vendor blogs are created equal. These earn their place because they publish original research, not product marketing.

Wiz Research

Cloud-native vulnerability research; the team behind several of the bigger cloud-CVE disclosures of the last few years.

BlogCloudResearch

Orca Security Research

Counterpart to Wiz โ€” original cloud research with well-written write-ups.

BlogCloudResearch

Datadog Security Labs

Stratus Red Team comes from this team; consistently good detection content.

BlogDetectionResearch

AWS Security Blog

The first-party reference. Subscribe.

BlogAWSFirst-Party

Microsoft Security Blog

Defender / Sentinel / Entra updates plus MSTIC threat intelligence.

BlogAzureFirst-Party

Google Cloud Threat Intelligence

Mandiant + GCP. Probably the strongest threat-intel blog in cloud right now.

BlogGCPThreat Intel

Palo Alto Unit 42

Threat research with strong cloud and container coverage.

BlogThreat IntelContainers

SentinelLabs

Adjacent but high-quality, especially on offensive tooling.

BlogThreat IntelOffense

Individual blogs worth a feed slot

Summit Route

Scott Piper. The flAWS author. Long-form AWS security analysis.

BlogAWSLong-form

marcolancini.it

Marco Lancini. Same voice as the newsletter, longer pieces.

BlogCloudLong-form

awsteele.com

Aidan Steele. Surprising and frequently eyebrow-raising AWS findings.

BlogAWSDeep-dive

kellyshortridge.com

Kelly Shortridge. Resilience engineering applied to security; required reading if you work on detection or program design.

BlogResilienceStrategy

Phil Venables

Google CISO. CISO-altitude essays; especially good on board-level security communication.

BlogStrategyCISO

Securosis

Rich Mogull and team. Cloud security commentary from someone who's been at it longer than most of the field.

BlogCloudLong-form
Cozy workspace setup with a laptop, book, and coffee cup on a wooden desk
Photo by Kaboompics on Pexels
A woman wearing headphones engaged in podcasting indoors by a window
Photo by Kaboompics on Pexels

Podcasts

Cloud Security Podcast

Ashish Rajan. The big one for our space. Practitioner interviews, vendor-fair, weekly.

PodcastCloudWeekly

Risky Business

Patrick Gray. Long-running, broader security but the news roundups are unmatched.

PodcastNewsWeekly

Darknet Diaries

Jack Rhysider. Narrative storytelling. The episodes on cloud breaches (Capital One, Code Spaces) are required listening.

PodcastStorytellingBreaches

Defense in Depth / CISO Series

David Spark. Cross-cutting security topics with senior practitioners.

PodcastCISOStrategy

SANS Internet Storm Center StormCast

Five-minute daily threat brief. Lowest possible activation energy.

PodcastThreat IntelDaily

Click Here

Recorded Future News. Polished journalism, weekly.

PodcastJournalismWeekly

People to follow on X / Bluesky / LinkedIn

A short, opinionated list of practitioners who consistently publish things worth reading. Many of these folks post the same content on multiple platforms; we note where they're most active. Search the name on the platform โ€” the well-known ones surface immediately. PRs welcome to add or update.

Cloud security depth

Detection, IR & offense

AppSec & DevSecOps

Strategy, leadership, broader security

Cloud journalism worth following

Three hours intentionally split across formats beats ten hours of doom-scrolling X. โ€” the recommended weekly split, above

Papers, frameworks & canonical reads

The handful of documents you'll keep returning to. All free.

Contribute or correct

This list is intentionally short and intentionally opinionated. It will go stale unless the community keeps it honest:

Where next