Month to month. Cancel any month. See pricing

Get a PR diagnosisGet a 15-minute PR diagnosis

Cybersecurity PR agency

Pocket PR is a cybersecurity PR agency for security vendors and research teams who sell trust for a living.

The team works remotely from Kyiv and Brno. Security reporters test your indicators. They also call your competitors, and they remember every exaggeration.

We publish research that survives that test and get you ready before your own bad day.

Cybersecurity PR agency

Illustration

Breach costs and disclosure clocks

  • $4.99Mglobal average cost of a data breach, record highibm.com
  • 45 daysCERT Coordination Center default before a reported flaw goes publiccertcc.github.io
  • 4 daysbusiness days for a US listed company to file an 8-K on a material incidentsec.gov

What a cybersecurity PR firm does that a tech agency does not

A general tech agency pitches features and funding.

A cybersecurity PR firm spends most of its time on three other jobs that look more like research publishing than advertising.

Product news gets its turn after them.

Our lead expert ran the communications strategy of Octava Defence, a Ukrainian cybersecurity operator, from 2018 to 2021, by her own profile.

Research publishing

  • Threat reports and vulnerability write ups that show their method. A researcher takes the calls.

Disclosure timing

  • News about a flaw is dated to the coordinated disclosure agreed with the vendor and often a national CERT.

Incident readiness

  • A breached security company gets the harshest coverage, so its statements must match its legal filings.

Responsible disclosure rules that shape security PR

Publicity never runs ahead of disclosure.

A vendor that pitches a flaw before the fix lands loses the affected company's trust, and usually the reporter's too.

Our calendar works backwards from the disclosure date under public norms reporters know well.

  1. ISO and IEC 29147

    How vendors receive and publish vulnerability reports.

  2. CERT Coordination Center, 45 days

    Reported flaws go public 45 days after the first report whether a patch exists or not.

  3. Google Project Zero, 90 days

    Plus 14 days grace if a fix is close, or 7 days when a flaw is exploited in the wild.

  4. Briefings under a short embargo

    They lift at the same hour as the advisory.

What security reporters cover, campaigns, vulnerabilities, defenses and infrastructure
Same hour as the advisorySet the embargo to lift at the minute the vendor advisory goes live. A reporter who publishes first and links to nothing looks careless, and blames you for it.

Incident disclosure deadlines for security companies

When the breach is yours, several legal clocks start at once and your public words must not contradict any filing.

We write every statement from one source document, so the customer email says what the reporter Q and A says.

JurisdictionRuleDeadline
United StatesListed companies file Form 8-K Item 1.05 describing what happened and its impactFour business days after deciding an incident is material
European Union NIS2Essential and important entities report to their CSIRT or authorityEarly warning within 24 hours, notification within 72 hours, final report within a month
European Union Cyber Resilience ActManufacturers of products with digital elements report actively exploited vulnerabilities. Security vendors are includedFrom 11 September 2026
GDPRPersonal data breaches go to the data protection authorityWithin 72 hours

Cybersecurity PR angles that earn coverage

Security desks reward evidence and punish hype.

Words like unhackable end careers on this beat, and so does naming a victim who has not disclosed. These angles get replies.

  • Original data with a method. How many exposed devices you found and over which dates, with the method shown.
  • A named researcher on the phone instead of a brand.
  • A talk accepted at Black Hat or DEF CON, which is news in itself.
  • A plain explanation of the CRA reporting duties that started in September 2026.
  • Fast commentary on a breaking incident that adds a fact the reporter does not have yet.

How to plan a security launch around RSAC and Black Hat

The security calendar has two peaks that serve different stories. RSAC in San Francisco each spring is commercial.

Buyers walk the floor, and a launch needs a named customer or a hard number to be heard.

Black Hat and DEF CON in early August are about research, with briefings booked weeks ahead under embargo.

A product launch at DEF CON usually backfires.

Security conference expo hall before the doors open

Illustration

Security shows worth a briefing slot

  1. Spring at Moscone Center in San Francisco

    RSAC Conference

    The largest vendor show in security. Funding and product news clusters that week, so only a story with data cuts through

  2. Early August in Las Vegas

    Black Hat USA

    Accepted research talks are news on their own, and reporters pre-book briefings with speakers weeks ahead

  3. Right after Black Hat in Las Vegas

    DEF CON

    The hacker community's own event. Hands on research earns respect there, while a sales pitch gets a cold room

  4. 8 to 10 June 2027 at ExCeL London

    Infosecurity Europe

    The main UK and European practitioner show, good for a first UK customer or a UK research story

  5. 27 to 29 October 2026 in Nuremberg

    it-sa Expo and Congress

    German speaking buyers meet their trade press here. In 2025 it had 993 exhibitors and 28,260 visitors

Security PR for European vendors selling to the US

US trade desks write for US buyers.

A vendor from Warsaw or Kyiv stays invisible there until it has a US reason to exist, and three reasons work.

A US vendor entering Germany faces the mirror problem, starting with data residency questions.

A US customer on the record

  • Named, speaking to a US trade desk.

Research with US data

  • A threat that hits US organisations, shown in US numbers.

A CRA policy angle

  • What the Cyber Resilience Act changes for US vendors selling into Europe.

How to measure cybersecurity PR

Counting clippings says little in security.

A quarterly report lists these signals with the source of each mention, so the board sees what moved and what did not.

  • Trade outlets that cited your research with a link to the method.
  • Your researcher called back for comment on the next incident.
  • Inbound requests from CISOs or analysts who named the article.
  • How AI assistants describe your company when a buyer asks who covers a threat.

How much a cybersecurity PR agency costs

Everything PR puts US mid-sized agencies with a tech specialty at $10,000 to $25,000 a month, usually with a three to six month minimum.

Pocket PR takes on a research launch or a disclosure calendar from $390 a month and adds incident readiness and a second market at $890.

A live breach is scoped on a call. Market rates are on how much PR costs.

Rising bars for cybersecurity PR prices from research launch to incident readiness
Rising bars for cybersecurity PR prices from research launch to incident readiness

Where the monthly security work goes

  1. Disclosure calendar

    Research news is dated to the disclosure day agreed with the affected vendor and the CERT. Never earlier. The embargo list is built around that date.

  2. Proof pack

    Each research story ships with its method and sample size, plus a researcher who can take technical follow ups on the phone.

  3. Incident drafts

    Holding statements for a breach of your own systems, written before you need them and timed to whichever legal clock applies to you.

A phishing kit found in Kraków

A phishing kit found by a small email security vendor

Situation
A 20 person email security company in Kraków finds a phishing kit that copies the login pages of European freight exchanges. It wants coverage but some victims are still compromised.
What we do
The kit is reported to the affected platforms and the national CERT first. No victim is named. On the agreed date the company publishes indicators with a method note. BleepingComputer and Infosecurity Magazine get an embargoed briefing, and the researcher is offered to Risky Business.
Outcome
This is an illustrative scenario, not a client result. It shows the sequence that keeps a vendor credible. Report first, then wait, then publish with proof.
Security founder marking a disclosure timeline on the wall above her laptop late in the day
Victims stay unnamedIf a victim later discloses on its own, the vendor can refer to that public statement. Until then the research describes the sector, never the company.Crisis communicationsIllustration

Security desks and podcasts that test claims

  • Dark Reading

    Enterprise security and the threat research behind it, with CISO commentary

    Online daily with newsletters

  • SecurityWeek

    Vulnerabilities in industrial systems, plus security funding deals

    Online daily with online summits

  • The Record

    Nation state operations and how governments respond to them

    Newsroom run by Recorded Future News

  • BleepingComputer

    Fast news on live ransomware campaigns and the patches that follow

    Online daily with forums

  • CyberScoop

    US federal cyber policy as CISA and Congress shape it

    Online daily from Washington

  • Infosecurity Magazine

    UK and European security news with practitioner opinion

    Online and print, linked to Infosecurity Europe

  • SC Media

    Product categories explained for security practitioners

    Online with its own podcasts

  • The Register, security desk

    Blunt analysis of breaches and vendor mistakes

    Online daily from London and San Francisco

All 12 outlets
  • Risky Business

    Weekly security news and long interviews with researchers and CISOs

    Podcast by Patrick Gray

  • Krebs on Security

    Cybercrime investigations into fraud rings, reported by Brian Krebs

    Investigative blog

  • Help Net Security

    Research reports and CISO interviews

    Online daily with a newsletter

  • CSO Online

    How CISOs set budgets and hire

    Online publication by Foundry

Anastasiia Bratkova portrait

Anastasiia Bratkova

Chief Brand, Marketing & Communications Officer, RSE

Signs every pitch

About Anastasiia

Questions

What security founders ask about press

What does a cybersecurity PR agency do?

It publishes threat research in a form security reporters can verify and dates it to coordinated disclosure. It also prepares the statements a vendor needs on the day it is breached itself.

When can we publish research about a vulnerability?

After coordinated disclosure, on the date agreed with the affected vendor or the CERT handling the case. Public deadlines such as the CERT Coordination Center's 45 days set the outer limit, and the story never runs before the advisory.

Can we name the company that was breached?

Only if it has disclosed the incident itself or agreed. Naming victims hurts your credibility with buyers and can expose you legally. Reporters respect vendors who protect victims.

How fast must a breached company make a statement?

It depends on the regime. A US listed company files an 8-K within four business days of judging an incident material. NIS2 entities send an early warning within 24 hours. GDPR requires notice to the data authority within 72 hours. The public statement should match those filings word for word.

Is Black Hat or RSAC better for a security launch?

For a product, RSAC, because buyers walk that floor. For research, Black Hat, where reporters come for findings and book speakers in advance.

Do security reporters accept embargoes?

Most trade reporters do for research with real data, provided the embargo is short and fixed. They will not hold a story about an active campaign that puts readers at risk.

Sources

Next step

Talk to the team

Defense, energy and large programs. A mutual NDA before any confidential brief.

Write in Telegram