Research publishing
- Threat reports and vulnerability write ups that show their method. A researcher takes the calls.
Month to month. Cancel any month. See pricing
Pocket PR is a cybersecurity PR agency for security vendors and research teams who sell trust for a living.
The team works remotely from Kyiv and Brno. Security reporters test your indicators. They also call your competitors, and they remember every exaggeration.
We publish research that survives that test and get you ready before your own bad day.

Illustration
A general tech agency pitches features and funding.
A cybersecurity PR firm spends most of its time on three other jobs that look more like research publishing than advertising.
Product news gets its turn after them.
Our lead expert ran the communications strategy of Octava Defence, a Ukrainian cybersecurity operator, from 2018 to 2021, by her own profile.
Publicity never runs ahead of disclosure.
A vendor that pitches a flaw before the fix lands loses the affected company's trust, and usually the reporter's too.
Our calendar works backwards from the disclosure date under public norms reporters know well.
How vendors receive and publish vulnerability reports.
Reported flaws go public 45 days after the first report whether a patch exists or not.
Plus 14 days grace if a fix is close, or 7 days when a flaw is exploited in the wild.
They lift at the same hour as the advisory.

When the breach is yours, several legal clocks start at once and your public words must not contradict any filing.
We write every statement from one source document, so the customer email says what the reporter Q and A says.
| Jurisdiction | Rule | Deadline |
|---|---|---|
| United States | Listed companies file Form 8-K Item 1.05 describing what happened and its impact | Four business days after deciding an incident is material |
| European Union NIS2 | Essential and important entities report to their CSIRT or authority | Early warning within 24 hours, notification within 72 hours, final report within a month |
| European Union Cyber Resilience Act | Manufacturers of products with digital elements report actively exploited vulnerabilities. Security vendors are included | From 11 September 2026 |
| GDPR | Personal data breaches go to the data protection authority | Within 72 hours |
Security desks reward evidence and punish hype.
Words like unhackable end careers on this beat, and so does naming a victim who has not disclosed. These angles get replies.
The security calendar has two peaks that serve different stories. RSAC in San Francisco each spring is commercial.
Buyers walk the floor, and a launch needs a named customer or a hard number to be heard.
Black Hat and DEF CON in early August are about research, with briefings booked weeks ahead under embargo.
A product launch at DEF CON usually backfires.

Illustration
Spring at Moscone Center in San Francisco
RSAC Conference
The largest vendor show in security. Funding and product news clusters that week, so only a story with data cuts through
Early August in Las Vegas
Black Hat USA
Accepted research talks are news on their own, and reporters pre-book briefings with speakers weeks ahead
Right after Black Hat in Las Vegas
DEF CON
The hacker community's own event. Hands on research earns respect there, while a sales pitch gets a cold room
8 to 10 June 2027 at ExCeL London
Infosecurity Europe
The main UK and European practitioner show, good for a first UK customer or a UK research story
27 to 29 October 2026 in Nuremberg
it-sa Expo and Congress
German speaking buyers meet their trade press here. In 2025 it had 993 exhibitors and 28,260 visitors
US trade desks write for US buyers.
A vendor from Warsaw or Kyiv stays invisible there until it has a US reason to exist, and three reasons work.
A US vendor entering Germany faces the mirror problem, starting with data residency questions.
Counting clippings says little in security.
A quarterly report lists these signals with the source of each mention, so the board sees what moved and what did not.
Everything PR puts US mid-sized agencies with a tech specialty at $10,000 to $25,000 a month, usually with a three to six month minimum.
Pocket PR takes on a research launch or a disclosure calendar from $390 a month and adds incident readiness and a second market at $890.
A live breach is scoped on a call. Market rates are on how much PR costs.

Research news is dated to the disclosure day agreed with the affected vendor and the CERT. Never earlier. The embargo list is built around that date.
Each research story ships with its method and sample size, plus a researcher who can take technical follow ups on the phone.
Holding statements for a breach of your own systems, written before you need them and timed to whichever legal clock applies to you.

Enterprise security and the threat research behind it, with CISO commentary
Online daily with newsletters
Vulnerabilities in industrial systems, plus security funding deals
Online daily with online summits
Nation state operations and how governments respond to them
Newsroom run by Recorded Future News
Fast news on live ransomware campaigns and the patches that follow
Online daily with forums
US federal cyber policy as CISA and Congress shape it
Online daily from Washington
UK and European security news with practitioner opinion
Online and print, linked to Infosecurity Europe
Product categories explained for security practitioners
Online with its own podcasts
Blunt analysis of breaches and vendor mistakes
Online daily from London and San Francisco
Weekly security news and long interviews with researchers and CISOs
Podcast by Patrick Gray
Cybercrime investigations into fraud rings, reported by Brian Krebs
Investigative blog
Research reports and CISO interviews
Online daily with a newsletter
How CISOs set budgets and hire
Online publication by Foundry
Questions
It publishes threat research in a form security reporters can verify and dates it to coordinated disclosure. It also prepares the statements a vendor needs on the day it is breached itself.
After coordinated disclosure, on the date agreed with the affected vendor or the CERT handling the case. Public deadlines such as the CERT Coordination Center's 45 days set the outer limit, and the story never runs before the advisory.
Only if it has disclosed the incident itself or agreed. Naming victims hurts your credibility with buyers and can expose you legally. Reporters respect vendors who protect victims.
It depends on the regime. A US listed company files an 8-K within four business days of judging an incident material. NIS2 entities send an early warning within 24 hours. GDPR requires notice to the data authority within 72 hours. The public statement should match those filings word for word.
For a product, RSAC, because buyers walk that floor. For research, Black Hat, where reporters come for findings and book speakers in advance.
Most trade reporters do for research with real data, provided the embargo is short and fixed. They will not hold a story about an active campaign that puts readers at risk.
Read next
Next step
Defense, energy and large programs. A mutual NDA before any confidential brief.