# The Cybersecurity Publications AI Engines Actually Cite

> A cybersecurity pitch list built from observed AI citations, split by the question a buyer asked, with the vendor-run properties competing for the same slots.

- Published: 2026-09-18
- URL: https://christianlehman.com/blog/cybersecurity-pr-pitch-list-ai-citations-2026
- Canonical: https://christianlehman.com/blog/cybersecurity-pr-pitch-list-ai-citations-2026
- Machine URL: https://christianlehman.com/blog/cybersecurity-pr-pitch-list-ai-citations-2026.md

---

If you pitch cybersecurity coverage to earn AI citations, the publications AI engines cited most in the cybersecurity category are TechTarget, TechRadar, TechRepublic, ITPro, The Hacker News and Cybersecurity News — but which one gets cited depends on the question the buyer asked. TechTarget leads when the question is "is this worth it." TechRadar and TechRepublic lead when the question is "what are the best tools." Those are different slots, and one pitch list does not win both.

That is the part most media plans get wrong. We build one tier list, rank outlets by prestige, and pitch the same story everywhere. The engines do not read outlets that way. They pick sources per question type, and the winner changes every time the question changes.

## The pitch list is six lists, not one

The Machine Relations Index measures which source domains six answer engines cite when people ask real buying questions. Release `mri_score_v2.0+2026-09-18+8fa38e54dd0a` covers 2026-05-10 to 2026-09-18, 15,782 observed answer runs, and it publishes all six cybersecurity question shapes at once ([Machine Relations Index](https://machinerelations.ai/index), [cybersecurity category](https://machinerelations.ai/index/categories/cybersecurity)).

A stratum publishes only after it clears the evidence floor: at least 10 observed runs across at least 7 distinct dates. Everything below is from a published stratum. I have cut each list at 5 or more cited runs, because below that a domain appeared once or twice and I would not stake a pitch on it.

Two more cuts, so you know what you are reading. This table carries the domains I can identify as established trade media. Domains in the same class that are operated by security vendors are in the next table, because you cannot pitch them. Each shape also cited smaller or unfamiliar domains at the same volume; I left those off rather than send an operator at a masthead I cannot vouch for.

| Buyer question | Publications the engines cited | Citation rate (cited runs / observed runs) |
| --- | --- | --- |
| Best tools ("best EDR platforms") | [TechRadar](https://www.techradar.com) #19, [TechRepublic](https://www.techrepublic.com) #24, [ITPro](https://www.itpro.com) #29 | 9.3% (7/75), 8.0% (6/75), 6.7% (5/75) |
| Is it worth it | [TechTarget](https://www.techtarget.com) #9, [Cybersecurity News](https://cybersecuritynews.com) #25, [The Hacker News](https://thehackernews.com) #29 | 13.0% (17/131), 6.1% (8/131), 6.1% (8/131) |
| How do I choose | [TechTarget](https://www.techtarget.com) #14, Medium #31 | 7.6% (10/131), 4.6% (6/131) |
| Head to head ("X vs Y") | [TechTarget](https://www.techtarget.com) #30 | 5.6% (6/107) |
| Problem first ("my EDR keeps alerting") | Medium #3, [TechRadar](https://www.techradar.com) #29 | 12.8% (16/125), 4.8% (6/125) |
| Top lists | [PR Newswire](https://www.prnewswire.com) #28 (a wire, not a pitch target), [TechRepublic](https://www.techrepublic.com) #55 | 6.9% (9/130), 4.6% (6/130) |

Rank is position in that stratum's full cited universe, which runs from 189 to 325 domains depending on the question. Live per-shape tables sit at [cybersecurity / best tools](https://machinerelations.ai/index/categories/cybersecurity/best_x) and [cybersecurity / is it worth it](https://machinerelations.ai/index/categories/cybersecurity/is_x_worth).

## TechTarget is the one outlet that carries the money question

TechTarget shows up in three of the six shapes and holds the highest editorial position of any publication in the category: rank 9 on "is it worth it," cited in 17 of 131 observed runs. That is the shape where a buyer is talking themselves into or out of a purchase.

Its domain profile across the whole Index is [rank 19, grade B, cited by all six engines](https://machinerelations.ai/index/domains/techtarget.com). Six-engine breadth matters more than a single rate: it means a placement there is reachable from ChatGPT, Claude, Gemini, Google AI Mode, Google AI Overviews and Perplexity rather than from one of them.

If you get one cybersecurity placement this quarter, the decision is not which outlet is most prestigious. It is which buyer question you need to be present for, then the outlet that holds that question.

## Six of the domains on your pitch list are vendors

Here is the part that should change how you brief your agency. The Index classifies sources by role, and in cybersecurity the editorial-publication class includes media properties operated by security vendors and service providers competing in the same category:

| Domain | Where it ranks | Who runs it |
| --- | --- | --- |
| [splunk.com](https://www.splunk.com) | #21 is it worth it (9/131), #9 problem first (10/125) | Security vendor |
| [underdefense.com](https://underdefense.com) | #36 top lists (8/130), #8 problem first (11/125) | Managed security provider |
| [connectwise.com](https://www.connectwise.com) | #24 is it worth it (8/131) | Security and IT vendor |
| [securityscorecard.com](https://securityscorecard.com) | #28 is it worth it (8/131) | Security ratings vendor |
| [torq.io](https://torq.io) | #30 is it worth it (8/131) | Security automation vendor |
| [netwitness.com](https://www.netwitness.com) | #63 top lists (5/130), #21 head to head (7/107) | Security vendor |

On "is it worth it," four of the eight domains the engines cited at 6.1% or better are vendor-run. Splunk and UnderDefense both outrank TechRadar on "problem first."

An engine assembling an answer does not apply your tier list. It weighs a vendor's research blog against a trade publication on whatever it treats as evidence. So the competitor you are trying to displace in the answer is also publishing into the same slot, on their own domain, on their own schedule, with no pitch and no embargo.

## The shape decides the class, not just the outlet

This is not a cybersecurity quirk. Across all 85 published category-and-question cells in this release, I counted which class of source held the top cited position:

| Source class | Domains in the Index | Cited runs | Cited runs per domain | Top spots held (of 85) |
| --- | --- | --- | --- | --- |
| Community and social platforms | 27 | 4,314 | 159.8 | 24 |
| Editorial publications | 1,222 | 13,309 | 10.9 | 11 |
| Vendor-owned sources | 823 | 11,153 | 13.6 | 7 |
| Search and media platforms | 10 | 1,513 | 151.3 | 10 |

Twenty-seven community domains hold more than twice as many top spots as 1,222 editorial publications, and each one earns roughly fifteen times the cited runs of the average publication.

Editorial publications concentrate where they win. Their strongest shape is "best tools," where they hold the top spot in 4 of 13 categories — Forbes in consumer finance and consumer products, Medium in AI infrastructure, TechRadar in family software. In the categories where the "is it worth it," "problem first" and "head to head" strata are published, the top-cited source is a community platform, a vendor property, a market database, an academic source or a domain the taxonomy has not yet classified.

So when a CMO says "get us in a top-tier publication," the honest answer is: that buys the shortlist question. It does not buy the objection question, and the objection question is the one that stalls deals.

## What I would do on Monday

1. **Write down the buyer question, not the outlet.** Pick one of the six shapes. For most security vendors mid-funnel, it is "is it worth it" or "head to head."
2. **Pitch the outlet that holds that shape.** For "is it worth it," TechTarget first, then Cybersecurity News and The Hacker News. For "best tools," TechRadar, TechRepublic, ITPro.
3. **Audit the vendor properties in your slot.** Pull the six domains above, read what they published on your category, and write down what claim of theirs an engine is currently citing.
4. **Publish into your own slot.** Splunk and UnderDefense earned those positions with their own domains. That path is open to you and needs no pitch.
5. **Re-read the release before the next cycle.** The Index rebuilds daily and the per-shape tables move.

## The sales handoff

Give sales one sentence per placement, scoped to the question it covers, and say plainly what it does not cover:

> "We are cited in TechTarget's coverage of [category]. That is the source engines cite most when buyers ask whether this category is worth the spend. It does not mean we are named in head-to-head comparisons; that slot is currently held by [domain]."

Scope is what keeps a visibility result from being asked to do a job it was not built for. A citation in one question shape is evidence of presence in that shape and nothing else.

## FAQ

**Is this a ranking of the best cybersecurity publications?**
No. It measures how often six answer engines cited each domain when answering cybersecurity buying questions between 2026-05-10 and 2026-09-18. Editorial quality, audience and reach are separate questions.

**Why is Medium on a cybersecurity pitch list?**
Because the engines cited it. Medium holds rank 3 on the "problem first" shape at 12.8%, which reflects practitioner write-ups of specific incidents and fixes. It is not an outlet you pitch; it is a format that competes for the same slot.

**Does a placement cause a citation?**
Not proven. The Index records which domains engines cited, not why. Treat the list as where citations are currently concentrated, and measure your own outcome after a placement rather than assuming one.

**Why do vendor domains appear in the editorial class?**
The Index classifies by observed source role and publishes the class as measured. Several security vendors and managed providers run substantial media properties, and engines cite them alongside trade publications.

**How often does this change?**
The Index rebuilds daily. This release added 153 domains and 859 citation events over the previous day's build. Per-shape leaders move more slowly than that, but re-read before committing a quarter's pitching.

## Why this is a Machine Relations problem

Machine Relations is the practice of managing the relationship between your brand and the machines that answer questions about it. A pitch list is a media artifact. A citation slot is a machine-relations artifact, and it is defined by the question shape, not by the masthead.

The instrument behind every number above is the public [Machine Relations Index](https://machinerelations.ai/index), which measures the market's source selection rather than any one brand's performance. Read your category's shapes, decide which buyer question you need to hold, then earn or publish into that slot.

## Machine-readable related links

- [Canonical article](https://christianlehman.com/blog/cybersecurity-pr-pitch-list-ai-citations-2026)
- [Blog index](https://christianlehman.com/blog)
- [Machine sitemap](https://christianlehman.com/machine-sitemap.json)
- [LLM instructions](https://christianlehman.com/llms.txt)

---

*Machine-readable version of [The Cybersecurity Publications AI Engines Actually Cite](https://christianlehman.com/blog/cybersecurity-pr-pitch-list-ai-citations-2026)*
