Conisec names the people who write here, and says plainly what each of them does. This page is generated from our actual contributor records, so it cannot drift away from who really holds a byline.
How bylines work
Analysis, guides and reported pieces carry a named contributor. Compiled factual records — Incident Tracker entries, jurisdiction field sets, sourced timelines — publish under the Conisec Staff newsroom byline, because the work there is assembly and verification rather than authorship. Both are explained in our editorial guidelines.
Contributors listed above joined recently, and most published work still sits under the newsroom byline. We do not backdate attribution: a byline moves onto a piece only when that person actually wrote it.
Who is accountable for what
A masthead is only useful if it answers one question: when this publication states something, who is answerable for it?
- Every factual claim traces to a primary source — the affected project’s own disclosure, an on-chain transaction, a regulator’s published instrument, or a filing. If a claim cannot be traced, it does not publish.
- A human editor checks the claim against that source before it goes live. That step is not delegated, and it is what the byline attests to.
- Errors are corrected in public and dated, and incident timelines are append-only. See corrections.
Why there are no pseudonymous bylines
Pseudonymity is normal in this industry and we understand why. We still do not use it for bylines, for a reason specific to what we cover: the value of a security or compliance claim depends heavily on who is making it and what they can be held to. A pseudonym can build a reputation, but it cannot be held to a professional record, and it can be abandoned the moment being wrong becomes expensive.
Sources are a separate matter and may be protected — the conditions are in our ethics policy.
What we publish about a contributor
A contributor page carries their real name, their actual role, and a biography that is true and specific enough to check. We do not inflate a title: someone who has just joined is listed as a contributor, not as a correspondent. Credentials appear only where we have verified them, and photographs only where the contributor has supplied one they own — several profiles currently show generated initials for that reason.
Anything we cannot verify is omitted rather than softened. On a security and compliance publication the author’s credentials are part of the product, and an unverifiable credential is worse than none.
Joining
If you would like to contribute, see write for us.