All press releases

For Reporters

Expert commentary and named-source availability.

Yolonda Smith is available for on-record commentary on cybersecurity, third-party risk, and cyber diligence in M&A. Phone or video, framework-anchored responses, and a clear answer to what she does and does not have an opinion on.

Media inquiries and briefing requests: [email protected]

Coverage areas

Small and mid-market cybersecurity. SMB and mid-market security posture, breaches, and operating patterns. Practitioner-side commentary from senior roles at Target (post-2013 incident response), Grubhub, sweetgreen, and Pwnie Express. Not Fortune-100 headline commentary — the 33-million-US-business tier that most cyber coverage misses.

Third-party and vendor incident response. When a vendor gets breached, what should their customers do in the next 72 hours? Author of Someone Else’s Breach: A Practitioner’s Guide to Third-Party Risk & Incident Management (Amazon, 2026). Framework: DC-TPIR (Dependency-Centric Third-Party Incident Response), covered in a peer-reviewed SSRN working paper. Four failure modes (CIA + Control) and a four-option decision framework (Accept / Mitigate / Reduce / Exit).

Cyber diligence in M&A. Quantitative cyber-risk analysis for private equity deals and corporate development. Author of Someone Else’s Debt: A Quantitative Framework for Cyber Diligence at Deal Speed (Amazon, 2026). Framework: QCD (Quantitative Cyber Diligence), a five-pillar methodology producing a Cyber Cost of Deal (CCOD) dollar output that modifies valuation. Coverage angle: what PE cyber diligence looks like when it stops being a 40-page questionnaire and becomes a defensible number an IC can price against.

GRC platforms and compliance automation. SOC 2, ISO 27001, HIPAA, PCI DSS, GDPR, NIST CSF, FedRAMP, CMMC — coverage grounded in what founders and lean compliance teams actually do at $299/mo tooling versus $200K/yr CISO hires. Competitive angle: Vanta, Drata, Secureframe, Sprinto, Thoropass — and where the SMB tier of the compliance-automation category is headed.

AI governance and ISO 42001.Practitioner take on the emerging AI assurance category. Not the ISO 42001 explainer piece — the part covering what audit-grade evidence for agentic AI actually has to look like, how the assurance model is a graph not a line, and where “trustworthy AI” claims start to fall apart under audit.

What to expect

  • Response time. Within 4 business hours during active news cycles when a story is breaking. Same or next business day for evergreen features and background briefings.
  • Format.Phone, Zoom, or async email — reporter’s preference. If a story needs a same-day quote, phone is fastest.
  • On-record by default. Yolonda is available on-record with attribution. Off-record briefings are possible for context calls but should be arranged in advance.
  • Framework citations. When commentary references QCD, CCOD, or DC-TPIR, the underlying methodology is published in book and peer-reviewed form — reporters can cite the methodology by name and link to the source material.
  • No embargo negotiation on standing coverage. Yolonda doesn’t gate expert commentary on outlet-tier considerations. If you have a story that fits the coverage areas above, ask.

Credentials and anchor publications

Prior coverage

Recent published Q&A commentary. For embargo, exclusive, or on-the-record interviews, reach out via [email protected].

Not the right source for

To keep pitch-fit high, the topics below are outside Yolonda’s beat. She’s happy to refer to other analysts and practitioners who cover them if useful — just ask.

  • Consumer tech breaches
  • Cryptocurrency or Web3 security
  • Nation-state or advanced-persistent-threat commentary (there are better sources for that beat)
  • General business or non-security topics

Book a briefing or ask a question

Email [email protected] with the story angle, deadline, and preferred call time window (with time zone). For general company or product questions, the press index lists formal releases and company boilerplate.