For Reporters
Expert commentary and named-source availability.
Yolonda Smith is available for on-record commentary on cybersecurity, third-party risk, and cyber diligence in M&A. Phone or video, framework-anchored responses, and a clear answer to what she does and does not have an opinion on.
Media inquiries and briefing requests: press@vcisolite.com
Coverage areas
Small and mid-market cybersecurity. SMB and mid-market security posture, breaches, and operating patterns. Practitioner-side commentary from senior roles at Target (post-2013 incident response), Grubhub, sweetgreen, and Pwnie Express. Not Fortune-100 headline commentary — the 33-million-US-business tier that most cyber coverage misses.
Third-party and vendor incident response. When a vendor gets breached, what should their customers do in the next 72 hours? Author of Someone Else’s Breach: A Practitioner’s Guide to Third-Party Risk & Incident Management (Amazon, 2026). Framework: DC-TPIR (Dependency-Centric Third-Party Incident Response), covered in a peer-reviewed SSRN working paper. Four failure modes (CIA + Control) and a four-option decision framework (Accept / Mitigate / Reduce / Exit).
Cyber diligence in M&A. Quantitative cyber-risk analysis for private equity deals and corporate development. Author of Someone Else’s Debt: A Quantitative Framework for Cyber Diligence at Deal Speed (Amazon, 2026). Framework: QCD (Quantitative Cyber Diligence), a five-pillar methodology producing a Cyber Cost of Deal (CCOD) dollar output that modifies valuation. Coverage angle: what PE cyber diligence looks like when it stops being a 40-page questionnaire and becomes a defensible number an IC can price against.
GRC platforms and compliance automation. SOC 2, ISO 27001, HIPAA, PCI DSS, GDPR, NIST CSF, FedRAMP, CMMC — coverage grounded in what founders and lean compliance teams actually do at $299/mo tooling versus $200K/yr CISO hires. Competitive angle: Vanta, Drata, Secureframe, Sprinto, Thoropass — and where the SMB tier of the compliance-automation category is headed.
AI governance and ISO 42001.Practitioner take on the emerging AI assurance category. Not the ISO 42001 explainer piece — the part covering what audit-grade evidence for agentic AI actually has to look like, how the assurance model is a graph not a line, and where “trustworthy AI” claims start to fall apart under audit.
What to expect
- Response time. Within 4 business hours during active news cycles when a story is breaking. Same or next business day for evergreen features and background briefings.
- Format.Phone, Zoom, or async email — reporter’s preference. If a story needs a same-day quote, phone is fastest.
- On-record by default. Yolonda is available on-record with attribution. Off-record briefings are possible for context calls but should be arranged in advance.
- Framework citations. When commentary references QCD, CCOD, or DC-TPIR, the underlying methodology is published in book and peer-reviewed form — reporters can cite the methodology by name and link to the source material.
- No embargo negotiation on standing coverage. Yolonda doesn’t gate expert commentary on outlet-tier considerations. If you have a story that fits the coverage areas above, ask.
Credentials and anchor publications
- Books. Someone Else’s Debt: A Quantitative Framework for Cyber Diligence at Deal Speed (2026) and Someone Else’s Breach: A Practitioner’s Guide to Third-Party Risk & Incident Management (2026).
- Peer-reviewed paper. DC-TPIR: A Dependency-Centric Framework for Quantitative Third-Party Incident Response (SSRN working paper, March 2026).
- Background. 20 years in cybersecurity leadership. Senior security roles at Target (post-2013 breach response), Grubhub, sweetgreen, and Pwnie Express. U.S. Air Force veteran (8 years). CISSP, CISM, GCIH, GSEC. MS Information Technology, BS Computer Science.
- Speaking. TEDx, DevOpsDays MSP, and Grace Hopper speaker.
Prior coverage
Prior coverage will be listed here as pieces land. If you’ve worked with Yolonda before and want a specific piece linked, email press@vcisolite.com.
Not the right source for
To keep pitch-fit high, the topics below are outside Yolonda’s beat. She’s happy to refer to other analysts and practitioners who cover them if useful — just ask.
- Consumer tech breaches
- Cryptocurrency or Web3 security
- Nation-state or advanced-persistent-threat commentary (there are better sources for that beat)
- General business or non-security topics
Book a briefing or ask a question
Email press@vcisolite.com with the story angle, deadline, and preferred call time window (with time zone). For general company or product questions, the press index lists formal releases and company boilerplate.