Interview Format Revisited: What Changed in Security-Practitioner Interviews 2014 to 2026
When I started this blog in 2008, the security-practitioner interview was a Q&A blog post. You emailed someone in the community, they wrote back with answers, you cleaned up the markdown, you published. That was the format for about ten years.
I want to look at what happened to that format between roughly 2014 and 2026. Not to be nostalgic about it. The shift matters because it changed who gets interviewed, what gets asked, and what gets read. As a CMS-security person who has both sat for these interviews and conducted them, I have watched the form mutate through five or six successive trends, and the latest one is worth a paragraph or two.
2014-2016: The Podcast Migration
The first big move was from written Q&A to audio. Risky.Biz, Down the Security Rabbithole, Defensive Security Podcast, Smashing Security a bit later. Practitioners stopped writing answers and started talking through them. This was good for the audience that could listen to an hour of conversation in the gym. It was less good for the audience that wanted to scan, copy a quote, or fact-check a claim against a primary source.
A side effect was that the interviewer’s voice mattered more. A written Q&A could be edited heavily. A 50-minute podcast is mostly the interviewer’s frame and follow-ups. Some podcasts were thoughtful about this and reached out to underrepresented voices. Others ended up rotating through the same dozen vendor-affiliated guests because they were the ones who would commit to a weekly cadence.
2017-2019: LinkedIn Long-Form and Medium
A parallel trend was the migration of written interviews to LinkedIn long-form posts and Medium. The format was the same as a 2010 blog interview, but the publishing surface was different. The benefit was reach. The cost was that the interview became one item in a feed of vendor-marketing posts and conference-summary content, and the reader’s attention budget for any single piece dropped to scan-and-move-on.
Around 2018 I noticed that the half-life of a published security interview compressed from “still useful 18 months later” to “stops getting visits after week 2”. The content was no worse. The discovery layer changed.
2020-2022: The Pandemic Cohort
When most conferences went virtual, a lot of conference Q&As migrated to YouTube. The “interview at the booth” format was replaced with the “interview in a Zoom call recorded and edited later” format. This was fine. The interesting shift was that the talent pool for interviewees broadened: people who had never travelled for conferences started agreeing to remote interviews. Some of the most interesting practitioners I have read in this period were people who would never have appeared at Black Hat in person.
The downside was that the production value dropped to “screen recording” for a lot of these. Audio quality varied. Some of the technical content was excellent but unwatchable because someone’s audio level was clipping for the entire 40 minutes.
2023-2024: The Substack Wave
Independent newsletters became the new home for the practitioner Q&A. Substack made it easy to publish, monetise via paid tiers, and avoid platform algorithms. A small number of security-focused newsletters built real audiences: Risky Bulletin, Detection at Scale, Black Hills Information Security’s weekly digest. These often included interview content, sometimes as featured Q&As, sometimes as roundtable discussions.
The interviewing format inside these newsletters was tighter than it had been on blogs. Word budgets were shorter. Quotes were edited down to one or two clean lines. The “long, meandering, technically rich” interview I used to publish on this blog in 2009 simply does not fit a newsletter format. Whether that is a loss depends on whether you valued the meandering or the density.
2025-2026: AI Transcription and the Format Question
The current shift is AI-transcribed and AI-summarised interviews. A practitioner has a 45-minute conversation. The recording is transcribed automatically. A summary is generated. The published artefact is sometimes the summary, sometimes the summary plus selected quotes, occasionally the full transcript with light editing.
The honest assessment is that some of this is excellent. AI transcription is now accurate enough that the transcript reads like prose. AI summaries are now consistent enough that the gist of a conversation is faithfully represented. For the reader who wants the headline takeaways from someone’s hour-long thinking, this is a strict improvement on hunting for them inside a Spotify episode.
What gets lost in this format is two things. First, the texture of the interview - the moment where a question landed wrong and the interviewee paused, the moment they corrected themselves halfway through an answer, the moment they laughed because they realised they were saying the same thing they had said five years earlier. The summary smooths this out. Second, the unique phrasing. AI summaries converge on a similar prose style across publications. The way one CMS practitioner would word an answer is no longer the way that practitioner sounds in the published artefact.
I do not think the AI-summary format is going away. I think it will coexist with longer-form formats that preserve the texture, and we will see more publications offering both: the 5-minute AI summary at the top, the 45-minute raw transcript or audio at the bottom, the reader picks what they want.
What This Means for CMS Security Specifically
The reason I started thinking about this was a pattern I noticed in 2024: there are very few interviews being published with CMS-security practitioners specifically. The interview circuit moved upmarket - CISOs, threat-intel leads, AI-safety researchers - and the people who actually maintain WordPress and Joomla sites do not get featured in the newsletters and podcasts that drive the conversation.
This matters because most websites in the world are still running on a CMS, the security advice for those websites is mostly produced by practitioners who are not getting interviewed, and the interview format used to be one of the main ways that practical CMS knowledge got transmitted from one administrator to the next.
I do not have a clean fix for this. What I can do, and what I plan to do over the next year on this blog, is run a small number of slow, written, long-form Q&As with CMS-security people who are doing the actual work. No podcast, no AI summary, no Substack newsletter. The 2010 format, applied to 2026 practitioners. We will see if anyone reads them.
If you would like to be interviewed for this series, or you can nominate a CMS-security practitioner you think should be, the contact form on this site still works. The format is going to be the same as it was in 2009: I will email you about ten questions, you write back when you have time, I will edit lightly and publish.