Subreddit guide

r/cybersecurity: rules, karma requirements and posting culture

A 1.5 million member forum for working security professionals: news, vulnerabilities, business security questions and careers. Heavily filtered and wary of marketers.

cybersecurity · Open on Reddit

Members
1.5M
Created
2012
New posts a day
74.9
Comments on a typical post
8
New posts removed
54%

The short answer

r/cybersecurity publishes no karma or account age number, but it is one of the harder rooms to post in: only about 46% of new posts in our sample stayed up, and AutoModerator held roughly 31% for review. Posts are text or links only, and every one carries a flair. Beginner career questions are sent to the FAQ and the weekly Mentorship Monday thread, and personal or home security questions belong in r/cybersecurity_help. Promotion is capped at under 10% of your activity here and once a week per thing promoted.

Who posts here

Knowledge levelIntermediate to advanced

The rules describe the readers as cybersecurity professionals and say basic questions on security fundamentals are not appropriate. Threads use SOC, SIEM, EDR, GRC and CVE numbers without explanation. A how do I get started question gets an automatic pointer to the Breaking In FAQ and the mentorship thread, and posts under the starting-a-career flair were the bulk of moderator removals in our sample.

  • SOC analysts, security engineers and GRC staff asking how other organisations handle a control, a tool or an alert backlog.
  • Senior people and managers, up to CISO level, talking about breaches, budgets and what leadership expects.
  • IT staff and developers trying to move into security, plus students, who are steered to the mentorship thread.
  • Researchers and open source authors sharing a write-up or a tool.
  • Vendors and their content teams, who are expected to disclose the affiliation and use the Corporate Blog flair.

Karma and account requirements

What it takes to get a post through in r/cybersecurity.

KarmaNot stated publicly. No rule or AutoModerator message in our evidence names a number, but AutoModerator held about 31% of sampled posts and Reddit's filters removed another 17%.
Account ageNot stated publicly.
Post flairEvery post in our sample had one. Business Security Questions & Discussion is the most common at about 25%. The Starting Cybersecurity Career flair triggers an automatic redirect to the FAQ and the mentorship thread.Mods' wording: “You have used the "Starting Cybersecurity Career" flair.”
Read the FAQ firstQuestions the FAQ already answers are removed, which covers most how do I break in questions.Mods' wording: “posts containing questions which are answered in the FAQ will be removed”
Self-promotion ratioPromotion must be under 10% of your posts and comments in the subreddit, and no more than once a week per promoted entity.Mods' wording: “Once per week at most per promoted entity.”
LinksLink directly to the content. URL shorteners are blocked, some domains are banned outright, and you cannot link to pages that demand an email or sign-up to read.Mods' wording: “Link shorteners such as tinyurl.com are not allowed on this subreddit”

What AutoModerator says

The moderators' bot leaves these messages on posts. They are the closest thing to an official statement of the thresholds.

Hi! You have used the "Starting Cybersecurity Career" flair. If you are looking for advice or input on starting a career in cybersecurity, please read over our FAQ Breaking In to Cybersecurity. If you have questions after reading through that FAQ, please post your followups as well as what research you've done so far in the Mentorship Monday thread (pinned to the top of the subreddit) for assistance. Our community can gladly help you there! If you have additional questions, please reach out to the mods. Thank you for reading!
Hello. It appears as though you are looking for someone to review your resume. We suggest you go to /r/resumes, which is a subreddit created to fine tune your resume and can give you specific advice on what to fix or alter. If you believe that this post has been removed in error, please contact the mod team.
Please read this entire post. Your survey is currently sitting in the moderation queue will not be approved until you take action. You are welcome to post a survey here but you must adhere to our guidelines: * The survey must be purely academic. Corporate surveys, corporate-sponsored surveys, etc. are not permitted. * The survey must be completely anonymous. Nothing in it can link back to a user's real-world identity. * There can be no offers of compensation for taking the survey (e.g.: drawings, gift cards, etc.). * The survey must be specific to cybersecurity professionals. * The post must link directly to the survey. URL shorteners are not allowed. * You are required to share your results with this community, for free, after your survey and analysis is completed. For surveys that cannot comply with these requirements, review the rules on r/SampleSize and try there. If your survey complies with these requirements, post a comment saying so and confirming the date we can expect your results to be published on this subreddit (set a reminder using RemindMeBot), and the mods will approve your post.
This domain is not permitted on this subreddit.
Hello, everyone. Please keep all discussions focused on *cybersecurity*. We are implementing a *zero tolerance policy* on any political discussions or anything that even looks like baiting. This subreddit also does not support hacktivism of any kind. Any political discussions, any baiting, any conversations getting out of hand will be met by a swift ban. This is a trying time for many people all over the world, so please try to be civil. Remember, attack the argument, not the person.

What you can post

Post typeSubreddit settingShare of recent posts
TextAllowed84%
LinkAllowed16%
ImageNot allowed0%
VideoNot allowed0%
PollAllowed0%

Post flairs in use

  • Business Security Questions & Discussion 25%
  • Personal Support & Help! 17%
  • Career Questions & Discussion 14%
  • News - General 8%
  • New Vulnerability Disclosure 7%
  • Certification / Training Questions 6%
  • Research Article 6%
  • AI Security 5%
  • Corporate Blog 4%
  • FOSS Tool 3%

What happens to a new post

Where the most recent posts ended up. Sample size: 400.

  • Stayed up46%
  • Removed by Reddit's filters17%
  • Held by AutoModerator31%
  • Removed by moderators6%
  • Deleted by the author<1%

Reddit counts a removal by the subreddit's own AutoModerator rules as a moderator removal, so that share is not all human. Held by AutoModerator means the post is waiting in the mod queue.

What happened when we posted here

We have posted here ourselves. This is how our own posts and comments fared.

Stayed up
99%
Removed by Reddit's filters
0%
Removed by moderators
1%
Period
August 2025 to August 2026

The rules, in the mods' words

  1. 1

    Read the FAQ before posting

    Please read the FAQ before posting a question, as it may contain the answer you are looking for. Please also check the collections we have, such as the Breaking In to Cybersecurity FAQ, which contains a *ton* of useful information for people looking to go into cybersecurity! Due to repetition, posts containing questions which are answered in the FAQ will be removed.

  2. 2

    Must be relevant to cybersecurity professionals

    This is a discussion-oriented sub for people who are, or aspire to be, cybersecurity professionals. The rule of thumb we apply is: if professionals would find it insightful or would enjoy insightful discussions around it, then it's appropriate here. Questions about personal or "home" cybersecurity MUST be posted on r/cybersecurity_help or r/techsupport. Memes, "security fails," homework help, etc. historically don't drive conversation, and will generally be removed.

  3. 3

    No low effort / poor quality posts

    This is a community of cybersecurity professionals - the people reading and replying to threads are actual people taking time out of their day. If you aren't putting effort into writing something, why should anyone put effort into reading it? "AI"/machine generated content, whether linked to or posted directly, is explicitly forbidden across this subreddit and will be removed when discovered. Copywritten content, SEO farming, and other slop are similarly forbidden.

  4. 4

    Security first / no editorializing

    This is the guiding principle for all posts. No editorializing and no political agendas. Posts discussing political issues that affect security are fine, but the post must be geared towards the security implication. Such posts will be heavily monitored and comments may be locked as needed.

  5. 5

    No advertising

    Want to share information or resources? Please review these guidelines: https://www.reddit.com/r/cybersecurity/wiki/advertising_guidelines You would rather build a relationship with the /r/CyberSecurity community than get banned! Educational articles or blogs that contain advertisement to a service are to flair their posts with "Corporate Blog." Soliciting DMs/calls/etc instead of posting answers directly has been used by marketers to try to circumvent this rule, and may also result in a ban.

  6. 6

    No excessive promotion

    All promotion (i.e. self-promotion) on this subreddit must be both: * Under 10% of your posts and comments on this subreddit. * Once per week at most per promoted entity. This rule is enforced to curb spam and unwanted promotional posts by non-community-members. We must always be a community member *first*, and self-interested *second*. A full explanation with examples is available on our wiki.

  7. 7

    No personally-identifiable information.

    Do not post personally-identifiable information, unless the source has consented to it. Moderation staff can and will request proof. Do not request personally identifiable information, or link to sites gating information/articles/documents/etc. and requiring personally identifiable information to proceed. A "free" sign-up to view content requiring your email is not "free as in freedom."

  8. 8

    Civility

    We're all professionals. Be excellent to each other.

  9. 9

    Ongoing security incidents are to be collated into one thread

    During ongoing major incidents - hacks, vulnerabilities, etc - in order to collate all discussion into one area, threads will be locked or removed and discussion redirected to one or few megathreads.

These are the rules as archived in January 2025. Rules change. Check the sidebar before you post.

The culture

r/cybersecurity calls itself a discussion forum for people who are, or want to be, security professionals. The test the moderators apply is whether professionals would find a post insightful. About 84% of posts are text and the rest are links. Images and video are switched off. The typical post is around 80 words, and only about a quarter of titles are questions, because a lot of the feed is news and vulnerability notices.

Three kinds of post make up most of it. Business security questions: how to stop lookalike-domain invoice fraud, how to log firewall sessions, what controls to put around AI agents holding real credentials. Career threads from people already in IT or security. And news: a newly exploited flaw, an arrest, a government agency changing its post-quantum timeline. The posts that scored highest in our sample were news items and a practitioner asking peers whether they were seeing more breaches.

The fault line is between what the rules say the room is for and what people try to post. Beginners arrive in large numbers asking how to start, and AutoModerator sent the FAQ redirect more than any other message in our sample. AI is the other pressure point. There is an AI Security flair and real discussion under it, but the rules ban machine-generated content outright and the regulars are quick to call out posts that read like it.

What lands

  • Security news with a clear professional angle, posted as a direct link with the original framing.
  • A specific operational question with your environment described: what tooling you run, what got through, what you have tried.
  • A peer check, such as asking whether others are seeing the same rise in incidents that one security leader reported.
  • A fresh vulnerability heads-up with the CVE numbers and vendor advisory linked.
  • A certification pass or career move from someone already working in the field, with the detail of how they got there.

What gets removed or ignored

  • Getting-started posts. In our sample 20 of the 24 moderator removals with a known flair were tagged Starting Cybersecurity Career, and the rules send those to the FAQ and Mentorship Monday.
  • Resume review requests, which AutoModerator removes and redirects to r/resumes.
  • Personal or home security help. The rules say those must go to r/cybersecurity_help or r/techsupport.
  • Consumer-level corporate blog posts, such as a guide to locking down your own online accounts. The advertising guidelines list personal and home security education as unacceptable content.
  • Surveys that are not purely academic, anonymous and unpaid. They sit in the queue until you confirm you meet the conditions and commit to sharing results.

The unwritten rules

  • Staying up is not the same as being read. Most posts in our snapshot sat at one point with no comments, and only a handful broke out.
  • Politics around security news is on a short leash. A pinned moderator comment on sensitive threads promises swift bans for baiting, and the rule says to keep the post about the security implication.
  • If you work for a vendor, say so. The sidebar asks anyone with a conflict of interest to disclose it, and asking people to DM you or book a call instead of answering in the thread is treated as dodging the advertising rule.
  • Do not write with AI. The low effort rule forbids machine-generated content whether posted or linked, and a bullet-heavy post asking what tool people wish existed reads as market research.
  • Comments run to about 27 words and argue the point. Around 7% carry a link, usually to a reference, not a product.

Self-promotion

There are two rules. No advertising, with a wiki page of guidelines for vendors, and no excessive promotion: under 10% of your posts and comments in the subreddit, once a week at most per promoted entity. The guidelines are friendlier than most. Original research, professional-level explainers and engineering blogs are allowed without prior approval as long as they are free, accurate and flaired Corporate Blog, and the mods say few companies that tried to be useful have been removed or banned. Articles that are mainly about your product are not allowed, and neither is content gated behind a sign-up. In practice Corporate Blog is a small slice of the feed, about 4% of posts, and the community expects you to be a member first: answer in other threads, reply to commenters on your own, and disclose who you work for.

How people write here

Typical post length
79 words
Typical title length
9 words
Titles phrased as a question
27%
Typical comment length
27 words
Comments that include a link
7%
Posts that carry a flair
100%

When people post

  1. 0:00 UTC, 11
  2. 1:00 UTC, 12
  3. 2:00 UTC, 6
  4. 3:00 UTC, 14
  5. 4:00 UTC, 7
  6. 5:00 UTC, 9
  7. 6:00 UTC, 9
  8. 7:00 UTC, 15
  9. 8:00 UTC, 14
  10. 9:00 UTC, 18
  11. 10:00 UTC, 16
  12. 11:00 UTC, 18
  13. 12:00 UTC, 19
  14. 13:00 UTC, 17
  15. 14:00 UTC, 17
  16. 15:00 UTC, 32
  17. 16:00 UTC, 24
  18. 17:00 UTC, 27
  19. 18:00 UTC, 26
  20. 19:00 UTC, 18
  21. 20:00 UTC, 28
  22. 21:00 UTC, 16
  23. 22:00 UTC, 15
  24. 23:00 UTC, 12

New posts by hour of day, UTC.

Top keywords

The words and phrases that show up far more often here than in other communities, from recent posts in r/cybersecurity.

  • cybersecurity 46 posts
  • security 64 posts
  • cyber 23 posts
  • soc 21 posts
  • cyber security 12 posts
  • vulnerabilities 17 posts
  • cloud security 9 posts
  • siem 9 posts
  • attacks 13 posts
  • vulnerability 13 posts
  • grc 6 posts
  • breach 10 posts
  • cryptography 6 posts
  • cybersecurity hey 4 posts
  • attacker 10 posts
  • access 22 posts
  • cloud 16 posts
  • security engineer 5 posts
  • security+ 5 posts
  • blue team 5 posts
  • learning 16 posts
  • sans 5 posts
  • network 15 posts
  • compromised 9 posts
  • labs 9 posts
  • pursue 8 posts
  • threats 6 posts
  • defender 6 posts
  • courses 9 posts
  • breaches 5 posts
  • security engineering 4 posts
  • blue 10 posts
  • vulnerabilities disclosed 3 posts
  • updated security 3 posts
  • threats specifically 3 posts
  • sunday executes 3 posts
  • sunday cve-2026-88771 3 posts
  • soc blue 3 posts
  • security assessments 3 posts
  • scans causing 3 posts

Recurring topics: security, cybersec, cyber, ai, tool, cyber security, soc, cybersecurity, hack, career.

Growth

  1. 20123
  2. 201365
  3. 2014443
  4. 20152.7k
  5. 20166.2k
  6. 201714k
  7. 201833k
  8. 2019103k
  9. 2020210k
  10. 2021325k
  11. 2023643k
  12. 20241.1M
  13. 20251.3M
  14. 20261.5M

Common questions

How much karma do you need to post in r/cybersecurity?

The moderators do not publish a karma or account age number. What the data shows is heavy filtering: about 31% of sampled posts were held by AutoModerator, 17% were removed by Reddit's filters and 6% by moderators, leaving roughly 46% up. An established account posting something relevant to working professionals has the best chance.

Can I promote my product or blog in r/cybersecurity?

Within limits. Promotion has to be under 10% of your posts and comments in the subreddit and at most once a week per promoted entity. Educational posts that advertise a service must use the Corporate Blog flair, be free to read without a sign-up, and not be mainly about the product. Asking people to DM or call you instead of answering publicly can get you banned.

Can I ask how to get into cybersecurity on r/cybersecurity?

Not as a standalone post. The rules say questions answered in the FAQ are removed, and AutoModerator points career starters to the Breaking In to Cybersecurity FAQ and the pinned Mentorship Monday thread. Post your follow-up questions there, along with what research you have already done.

Why was my r/cybersecurity post removed?

The common causes are a beginner career question, a resume review request, a personal or home security problem, a survey that does not meet the academic conditions, a banned domain or link shortener, or content that reads as advertising or AI-generated. Many posts are also held by AutoModerator for review before anyone sees them.

Data as of October 4, 2026. Numbers come from public Reddit data (the Arctic Shift archive and GummySearch) sampled on this date. Removal share counts posts taken down by moderators, AutoModerator or Reddit's own filters. Banner and icon belong to the community. Moderators change rules without notice, so treat the sidebar as the final word.

Retro engraving of two spacecraft dockingFree audit

See what Reddit says about you.

Not a generic audit. Your actual numbers: where you get mentioned, where your three closest competitors get mentioned instead, and what your own analytics say about traffic you are already losing.

Drops your email into the two-minute application.