New: warm up Reddit accounts. You own them.
Rankhog
Subreddit guides

r/Information_Security rules, stats, and what to post

A source-backed Rankhog guide to r/Information_Security: public rules, community context, posting fit, and startup-promotion risk before you publish.

By Anthony Riera, founder and operator of Rankhog.

Subreddit guides combine public Reddit source URLs, captured rules, visible verification dates, and Rankhog's account-safety workflow.

Current public stats

Members
44,634
Verified
September 8, 2026
Category
Technical product and developer communities

Rules can change, so Rankhog keeps verification dates and the original public Reddit sources visible.

Rule summary

  • Follow Reddit’s Rules: All content must follow Reddit’s site-wide rules.
  • Keep it Relevant: Content must be related to the information security industry.
  • Keep it Legal, Ethical & Moral: Ensure all content is legal, ethical and moral.
  • No Low Effort / Low Quality Content: Put effort into your posts.
  • No Duplicate / Spam Content: Ensure posts are unique and not spam.
  • Be Respectful: Be respectful in all posts, comments, discussions, etc.

Works well

  • A detailed analysis post about a recent security incident or vulnerability, written from your own experience or research, with no product pitch.
  • A lessons-learned post about a security challenge your team faced and how you solved it, focused on the problem and the approach.
  • A well-formed question about a specific information security concept or tool, with enough context that the community can give a useful answer.
  • A link to a genuinely useful security blog post, accompanied by a summary in the post body that explains why it matters to the community.

Avoid

  • Posting content that has nothing to do with information security.
  • Dropping a link with no context or explanation, which the mods will likely read as spam under the No Duplicate / Spam Content rule.
  • Reposting the same article or discussion that someone already shared, since duplicates are called out for removal.
  • Writing a shallow or rushed post, because the No Low Effort / Low Quality Content rule gives mods a reason to delete it.
  • Being rude or combative in comments or replies, which breaks the Be Respectful rule.
  • Sharing anything illegal, unethical, or morally questionable, even as a hypothetical, because the Keep it Legal, Ethical & Moral rule is explicit.

What actually works in r/information_security

These are the highest scoring posts Rankhog observed in r/information_security over the past month, with what each one did differently. Rankhog watches this community continuously, so it sees posts when they are published and again as they climb.

  1. Screenshot of a post in r/information_security titled "A junior pasted our prod DB creds into ChatGPT at work while I watched and could not compute it." with 1.0k upvotes
    Upvotes
    1.0k
    Comments
    274
    Posted
    Aug 31, 2026

    Why it worked

    • Told in the first person
    • Short paragraphs rather than one block of text

    Read the full thread on Reddit

  2. Screenshot of a post in r/information_security titled "Found out someone in ops built a customer facing app on Replit and no one told IT" with 229 upvotes
    Upvotes
    229
    Comments
    23
    Posted
    Sep 4, 2026

    Why it worked

    • Short paragraphs rather than one block of text

    Read the full thread on Reddit

  3. Screenshot of a post in r/information_security titled "153 MILLION drivers licenses leaked and up for sale." with 57 upvotes
    Upvotes
    57
    Comments
    8
    Posted
    Sep 2, 2026

    Why it worked

    • Short paragraphs rather than one block of text

    Read the full thread on Reddit

  4. Screenshot of a post in r/information_security titled "A Tool That Steals Your Microsoft 365 Login Rents for $320/month" with 50 upvotes
    Upvotes
    50
    Comments
    10
    Posted
    Aug 27, 2026

    Why it worked

    • Short paragraphs rather than one block of text

    Read the full thread on Reddit

  5. Screenshot of a post in r/information_security titled "I pasted our Q3 financials into ChatGPT for a quick summary. It worked perfectly. Then I sat there staring at the…" with 32 upvotes
    Upvotes
    32
    Comments
    19
    Posted
    Aug 25, 2026

    Why it worked

    • Told in the first person
    • Short paragraphs rather than one block of text

    Read the full thread on Reddit

  6. Screenshot of a post in r/information_security titled "Palo Alto CEO claims there's $1 trillion of security debt because pre-AI infrastructure wasn't built for modern…" with 26 upvotes
    Upvotes
    26
    Comments
    12
    Posted
    Sep 8, 2026

    Why it worked

    • Kept short enough to read in one pass

    Read the full thread on Reddit

  7. Screenshot of a post in r/information_security titled "The agent just needed read access until one tool description changed" with 25 upvotes
    Upvotes
    25
    Comments
    13
    Posted
    Sep 5, 2026

    Why it worked

    • Short paragraphs rather than one block of text

    Read the full thread on Reddit

  8. Screenshot of a post in r/information_security titled "What are the best AEV solutions people are actually using?" with 24 upvotes
    Upvotes
    24
    Comments
    8
    Posted
    Aug 28, 2026

    Why it worked

    • Asks the community a question instead of announcing something

    Read the full thread on Reddit

  9. Screenshot of a post in r/information_security titled "Palo Alto's CEO says $1 trillion of cybersecurity infra isn't built for AI-speed attacks" with 21 upvotes
    Upvotes
    21
    Comments
    24
    Posted
    Sep 3, 2026

    Why it worked

    • Short paragraphs rather than one block of text

    Read the full thread on Reddit

  10. Screenshot of a post in r/information_security titled "Demand for cyber security professionals is going to skyrocket?" with 19 upvotes
    Upvotes
    19
    Comments
    5
    Posted
    Aug 28, 2026

    Why it worked

    • Asks the community a question instead of announcing something
    • Kept short enough to read in one pass

    Read the full thread on Reddit

What r/Information_Security Is For

This community is for information security content. The public description says it covers news, questions, analysis, and blog posts related to the field. The rules reinforce that everything must be tied to the information security industry. So the people here are professionals, students, and enthusiasts who care about security topics and want to read, discuss, or ask about them.

Rules That Matter Before Posting

The rule that matters most for a founder or marketer is Keep it Relevant, because anything that drifts from the information security industry gives moderators a clear reason to remove it. The No Low Effort / Low Quality Content rule is the one that will catch a lazy promotional post, so whatever you share needs real substance. The No Duplicate / Spam Content rule is the one that punishes reposted links or repeated self-promotion, so you should check what has already been posted before you submit anything. The Keep it Legal, Ethical & Moral rule matters too, especially in a security community where people sometimes share exploit details or breach data, so stay on the right side of that line. Finally, Be Respectful means you should engage calmly even if someone criticizes your post or your product.

What To Post

A good post here is a piece of information security content that stands on its own merit. If you are a founder, think about what your team has learned about a security problem, a threat, a tool, or a process. Write that up as analysis or a lessons-learned post. If you have a blog post that explains a security concept in depth, share it with enough context in the post body that a reader gets value without clicking the link. If you have a question, make it specific and tied to the industry. The key is that the post should read like it belongs in an information security community, not like it was written to drive traffic somewhere.

What To Avoid

Avoid anything that is not directly about information security, because the Keep it Relevant rule is explicit. Avoid duplicate links or repeated promotional posts, since the No Duplicate / Spam Content rule calls those out. Avoid shallow posts with no analysis or discussion value, because the No Low Effort / Low Quality Content rule gives moderators a reason to remove them. Avoid anything illegal, unethical, or morally questionable, which the Keep it Legal, Ethical & Moral rule makes clear. And avoid being rude or dismissive in comments, because the Be Respectful rule covers all interactions.

Use Rankhog before posting in r/Information_Security

Want the version that does not run out? Subscribers get unlimited tool runs and more careful checks before posting.

Get my free Reddit SEO audit

Start your 3-day free trial. Card required. $99/month after trial. Next, connect a verified Reddit account; no strategy starts until you explicitly start Rankhog.

Common questions about r/Information_Security

Can I share a link to my company's blog post about a security topic?

The rules do not ban links or promotion outright, but the No Duplicate / Spam Content rule means you must add real value and avoid dropping bare links with no discussion.

Is it okay to announce my security product here?

It depends on relevance. If your product solves a specific information security problem and you frame the post around the problem and lessons learned, it has a better chance than a generic product announcement.

Are AI-generated posts allowed?

The rules do not mention AI content specifically. What matters is that the post is relevant to information security, not low effort, and not spam.

Can I ask a technical question about a security concept?

Yes, as long as the question is directly related to information security, shows effort, and is respectful.

Related subreddit guides