Close Menu
  • Home
  • Articles
    • Attacks
      • BEC
      • Data Breach
      • DDoS
      • Evasion Attacks
      • Injection
      • Malware
      • MITM
      • Phishing
      • Ransomware
      • RCE
      • Social Engineering
      • Spoofing
      • Spyware
    • Business and Policy
      • BCP and DRP
      • GRC
      • Regulations
    • Data Protection
      • DLP
      • DRM
      • Encryption
      • IAM
    • Future, Trends and Insight
      • AI
      • Events & Community
      • Emerging Tech
      • Expert Panel
      • Interviews With Experts
      • Insights
      • Study & Research
    • Resources
      • Guides
      • Tools
      • Training & Education
    • Security
      • API
      • Apps
      • Cloud
      • Critical Infrastructure
      • Endpoint
      • Hardware
      • IoT
      • Mobile
      • Network
      • OT
      • Port Security
      • Security Architecture
      • Software Development
      • Supply Chain
      • Zero Trust
    • Threats and Vulnerabilities
      • Emerging Threats
      • Insider Threats
      • Risk Management
      • Threat Intelligence
      • Zero Day
  • News and Exclusives
    • Latest News
    • ISB Exclusive
    • Positive News
  • Who We Are
    • About Us
    • Information Security Buzz Expert Panel​
    • Write for Us
    • Media Pack
  • Contact Us
  • Newsletter
Facebook X (Twitter) LinkedIn
Facebook X (Twitter) LinkedIn
Information Security BuzzInformation Security Buzz
  • Home
  • Articles
    • Attacks
      • BEC
      • Data Breach
      • DDoS
      • Evasion Attacks
      • Injection
      • Malware
      • MITM
      • Phishing
      • Ransomware
      • RCE
      • Social Engineering
      • Spoofing
      • Spyware
    • Business and Policy
      • BCP and DRP
      • GRC
      • Regulations
    • Data Protection
      • DLP
      • DRM
      • Encryption
      • IAM
    • Future, Trends and Insight
      • AI
      • Events & Community
      • Emerging Tech
      • Expert Panel
      • Interviews With Experts
      • Insights
      • Study & Research
    • Resources
      • Guides
      • Tools
      • Training & Education
    • Security
      • API
      • Apps
      • Cloud
      • Critical Infrastructure
      • Endpoint
      • Hardware
      • IoT
      • Mobile
      • Network
      • OT
      • Port Security
      • Security Architecture
      • Software Development
      • Supply Chain
      • Zero Trust
    • Threats and Vulnerabilities
      • Emerging Threats
      • Insider Threats
      • Risk Management
      • Threat Intelligence
      • Zero Day
  • News and Exclusives
    • Latest News
    • ISB Exclusive
    • Positive News
  • Who We Are
    • About Us
    • Information Security Buzz Expert Panel​
    • Write for Us
    • Media Pack
  • Contact Us
  • Newsletter
Subscribe
Information Security BuzzInformation Security Buzz
Home - Articles - Product Endorsement Rules Of Engagement
Articles

Product Endorsement Rules Of Engagement

ISBuzz TeamBy ISBuzz TeamJuly 27, 20164 Mins Read
Share LinkedIn Twitter Facebook Copy Link Email
Share
Facebook Twitter LinkedIn Email Copy Link
Quick AI Summary
ChatGPTClaudeGeminiGrokPerplexityDeepSeekCopilot

When I started writing for Tripwire and some of the other information security websites that graciously publish my work, I had a few humble goals in mind:

  • To raise awareness about security-related topics for the general public;
  • To spark some thought and conversation about information security;
  • To educate folks who are considering a career and just starting out in the information security field;
  • To be more like my info-sec rock star friend, Javvad Malik.

I never expected that anyone would want me to endorse any products, but lately, I have received unsolicited requests to review and endorse some security products.

Generally I kindly decline these offers.  I am flattered by the solicitations, however, product endorsements do not satisfy my desire to help others in the InfoSec community.

However, since I am well-aware that I am not the only person who these companies approach for endorsements, I would like to take some time to offer some rules of engagement to help these companies increase their chances of convincing others to endorse their products.

Rule #1 for getting someone to review and endorse your security product:

If you want someone to go to your web site to review your product give them the name of the product and a way for them to find the correct link to the official site.

If you are selling a security product, chances are very great that the person you are contacting will not click on a link you provide.  Any decent security-minded person will seek out the official site from other sources and will check your product from there, not from an unsolicited link.

 Rule #2 for getting someone to review and endorse your security product:

Make sure that your web site does not generate a redirection notice.

Nothing raises a red flag faster than when your site indicates that it is performing a redirection.

Security professionals spend more than enough time warning our patrons to never follow redirections from one site to another.  Why would the manufacturer of a security product ever expect any security professional to ignore such a simple security practice?

Rule #3 for getting someone to review and endorse your security product:

Make sure that your site certificate is in order.

If your home page displays  http  in the navigation bar, indicating a certificate problem, that is going to cause most security folks to close that browser window and move on with their day.  Not all sites have implemented TLS on their home page.  This is not as bad as a certificate warning mentioned above.  If you are using a TLS Certificate, please obtain one from a trusted Certificate Authority.  Remember that a security analyst, researcher, or hacker will probably check this type of information before proceeding.

Rule #4 for getting someone to review and endorse your security product:

Beware of the Appeal to Authority fallacy.

This is a problem that is as old as Socrates.  If you want someone to endorse your product, check to make sure that they are qualified to do so.  Just because 9 out of 10 dentists like your encryption product doesn’t make it a good product.  No one has fallen for that fallacy since 1972.  If you want an endorsement for an encryption technology, ask a qualified authority on the subject.

I applaud all of the people who have taken the bold entrepreneurial leap to create some of the great security products that keep us safe.  Without your innovation, we would be in a very sad state.  While many would argue that we are no safer than we were 10 years ago, I am more optimistic.  However, if you want to add some real punch to your product, please follow the simple steps outlined above before approaching any security professional for a review and subsequent endorsement.

[su_box title=”About Bob Covello” style=”noise” box_color=”#336588″][short_info id=’83956′ desc=”true” all=”false”][/su_box]

ISBuzz Team
  • ISBuzz Team
    Air Canada Data Breach: BianLian Extortion Group Claims A Massive Heist Contrary To Airline’s Earlier Statement
  • ISBuzz Team
    Unprecedented DDoS Attack Rocks The Web: Tech Giants Reveal A Digital Tsunami
  • ISBuzz Team
    CISA Flags High-Severity Adobe Acrobat Reader Flaw Amid Active Exploits
  • ISBuzz Team
    Curl Security Alert: Patching A Critical Bug Averting Potential Cyber Catastrophe

The opinions expressed in this post belong to the individual contributors and do not necessarily reflect the views of Information Security Buzz.

Share. Facebook Twitter LinkedIn Email Copy Link

Related Posts

Visual data is the blind spot in enterprise security: that’s about to change

May 4, 20267 Mins Read

Making stolen data worthless: why security must start with the data

March 30, 20265 Mins Read

Meta’s Smart Glasses Privacy Scandal Expands After Sama Credentials Found on the Dark Web

March 10, 20264 Mins Read
ISB-Bora-Side-Bar

No se ha podido establecer conexión. Error 429

 
ISB-Bora-Side-Bar
Black ISB Logo

Information Security Buzz is an independent resource that provides the experts’ comments, analysis, and opinion on the latest Cybersecurity news and topics

X (Twitter) LinkedIn Facebook RSS

Working With Us

  • About Us
  • Advertise With Us
  • Contact Us

Write For Us

  • How To Contribute

The Pages

  • Privacy Policy
  • Cookie Policy
  • AI Policy
  • Terms & Conditions
  • Copyright Notice

Information Security Buzz and all its contents are copyright © 2014-2025. All rights reserved. All third-party trademarks are recognized.

Type above and press Enter to search. Press Esc to cancel.

Manage Consent
To provide the best experiences, we use technologies like cookies to store and/or access device information. Consenting to these technologies will allow us to process data such as browsing behavior or unique IDs on this site. Not consenting or withdrawing consent, may adversely affect certain features and functions.
Functional Always active
The technical storage or access is strictly necessary for the legitimate purpose of enabling the use of a specific service explicitly requested by the subscriber or user, or for the sole purpose of carrying out the transmission of a communication over an electronic communications network.
Preferences
The technical storage or access is necessary for the legitimate purpose of storing preferences that are not requested by the subscriber or user.
Statistics
The technical storage or access that is used exclusively for statistical purposes. The technical storage or access that is used exclusively for anonymous statistical purposes. Without a subpoena, voluntary compliance on the part of your Internet Service Provider, or additional records from a third party, information stored or retrieved for this purpose alone cannot usually be used to identify you.
Marketing
The technical storage or access is required to create user profiles to send advertising, or to track the user on a website or across several websites for similar marketing purposes.
  • Manage options
  • Manage services
  • Manage {vendor_count} vendors
  • Read more about these purposes
View preferences
  • {title}
  • {title}
  • {title}