It happened again. Another “boutique security firm” popped up that turns out to be nothing more than a website and some impressive-sounding credentials that do not check out.
The infosec industry has a problem with people misrepresenting their qualifications and experience. It is easy to set up a professional-looking website, list some certifications (real or otherwise), and start selling security services. The barrier to entry is essentially zero.
This matters because companies hire these firms to protect their data and their customers. When the firm is fake or incompetent, real people get hurt. Data gets breached. Money gets stolen. Trust gets destroyed.
How do you spot a fake? A few red flags:
- No verifiable track record or references
- Certifications that cannot be confirmed through the issuing body
- Vague descriptions of past work with no specifics
- No presence in the security community (conferences, publications, research)
- Claims that seem too good to be true
Do your due diligence before hiring a security firm. Ask for references. Verify certifications. Check their reputation in the community. Your data depends on it.