Skip to Content
HandbookBrandVoice & tone

Voice & tone

The core principle

Write the way you’d explain something to a smart friend, not a business associate you’re trying to impress or a prospect you’re trying to close.

That means:

  • Clear and simple: If a simpler word works, use it.
  • Specific: Concrete nouns and real examples beat abstract claims every time.
  • Direct: State what the thing is. Don’t make the reader infer. Don’t use filler words.
  • Honest: Including about limitations. Cybersecurity personnel trust honesty more than polish.
  • Conversational: Contractions are fine. Starting a sentence with “But” or “And” is fine.
  • No jargon for jargon’s sake: Technical precision when it helps. No buzzwords.
  • No emojis: Emojis come off as try-hard and cringe. Avoid them, and prioritize using plain English.

If there’s an industry-standard phrase, question if it’s actually the best way to describe something – or if somebody came up with it once and then everyone else followed suit. Maybe it makes sense to stick with it, but we also have the unique opportunity to come up with a new term if it seems worth doing.

What to avoid

Hedge words and weasel phrases

These make copy feel weak and corporate. Cut them:

Instead of thisConsider…
“helps you to”just say what it does
”empowers teams to”say what teams can now do
”enables you to unlock”say what they get
”leverages”uses
”utilize”use
”streamline”speed up / simplify
”robust”strong, solid, or just describe it
”best-in-class”show, don’t claim
”holistic”comprehensive, or just describe the parts
”seamless”describe why it’s easy
”synergy”No.

Passive voice

Active: “SucuriLabs prevents phishing.” Passive: “Phishing is prevented by SucuriLabs.”

The active version is shorter, clearer, and more confident.

Feature-first headlines

“Introducing our new dashboard” says nothing about why anyone should care. Lead with the benefit or the specific capability.

Forced humor

A joke that has to be explained isn’t funny. Humor in SucuriLabs copy works when it’s specific, unexpected, and comes from a genuine perspective. It doesn’t work when it’s “here’s a wacky metaphor to make our SaaS product seem fun.”

When in doubt, just be clear. Clear beats clever, and makes the genuine humor stand out.

Dos and don’ts with examples

Headlines

DoDon’t
”Spot emails impersonating your suppliers""Unlock next-generation vendor trust intelligence"
"See why an email was flagged""Harness actionable AI-powered threat insights"
"Review suspicious emails in one place""The all-in-one platform for modern cybersecurity teams"
"Block malicious emails with active prevention""Eliminate every email threat, automatically"
"Protect your team from email fraud""SucuriLabs is a cutting-edge AI-driven security solution”

On that last one: lead with what the customer protects, not what our software is. Name the threat and the outcome. Keep claims specific: detection-only mode doesn’t block delivery, and active prevention isn’t a guarantee that every attack will be stopped.

Body copy

DoDon’t
”Connect Microsoft 365 to import your users and groups. Then activate the users you want to monitor.""Leverage our seamless integration to unlock comprehensive protection across your organization."
"Review the sender, detection signals, and attachments in one place. Then choose a remediation action.""Our holistic threat intelligence empowers analysts to streamline incident response."
"Detection-only mode flags potential threats without blocking email delivery.""Our advanced monitoring mode delivers robust, frictionless security.”

Errors

DoDon’t
”Connecting Microsoft 365 requires a tenant administrator account. Sign in with one and try again.""Integration failed due to insufficient privileges."
"Message content is restricted. Enter a reason and select Request Access.""Access denied. Please contact support.”

Say what happened and give the next step. Don’t guess at the cause or promise that a retry will fix it. If an action failed, don’t describe it as completed.

Emails

DoDon’t
”Your Microsoft 365 users have been imported. Open Users and activate the accounts you want to monitor.""We’re delighted to announce that your onboarding journey has reached an exciting milestone."
"An incident needs review. Open it to check the detection signals and decide what action to take.""A critical security event demands your immediate attention to safeguard your organization.”

Give the reader a reason to act and a clear next step. Match the urgency to the evidence; don’t turn every detection into an emergency.

Social media

DoDon’t
”A familiar sender name isn’t proof. Check the address and authentication results before trusting the message.""Stay one step ahead of today’s ever-evolving threat landscape."
"Investigating a suspicious email? SucuriLabs brings together:
• Sender and recipient details
• Detection signals
• Link and attachment analysis
• Remediation history"
"SucuriLabs delivers a comprehensive, AI-powered ecosystem of actionable intelligence for end-to-end incident management."
"Detection-only mode flags threats. Active prevention also blocks malicious emails. Choose the mode that fits your security policy.""Set it and forget it. SucuriLabs makes your business immune to email attacks.”
(reply) “this is incredible”(reply) “Nice work! We love it!” 😁
Last updated on