Journal 11.2: Bug Bounty Policies
- ghens004
- Aug 2
- 2 min read
Journal 11.2: Bug Bounty Policies
Gary Hensley
07/26/26
In the article Hacking for good: Leveraging HackerOne data to develop an economic model of Bug Bounties. They looked bug bounty programs and how they fit in the cybersecurity field and if there is a benefit. This gives options for jobs and for companies as an alternative way of finding cybersecurity vulnerabilities.
Programs like bug bounties are a cost effective option for companies to allow ethical hackers to do penetration testing. This allows companies to find vulnerabilities and opens up more eyes to problems that may be missed. This is a way to do continuous security checks and improvements. It was noted that a small percentage of hackers actually submitted high value findings. Many participants submitted only a few reports. Most hackers participated when there were higher payouts or bonuses. HackerOne offered a marketplace for hackers to find jobs and pick and choose between better payouts. Companies rely on freelance security due to the global shortage of cyber professionals and the value of more eyes looking at the question at hand. The article also noted that some sectors get fewer reports, possibly due to the value on the black market.
These programs help level the playing field for cybersecurity between large and small companies. They are a useful tool for identifying different perspectives and weaknesses across companies. It is assumed that people working with hacker one are white hat and ethical hackers participating in these bug bounties. There could be some concer with allowing people access to find you weaknesses.
Reference
Sridhar, K., & Ng, M. (2021). Hacking for good: Leveraging HackerOne data to develop an economic model of bug bounties. Journal of Cybersecurity, 7(1), Article tyab007. https://doi.org/10.1093/cybsec/tyab007
Comments