Bug bounty programs work. It makes sense: White-hat hackers of all stripes and skill levels get a chance to track down critical flaws, improve their security reputation and get paid.

Dark Reading noted these programs are quickly “growing up,” offering bigger payouts and using a more formal approach to determine vulnerability values. Here’s a look at the maturing market of big league bug squashing.

The Rise of Bug Bounty Programs

Crowdsourcing the bug-hunt business is a solid choice for big tech companies. Even with large IT staff, it’s impossible to invest the kind of time and effort necessary to track down both existing and zero-day flaws. Add in the fact that familiarity with local systems makes in-house IT less than impartial, and there are big benefits to bug finding.

So it’s no surprise that the market is growing. ZDNet reported that Intel just launched its first bug bounty program. Payouts are $7,500 for critical software bugs, $10,000 for critical firmware security flaws and up to $30,000 for each “critical Intel hardware bug.”

Meanwhile, companies like HackerOne and Bugcrowd, which manage bounty programs for other organizations, are seeing a marked increase in the number of registered hackers, according to Dark Reading. HackerOne in particular has more than 100,000 people on board, and has helped 750 organizations find 40,000 bugs.

Results come quickly — more than 75 percent of companies that sign up with HackerOne get at least one bug report within 24 hours. Even companies with long-standing bounty programs, such as Microsoft, are increasing their payouts. If participants find zero-day vulnerabilities that Microsoft can replicate, the rewards reach $15,000 or more.

Locking It Down

Along with bigger payouts, companies are also tightening up the formula they use to assign bug values. What’s the math behind all the money?

CSO Online explained that it’s critical for companies to define what a bug is worth — and be prepared to change this number as market forces shift. Dark Reading also pointed to several key factors in “formalizing” bug bounty programs to pay out more when specific conditions are met. For example, HackerOne takes into account the severity of the flaw, the scarcity or abundance of similar bugs, the potential impact of the vulnerability in the wild and the maturity of a company’s existing security program.

What does this mean for bug hunters? Low-risk flaws that are common across industries, won’t lead to severe data breaches and can be effectively handled by internal teams will pay out on the low end of the spectrum: likely between $1,000 and $5,000. On the higher end, rare, risky and repeatable bugs that put corporate resources in jeopardy could net anywhere from $15,000 to $100,000.

The bottom line is that bug bounty programs, both internal and managed, are maturing as corporate risk increases. They are also becoming increasingly structured as more hackers lend their squashing skills to protect corporate data.

More from

Did Brazil DSL Modem Attacks Change Device Security?

From 2011 to 2012, millions of Internet users in Brazil fell victim to a massive attack against vulnerable DSL modems. By configuring the modems remotely, attackers could redirect users to malicious domain name system (DNS) servers. Victims trying to visit popular websites (Google, Facebook) were instead directed to imposter sites. These rogue sites then installed malware on victims' computers. According to a report from Kaspersky Lab Expert Fabio Assolini citing statistics from Brazil's Computer Emergency Response Team, the attack ultimately…

Who Carries the Weight of a Cyberattack?

Almost immediately after a company discovers a data breach, the finger-pointing begins. Who is to blame? Most often, it is the chief information security officer (CISO) or chief security officer (CSO) because protecting the network infrastructure is their job. Heck, it is even in their job title: they are the security officer. Security is their responsibility. But is that fair – or even right? After all, the most common sources of data breaches and other cyber incidents are situations caused…

Transitioning to Quantum-Safe Encryption

With their vast increase in computing power, quantum computers promise to revolutionize many fields. Artificial intelligence, medicine and space exploration all benefit from this technological leap — but that power is also a double-edged sword. The risk is that threat actors could abuse quantum computers to break the key cryptographic algorithms we depend upon for the safety of our digital world. This poses a threat to a wide range of critical areas. Fortunately, alternate cryptographic algorithms that are safe against…

Securing Your SAP Environments: Going Beyond Access Control

Many large businesses run SAP to manage their business operations and their customer relations. Security has become an increasingly critical priority due to the ongoing digitalization of society and the new opportunities that attackers exploit to achieve a system breach. Recent attacks related to corrupt data, stealing personal information and escalating privileges for remote code execution all highlight the new and varied entry points threat actors have taken advantage of. Attackers with the appropriate skills could be able to exploit…