March 22, 2017 By Douglas Bonderud 2 min read

Bug bounty programs work. It makes sense: White-hat hackers of all stripes and skill levels get a chance to track down critical flaws, improve their security reputation and get paid.

Dark Reading noted these programs are quickly “growing up,” offering bigger payouts and using a more formal approach to determine vulnerability values. Here’s a look at the maturing market of big league bug squashing.

The Rise of Bug Bounty Programs

Crowdsourcing the bug-hunt business is a solid choice for big tech companies. Even with large IT staff, it’s impossible to invest the kind of time and effort necessary to track down both existing and zero-day flaws. Add in the fact that familiarity with local systems makes in-house IT less than impartial, and there are big benefits to bug finding.

So it’s no surprise that the market is growing. ZDNet reported that Intel just launched its first bug bounty program. Payouts are $7,500 for critical software bugs, $10,000 for critical firmware security flaws and up to $30,000 for each “critical Intel hardware bug.”

Meanwhile, companies like HackerOne and Bugcrowd, which manage bounty programs for other organizations, are seeing a marked increase in the number of registered hackers, according to Dark Reading. HackerOne in particular has more than 100,000 people on board, and has helped 750 organizations find 40,000 bugs.

Results come quickly — more than 75 percent of companies that sign up with HackerOne get at least one bug report within 24 hours. Even companies with long-standing bounty programs, such as Microsoft, are increasing their payouts. If participants find zero-day vulnerabilities that Microsoft can replicate, the rewards reach $15,000 or more.

Locking It Down

Along with bigger payouts, companies are also tightening up the formula they use to assign bug values. What’s the math behind all the money?

CSO Online explained that it’s critical for companies to define what a bug is worth — and be prepared to change this number as market forces shift. Dark Reading also pointed to several key factors in “formalizing” bug bounty programs to pay out more when specific conditions are met. For example, HackerOne takes into account the severity of the flaw, the scarcity or abundance of similar bugs, the potential impact of the vulnerability in the wild and the maturity of a company’s existing security program.

What does this mean for bug hunters? Low-risk flaws that are common across industries, won’t lead to severe data breaches and can be effectively handled by internal teams will pay out on the low end of the spectrum: likely between $1,000 and $5,000. On the higher end, rare, risky and repeatable bugs that put corporate resources in jeopardy could net anywhere from $15,000 to $100,000.

The bottom line is that bug bounty programs, both internal and managed, are maturing as corporate risk increases. They are also becoming increasingly structured as more hackers lend their squashing skills to protect corporate data.

More from

How will the Merck settlement affect the insurance industry?

3 min read - A major shift in how cyber insurance works started with an attack on the pharmaceutical giant Merck. Or did it start somewhere else?In June 2017, the NotPetya incident hit some 40,000 Merck computers, destroying data and forcing a months-long recovery process. The attack affected thousands of multinational companies, including Mondelēz and Maersk. In total, the malware caused roughly $10 billion in damage.NotPetya malware exploited two Windows vulnerabilities: EternalBlue, a digital skeleton key leaked from the NSA, and Mimikatz, an exploit…

3 Strategies to overcome data security challenges in 2024

3 min read - There are over 17 billion internet-connected devices in the world — and experts expect that number will surge to almost 30 billion by 2030.This rapidly growing digital ecosystem makes it increasingly challenging to protect people’s privacy. Attackers only need to be right once to seize databases of personally identifiable information (PII), including payment card information, addresses, phone numbers and Social Security numbers.In addition to the ever-present cybersecurity threats, data security teams must consider the growing list of data compliance laws…

ICS CERT predictions for 2024: What you need to know

4 min read - As we work through the first quarter of 2024, various sectors are continuously adapting to increasingly complex cybersecurity threats. Sectors like healthcare, finance, energy and transportation are all regularly widening their digital infrastructure, resulting in larger attack surfaces and greater risk exposure.Kaspersky just released their ICS CERT Predictions for this year, outlining the key cybersecurity challenges industrial enterprises will face in the year ahead. The forecasts emphasize the persistent nature of ransomware threats, the increasing prevalence of cosmopolitical hacktivism, insights…

Topic updates

Get email updates and stay ahead of the latest threats to the security landscape, thought leadership and research.
Subscribe today