https://www.channelfutures.com/wp-content/themes/channelfutures_child/assets/images/logo/footer-new-logo.png
  • Home
  • Technologies
    • Back
    • SDN/SD-WAN
    • Cloud
    • RMM/PSA
    • Security
    • Telephony/UC/Collaboration
    • Cable
    • Mobility & Wireless
    • Fiber/Ethernet
    • Data Centers
    • Backup & Disaster Recovery
    • IoT
    • Desktop
    • Artificial Intelligence
    • Analytics
  • Strategy
    • Back
    • Mergers and Acquisitions
    • Channel Research
    • Business Models
    • Distribution
    • Technology Solutions Brokerages
    • Sales & Marketing
    • Best Practices
    • Vertical Markets
    • Regulation & Compliance
  • MSP 501
    • Back
    • 2023 MSP 501 Application
    • 2022 MSP 501 Rankings
    • 2022 NextGen 101 Rankings
  • Intelligence
    • Back
    • Galleries
    • Podcasts
    • From the Industry
    • Reports/Digital Issues
    • Webinars
    • White Papers
  • Channel Futures TV
  • EMEA
  • Channel Chatter
    • Back
    • People on the Move
    • New/Changing Channel Programs
    • New Products & Services
    • Industry Honors
  • Resources
    • Back
    • Advisory Boards
    • Industry Organizations
    • Our Sponsors
    • Advertise
    • 2023 Editorial Calendar
  • Awards
    • Back
    • 2022 MSP 501
    • Channel Influencers
    • Circle of Excellence
    • DE&I 101
    • Technology Advisor 101 (TA 101)
    • Channel Leaders Lists
  • Events
    • Back
    • 2023 Call for Speakers
    • CP Conference & Expo
    • MSP Summit
    • Channel Partners Europe
    • Channel Partners Event Coverage
    • Webinars
    • Industry Events
  • About Us
  • DE&I
Channel Futures
  • NEWSLETTER
  • Home
  • Technologies
    • Back
    • SDN/SD-WAN
    • Cloud
    • RMM/PSA
    • Security
    • Telephony/UC/Collaboration
    • Cable
    • Mobility & Wireless
    • Fiber/Ethernet
    • Data Centers
    • Backup & Disaster Recovery
    • IoT
    • Desktop
    • Artificial Intelligence
    • Analytics
  • Strategy
    • Back
    • Mergers and Acquisitions
    • Channel Research
    • Business Models
    • Distribution
    • Technology Solutions Brokerages
    • Sales & Marketing
    • Best Practices
    • Vertical Markets
    • Regulation & Compliance
  • MSP 501
    • Back
    • 2023 MSP 501 Application
    • 2022 MSP 501 Rankings
    • 2022 NextGen 101 Rankings
  • Intelligence
    • Back
    • Galleries
    • Podcasts
    • From the Industry
    • Reports/Digital Issues
    • Webinars
    • White Papers
  • Channel Futures TV
  • EMEA
  • Channel Chatter
    • Back
    • People on the Move
    • New/Changing Channel Programs
    • New Products & Services
    • Industry Honors
  • Resources
    • Back
    • Advisory Boards
    • Industry Organizations
    • Our Sponsors
    • Advertise
    • 2023 Editorial Calendar
  • Awards
    • Back
    • 2022 MSP 501
    • Channel Influencers
    • Circle of Excellence
    • DE&I 101
    • Technology Advisor 101 (TA 101)
    • Channel Leaders Lists
  • Events
    • Back
    • 2023 Call for Speakers
    • CP Conference & Expo
    • MSP Summit
    • Channel Partners Europe
    • Channel Partners Event Coverage
    • Webinars
    • Industry Events
  • About Us
  • DE&I
    • Newsletter
  • REGISTER
  • MSPs
  • VARs / SIs
  • Agents
  • Cloud Service Providers
  • Channel Partners Events
 Channel Futures

Cloud


Cybersecurity

Security Roundup: Bug Bounty Programs, Security Underspending, Opaq, Fortanix-Equinix

  • Written by Edward Gately
  • March 17, 2018
HackerOne is the platform behind many bug bounty programs.

On the front line of the cybersecurity war stands an army of hackers who are using their skills for good instead of evil.

These hackers are part of bug bounty programs, in which companies like Bitdefender, Barracuda Networks and Kaspersky Lab offer rewards for finding and reporting software bugs so they can be fixed before cybercriminals exploit them.

HackerOne is the platform behind many of these programs. HackerOne customers have resolved more than 64,000 vulnerabilities and have been awarded more than $25 million in bug bounties.

HackerOne's Adam Bacchus

HackerOne’s Adam Bacchus

To get the lowdown on bug bounty programs, we spoke with Adam Bacchus, HackerOne’s director of program operations. He runs HackerOne’s internet bug-bounty program, disclosure assistance and other efforts to help organizations start and run successful bug-bounty programs, help hackers succeed, and generally drive the creation of bounties.

“Bounty hunters are definitely the leaders in the space,” he said. “When you have a bug bounty program, you have a veritable army. It’s almost like a neighborhood watch where you have hundreds or thousands, or hundreds of thousands of hackers who are all watching out for you and they’ve all got your back. And they are very much on the front line in the way that they’re constantly watching out and looking for vulnerabilities, and giving you a friendly head’s up if they find something.”

Bug bounty programs basically are vulnerability disclosure programs with an added financial incentive, Bacchus said.

“A disclosure program is saying, ‘Hey, if you’re a hacker out there, a friendly hacker, and you found a bug in one of our systems, this is how you can contact us and tell us about it, and we have an agreement with you, we’re not going to try to sue you or throw you in jail,'” he said. “Here [are] the rules of engagement, here’s what you can hack on, here’s what you can’t hack on, and please don’t go after other users’ data. In a bug bounty program, we’re also saying, “Hey, depending on the severity of the bug, if you find a huge bone-crushing issue, we’re willing to pay out a certain amount of money depending on the severity of the bug. They’ll reward you for taking the time to do that research and letting us know about that issue.”

When a company launches a bug bounty program, lots of bugs are found because “you’re leveraging the power of hundreds if not thousands of eyeballs looking at your property,” Bacchus said.

“What we’ve seen on all of our programs that we run is after the initial spike, things will tamper down a little bit once the low-hanging fruit has been caught,” he said. “So what most programs will do is, over time they’ll actually increase the bounty amounts so as bugs are harder to find, you essentially have to pay more to get that return on investment from hackers. And you eventually move or shift from improving the security to what we call proving security in that lots and lots of hackers are going after you and trying to find bugs. If the well is starting to dry up, that’s a good sign …

  • Page 1
  • Page 2
  • Page 3
  • Page 4
Tags: Agents Cloud Security

Most Recent


  • Baseball swing
    VMware Partner Connect Now in Full Swing Worldwide
    "This is the complete end state” of VMware’s channel program, per Tracy-Ann Palmer, and will hold for years.
  • Doubling down
    The Gately Report: Huntress to Double Down on MSP Partner Investment
    A massive health care industry data breach remained under wraps for nearly a year.
  • Layoffs
    Latest Amazon Layoffs Impacting 9,000 Workers, Including AWS
    This likely isn't the end of layoffs at Amazon.
  • HPE Greenlake depiction
    HPE to Expand GreenLake Into ITOM Market with OpsRamp Acquisition
    OpsRamp was part of Hewlett Packard Pathfinder’s venture capital investment in 2020.

Leave a comment Cancel reply

-or-

Log in with your Channel Futures account

Alternatively, post a comment by completing the form below:

Your email address will not be published. Required fields are marked *

Related Content

  • College classroom
    Community College Ransomware Attack Wreaks Havoc
  • Virtual Desktop
    6 Enhancements to Microsoft’s WVD, Plus a New Name: Azure Virtual Desktop
  • Cloud computing concept
    Cloud Computing Adoption Isn’t Slowing — Need to Convince Clients?
  • Welcome Mat
    Ex-Telarus Exec Scott Forbush Leaves Upstack for PPT Solutions After 5 Months

Upcoming Events

View all

Channel Partners Conference & Expo

May 1, 2023 - May 4, 2023

Channel Partners Europe

June 13, 2023 - June 14, 2023

Channel Futures Leadership Summit

October 30, 2023 - November 2, 2023

Galleries

View all

VMware Partner Connect Now in Full Swing Worldwide

March 20, 2023

The Gately Report: Huntress to Double Down on MSP Partner Investment

March 20, 2023

8 Channel People Making Waves This Week at T-Mobile, Kaseya, Google Cloud, Atlassian, More

March 17, 2023

Industry Perspectives

View all

10 Strategic Smart Enterprise Drivers for 2023

March 16, 2023

Does Your Company Have a Virtual Water Cooler?

March 13, 2023

How Hybrid Work Poses Major Cybersecurity Risks

March 1, 2023

Webinars

View all

Equipping the Hybrid Workforce: What It Takes to Execute

March 28, 2023

Give Customers the Power: How MSPs Can Leverage Cloud Choice

April 4, 2023

DE&I Dialogue: How the Right DE&I Initiatives Can Propel Your Business

April 5, 2023

White Papers

View all

6 UCaaS Reseller Challenges and How Real World Businesses Solved Them

February 1, 2023

Frost Radar: North American UCaaS Market, 2022

February 1, 2023

The Complete Guide to White-Label UCaaS for Reseller Success

February 1, 2023

Channel Futures TV

View all

Real-Life M&A: Advice for a Successful Channel Deal

Coffee with Craig and James Episode 120: Ronnell Richards

March 3, 2023

XDR Technology: Latest Breakthroughs, How to Talk to Customers

March 1, 2023

Coffee with Craig and James Episode 119: Alliance of Channel Women

February 22, 2023

Twitter

ChannelFutures

.@HPE acquiring @OpsRamp to add capabilities to @HPE_GreenLake. #cloud dlvr.it/SlCFz9

March 20, 2023
ChannelFutures

The relationship between technology advisor (agent) firms, technology service distributors (TSDs) and suppliers is… twitter.com/i/web/status/1…

March 20, 2023
ChannelFutures

.@citrix channel marketing exec Tricia Atkinson is joining @Equinix to lead global partner #marketing.… twitter.com/i/web/status/1…

March 20, 2023
ChannelFutures

.@bizITsolutions announced a partnership with New Charter Technologies. dlvr.it/SlBh09 https://t.co/xpqbQcKC6y

March 20, 2023
ChannelFutures

.@VMware has finalized #PartnerConnect and plans to keep it as-is (minus simplification changes) for years to come.… twitter.com/i/web/status/1…

March 20, 2023
ChannelFutures

Our latest #GatelyReport includes a Q&A with @HuntressLabs, massive ILS #databreach, new @SECGov cyber proposal,… twitter.com/i/web/status/1…

March 20, 2023
ChannelFutures

Channel people making waves include: @MikeSievert, @TheFredVoccola, @Ichhpurani, @mcannonbrookes, @scottfarkas… twitter.com/i/web/status/1…

March 17, 2023

MSP 501

The industry's largest and most comprehensive partner awards program.

Newsletters and Updates

Sign up for The Channel Report, Channel Futures Update, MSP 501 Newsletter and more.

Live Channel Events

Get the latest information on the next industry-leading Channel Partners event.

Galleries

Educational slide shows and images from live events.

Media Kit And Advertising

Want to reach our audience? Access our media kit.

DISCOVER MORE FROM INFORMA TECH

  • Channel Partners Events
  • Telecoms.com
  • MSP 501
  • Black Hat
  • IoT World Today
  • Omdia

WORKING WITH US

  • Contact
  • About Us
  • Advertise
  • Newsletter

FOLLOW Channel Futures ON SOCIAL

  • Privacy
  • CCPA: “Do Not Sell My Data”
  • Cookie Policy
  • Terms
Copyright © 2023 Informa PLC. Informa PLC is registered in England and Wales with company number 8860726 whose registered and Head office is 5 Howick Place, London, SW1P 1WG.
This website uses cookies, including third party ones, to allow for analysis of how people use our website in order to improve your experience and our services. By continuing to use our website, you agree to the use of such cookies. Click here for more information on our Cookie Policy and Privacy Policy.
X