{"id":334,"date":"2025-08-07T09:06:54","date_gmt":"2025-08-07T09:06:54","guid":{"rendered":"https:\/\/sites.wp.odu.edu\/gonzalezcybersite\/?p=334"},"modified":"2025-08-07T09:14:54","modified_gmt":"2025-08-07T09:14:54","slug":"cyse-201s-module-11-journal-entry-2","status":"publish","type":"post","link":"https:\/\/sites.wp.odu.edu\/gonzalezcybersite\/2025\/08\/07\/cyse-201s-module-11-journal-entry-2\/","title":{"rendered":"CYSE 201S Module 11 Journal Entry 2                        Bug Bounty Policies"},"content":{"rendered":"\n<p> As I was reading the article, I was fascinated, and had no idea about bug bounty<\/p>\n\n\n\n<p>policies or programs&#8217; real effect at the business scale. I can understand why a lot of<\/p>\n\n\n\n<p>businesses are dubious about third-party companies reporting cybersecurity flaws and<\/p>\n\n\n\n<p>vulnerabilities. Nobody wants to get strangers into their own backyards and find out their<\/p>\n\n\n\n<p>most intimate secrets per say, this fear is preventing companies from finding blind spots.<\/p>\n\n\n\n<p>As I keep on reading, the point of view is swiftly changing to the point that it is becoming<\/p>\n\n\n\n<p>a big business that has reached hundreds of millions of dollars in bounty revenue.<\/p>\n\n\n\n<p>Companies are even taking things a step further by taking part in bug bounty markets,<\/p>\n\n\n\n<p>where independent security researchers\u2014also known as ethical hackers\u2014are hired to<\/p>\n\n\n\n<p>locate flaws in business IT systems, and code bases and persuasively communicate<\/p>\n\n\n\n<p>vulnerabilities for them to be able to create better cybersecurities in their systems.<\/p>\n\n\n\n<p>But again companies are trying to keep their evaluations and vulnerabilities private,<\/p>\n\n\n\n<p>which prevents future studies, the lack of paperwork is limited to none, is not publicly<\/p>\n\n\n\n<p>available, and there is a struggle to establish research so it has to be based on<\/p>\n\n\n\n<p>observations which might not be as effective as the raw data from a valid report.<\/p>\n\n\n\n<p>Learning how big companies are being successful by implementing these policies, and<\/p>\n\n\n\n<p>how ethical hackers are getting compensated, I might want to head in that job field to<\/p>\n\n\n\n<p>get hefty rewards while companies still maintain a cost-effective budget, like stated in<\/p>\n\n\n\n<p>the reading it is cheaper than hiring two full time IT positions.<\/p>\n\n\n\n<p>This research paper has the economic principles written all over it, by literally explaining<\/p>\n\n\n\n<p>how beneficial cost-benefit analysis comes into play by deciding the reward money and<\/p>\n\n\n\n<p>the loss by limiting hacks that will interrupt operations for the company. It is just amazing<\/p>\n\n\n\n<p>how everything comes into play all together.<\/p>\n\n\n\n<p>The findings of the research are fascinating, stating the obvious. That bug bounties are<\/p>\n\n\n\n<p>very effective tools, no matter the size of the company, it discovered that depending on<\/p>\n\n\n\n<p>the type of company, some might receive fewer reports.<\/p>\n\n\n\n<p>Companies need to make an effort to make at least some of the findings available, to be<\/p>\n\n\n\n<p>able to create a better understanding, because we know very little about this market. By<\/p>\n\n\n\n<p>increasing our knowledge, ethical hacking might be a new way to combat cyberattacks,<\/p>\n\n\n\n<p>enhancing our comprehension of an increasingly needed new cybersecurity tool.Resource:<\/p>\n\n\n\n<p>Kiran Sridhar, Ming Ng, Hacking for good: Leveraging HackerOne data to develop an<\/p>\n\n\n\n<p>economic model of Bug Bounties, <em>Journal of Cybersecurity<\/em>, Volume 7, Issue 1, 2021,<\/p>\n\n\n\n<p>tyab007, https:\/\/doi.org\/10.1093\/cybsec\/tyab007<\/p>\n","protected":false},"excerpt":{"rendered":"<p>As I was reading the article, I was fascinated, and had no idea about bug bounty policies or programs&#8217; real effect at the business scale. I can understand why a lot of businesses are dubious about third-party companies reporting cybersecurity flaws and vulnerabilities. Nobody wants to get strangers into their own backyards and find out&#8230; <\/p>\n<div class=\"link-more\"><a href=\"https:\/\/sites.wp.odu.edu\/gonzalezcybersite\/2025\/08\/07\/cyse-201s-module-11-journal-entry-2\/\">Read More<\/a><\/div>\n","protected":false},"author":30571,"featured_media":0,"comment_status":"open","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"footnotes":"","wds_primary_category":0},"categories":[1],"tags":[],"_links":{"self":[{"href":"https:\/\/sites.wp.odu.edu\/gonzalezcybersite\/wp-json\/wp\/v2\/posts\/334"}],"collection":[{"href":"https:\/\/sites.wp.odu.edu\/gonzalezcybersite\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/sites.wp.odu.edu\/gonzalezcybersite\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/sites.wp.odu.edu\/gonzalezcybersite\/wp-json\/wp\/v2\/users\/30571"}],"replies":[{"embeddable":true,"href":"https:\/\/sites.wp.odu.edu\/gonzalezcybersite\/wp-json\/wp\/v2\/comments?post=334"}],"version-history":[{"count":2,"href":"https:\/\/sites.wp.odu.edu\/gonzalezcybersite\/wp-json\/wp\/v2\/posts\/334\/revisions"}],"predecessor-version":[{"id":344,"href":"https:\/\/sites.wp.odu.edu\/gonzalezcybersite\/wp-json\/wp\/v2\/posts\/334\/revisions\/344"}],"wp:attachment":[{"href":"https:\/\/sites.wp.odu.edu\/gonzalezcybersite\/wp-json\/wp\/v2\/media?parent=334"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/sites.wp.odu.edu\/gonzalezcybersite\/wp-json\/wp\/v2\/categories?post=334"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/sites.wp.odu.edu\/gonzalezcybersite\/wp-json\/wp\/v2\/tags?post=334"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}