Kyle Sershon – IT Professional

Journal 13 – Bug Bounty Programs

A bug bounty program’s purpose is to identify vulnerabilities that malicious actors could exploit. It also allows smaller companies to strengthen their security posture without the costly price tag of hiring dedicated staff. Bug bounty programs are scalable, so they can help meet the needs of any size company.  The research shows companies in the financial, retail, and health industries have fewer reports than others. The study also found that motives for hackers to participate in these programs vary, but hackers are eager to gain a reputation, and therefore, that is beneficial to a company with a smaller budget. Another finding was that the number of new programs a company has does not affect the number of reports they receive, which may correlate to more talent being available for companies to utilize. Overall, this shows the importance that bug bounty programs have in the cyber security industry as they give companies the ability to patch areas where they are vulnerable while also growing the ethical hacker community and available talent to protect companies and the world from criminal hackers.