The paper emphasizes the value of bug bounty programs in improving cybersecurity and offers details on the variables affecting their efficacy. It describes the process, which includes gathering data from HackerOne and addressing endogeneity with narrative tools. It does, however, recognize certain drawbacks, including bias resulting from missing variables and difficulties assessing problem severity.