Overview
Direct Answer
A crowdsourced security initiative in which organisations offer monetary rewards to external researchers who identify and responsibly disclose software vulnerabilities before public exploitation. This model leverages distributed expertise to uncover defects that internal testing may overlook.
How It Works
Organisations publish vulnerability scope, submission guidelines, and reward tiers on dedicated platforms or websites. Security researchers probe applications, systems, or infrastructure within defined parameters, document findings with proof-of-concept evidence, and submit reports through controlled channels. The organisation validates each submission, assigns severity ratings, and disburses payment upon verification and remediation.
Why It Matters
The approach substantially reduces time-to-discovery for critical flaws while distributing security assessment costs across a global talent pool. Organisations gain access to specialised expertise at lower expense than maintaining equivalent internal security teams, whilst researchers earn income for specialist work.
Common Applications
Major software vendors, financial services platforms, cloud infrastructure providers, and consumer technology firms operate ongoing programmes. Technology companies including Microsoft, Google, and Apple maintain active initiatives; financial institutions and healthcare providers similarly utilise the model to protect sensitive systems.
Key Considerations
Programmes require clear scope definition and legal frameworks to prevent scope creep and litigation. Reward calibration and response timeliness directly influence researcher participation rates and data quality; poorly managed initiatives risk reputational damage or delayed vulnerability remediation.
More in Cybersecurity
Encryption
Data ProtectionThe process of converting plaintext data into ciphertext using an algorithm, making it unreadable without the decryption key.
Next-Generation Firewall
Defensive SecurityAn advanced firewall that goes beyond traditional packet filtering to include application awareness and intrusion prevention.
Software Bill of Materials
Offensive SecurityA comprehensive inventory of all software components, libraries, and dependencies used in an application, enabling vulnerability tracking and supply chain risk management.
Cloud-Native Application Protection
Offensive SecurityAn integrated security platform that protects cloud-native applications across the full lifecycle, combining workload protection, configuration management, and runtime security.
Biometric Authentication
Identity & AccessUsing unique biological characteristics like fingerprints, facial features, or iris patterns to verify identity.
Extended Detection and Response
Offensive SecurityA unified security platform that integrates multiple security tools and data sources for comprehensive threat detection.
Compliance Framework
Security GovernanceA structured set of guidelines and best practices for meeting regulatory requirements and industry standards.
End-to-End Encryption
Data ProtectionA communication system where only the communicating users can read the messages, with encryption at both endpoints.