I’ve been doing security bug hunting, penetration tests and managing in-house bug bounty programs for various companies, for over half a decade already. During that time I learnt that it doesn’t really happen too often that hiring company knows exactly what to do with security engagements results.
I’d like to help and suggest what you can do to fully benefit from what you paid for.
I’ve been thinking quite a lot about coming up with a series of articles on how to secure small and medium organizations from the ground up. It was waiting for the right moment and it’s time to start it out, especially that very recently this question appeared on Peerlyst where I’ve put my $0.02 on that subject. So as there is a need for decent guidance, let me welcome you to first article from series “Securing the business from the ground up”. Expect more articles on subject similar to this.
I’ve seen many companies struggling with a choice between penetration tests and bug bounties, and in the era of overhyped BugBounty programs this is a big question, both for PR/marketing and security teams.
There are as many answers to “pentest or bugbounty” as many people you ask. Everyone has slightly different POV on this, so I suggest you to gather opinions from many people and decide yourself what works best for your business.
I want to approach this from a bit different angle than I’ve seen so far, so this should be an interesting read for you. Continue reading “Pentests vs BugBounty for startups and SMBs”→