Home / Companies / Bugcrowd / Blog / October 2022

October 2022 Summaries

3 posts from Bugcrowd

Filter
Month: Year:
Post Summaries Back to Blog
At Bugcrowd, a multi-solution, layered approach to crowdsourced security at scale is offered through the Security Knowledge Platform, addressing pain points in fragmented security environments by providing a blend of data, technology, and human intelligence. This platform helps security teams overcome challenges such as poor visibility into security posture, multiple single points of dependency, siloed security data and insights, and overhead in managing multiple providers. The addition of multi-tier program management to the Bugcrowd Platform provides customers with flexibility for solving multiple security goals across assets in pen tests, bug bounties, VDPs, and ASM programs, in any combination, allowing them to manage asset security throughout its lifecycle, share submissions and roles across programs, and get valuable insights from data analytics and reports. This new model unlocks new reporting and insights, reduces administration overhead, allows customers to duplicate engagements with a single click, and provides an intuitive navigation UI, making it easier for security leaders to focus on the big picture and manage their security solutions more efficiently.
Oct 24, 2022 751 words in the original blog post.
At Bugcrowd, customers often ask about growing and improving their bug bounty programs over time. To address these concerns, it's essential to define objectives and metrics for the program as a first step. This will provide a critical tool to measure if the program is on track and healthy, as well as when adjustments are needed. Common success metrics include raw activity (submissions), valid submissions, critical findings, dollar awards, target additions, existence of the program, verified coverage testing, and iterating based on these metrics to increase incentives, grow the crowd, add scope, or other necessary changes.
Oct 20, 2022 889 words in the original blog post.
The cybersecurity landscape has seen significant legislative activity in recent months, with over 250 bills or resolutions introduced or considered by state legislatures in the US alone, addressing various aspects of cybersecurity such as training, funding, and workforce development. The US Congress has also passed several major bills, including requirements for reporting cyber incidents, establishing a cybercrime taxonomy, and promoting cybersecurity education and training. These developments are expected to influence how organizations design and implement their cybersecurity strategies, creating potential burdens for security teams. However, crowdsourced cybersecurity can help solve this problem by providing a platform that brings together multiple security workflows, layers them for maximum risk reduction, and activates the right crowd at the right time. Effective use of such platforms requires careful consideration of best practices to avoid common pitfalls.
Oct 11, 2022 661 words in the original blog post.