Company
Date Published
Author
Grant McCracken
Word count
4751
Language
English
Hacker News points
None

Summary

A larger scope is beneficial for engagement as it increases the time required to find an issue, making it easier for researchers to discover new vulnerabilities, thereby increasing the probability of participation. Increasing the program's scope allows the organization to simulate how attackers would approach their entire attack surface, providing a more accurate and real-world reflection of how attackers engage. This is especially important in open-scope programs, where no asset belonging to the organization is out of scope. Running an open-scope program with a large scope enables the organization to emulate the attacker's approach, making it easier for researchers to find issues and increasing engagement. The value of trust, recognition, and swag cannot be understated in increasing engagement, as they build relationships and provide exclusive experiences that incentivize participation. Engaged program owners created engaged programs; disengaged program owners create disengaged programs, highlighting the importance of treating researchers with respect and building meaningful relationships to increase engagement. Addressing barriers to entry is crucial for a successful program, and running the wrong program type or imposing limitations can lead to low engagement.