Learn/Advisory
AdvisoryCloud & infrastructure

What our bug bounty programme actually cost us this year

Every report we received, what we paid, how long we took, and the things we got wrong. Published because a programme nobody can audit is marketing.

ncNorthwind CloudAug 2026 · 3 min read

Why publish this

A security programme that only reports its wins is an advert. These are the numbers as they are, including the ones we are not pleased with.

Where we were slow

Our published first-response target is two days. We hit it most of the time. The exceptions were all in the same week, and all for the same reason: one person was away and the rota did not cover it.

What we changed

  1. Triage is two people now, always.
  2. Anything critical pages someone rather than waiting in the queue.
  3. We raised the Critical band, because the old top payout was below what the finding was worth to us.
← More from Learn