AdvisoryCloud & infrastructure
What our bug bounty programme actually cost us this year
Every report we received, what we paid, how long we took, and the things we got wrong. Published because a programme nobody can audit is marketing.
Why publish this
A security programme that only reports its wins is an advert. These are the numbers as they are, including the ones we are not pleased with.
Where we were slow
Our published first-response target is two days. We hit it most of the time. The exceptions were all in the same week, and all for the same reason: one person was away and the rota did not cover it.
What we changed
- Triage is two people now, always.
- Anything critical pages someone rather than waiting in the queue.
- We raised the Critical band, because the old top payout was below what the finding was worth to us.