Skip to content
Cybersecurity

Bug Bounty

A bug bounty programme rewards external security researchers (ethical hackers) for finding and responsibly disclosing security vulnerabilities in an organisation's systems, applications, or infrastructure. Payouts range from small recognition rewards ($50-500) to high-impact bounties ($10K-$2M+) depending on severity. Major platforms: HackerOne, Bugcrowd, Synack, Intigriti, YesWeHack.

What Is Bug Bounty?

A bug bounty programme rewards external security researchers (ethical hackers) for finding and responsibly disclosing security vulnerabilities in an organisation’s systems, applications, or infrastructure. It complements internal security activities (SAST, DAST, pentesting, red teaming) by tapping into a global community of adversarially-minded experts. Major bug bounty programmes pay millions annually — Apple paid out $20M+ in 2024, Microsoft $13.6M, Google $11.8M.

Bug Bounty vs VDP vs Pentest

Programme typeAudienceCostScopeUse case
Vulnerability Disclosure Programme (VDP)AnyoneFree (just safe harbour)DefinedEntry level — receive reports
Private bug bountyVetted researchersPer findingDefined, narrowMature programmes, sensitive products
Public bug bountyAnyonePer finding (volume)BroadContinuous assurance
Penetration testHired teamFixed feeTime-boxed, narrowCompliance, pre-launch
Red teamHired teamFixed feeWhole orgDetection effectiveness

Leading Platforms (2026)

  • HackerOne — largest by programme count; strong triage; default for many enterprises.
  • Bugcrowd — broad researcher community; good VDP + bug bounty hybrid.
  • Synack — vetted researcher pool; white-glove for enterprise.
  • Intigriti — European-focused; banking-friendly.
  • YesWeHack — French/European with global reach.

Payout Ranges

Typical 2026 ranges:

  • Low / Informational — $50-500
  • Medium — $500-5,000
  • High — $5,000-25,000
  • Critical — $25,000-200,000
  • Top-tier exceptional — $200,000-$2M+ (Apple Security Bounty, Google VRP for Android remote, ZDI for browser RCE chains)

Best Practices for Running a Bug Bounty Programme

  • Start with VDP — at least 6-12 months before paid bounty.
  • Realistic scope — start narrow; expand gradually.
  • Fast triage SLA — researchers leave programmes with slow response times.
  • Competitive payouts — underpaying drives away top researchers.
  • Engineering capacity — don’t start bounty without fix-and-deploy capability.
  • Safe harbour — protect researchers acting in good faith.
  • Transparent rules — clearly defined scope, out-of-scope, severity criteria.

Explore Our Services

Frequently asked questions

+ What is a bug bounty programme in simple terms?

A bug bounty programme is a structured agreement where an organisation invites external security researchers (ethical hackers) to find vulnerabilities in its products and rewards them for responsible disclosure. Researchers test under defined scope and rules, submit findings privately, and receive payment based on severity. Bug bounty complements pentest and SAST/DAST: pentests are time-boxed and team-focused, bug bounty is continuous and crowd-sourced. Major bug bounty programmes (Apple, Google, Microsoft, Meta, US Department of Defense) pay millions annually. Smaller organisations start with free public Vulnerability Disclosure Programmes (VDP) and graduate to paid bug bounty as their security maturity grows.

+ What's the difference between bug bounty and a Vulnerability Disclosure Programme (VDP)?

**VDP** is the entry-level: a publicly-stated channel for receiving vulnerability reports (security.txt + dedicated email/portal). No payment, just a 'safe harbour' commitment that researchers won't be sued for testing. Required by US federal agencies (Cybersecurity Executive Order 14028) and increasingly expected of B2B vendors. **Bug bounty** is paid and managed: scoped invitations to specific researchers, defined targets, severity-based payouts, structured triage. Most organisations should start with a VDP (low cost, high signal); add bug bounty when SOC and engineering can absorb a steady inflow of legitimate findings (typically after 12-24 months of mature pentest + SAST programme).

+ Who are the leading bug bounty platforms?

Five major platforms (2026): (1) **HackerOne** — largest by company count and total payout; default for many enterprise programmes; strong triage services, (2) **Bugcrowd** — broad researcher community, good for VDP and bug bounty, (3) **Synack** — vetted researcher pool, white-glove for enterprise; combines crowd with managed service, (4) **Intigriti** — European-focused; popular in regulated industries (banking), (5) **YesWeHack** — French/European, growing global reach. Other notable: Open Bug Bounty (free, web-only), Cobalt (PtaaS — Pentest as a Service hybrid), Bug-Bounty.gov for US government. Selection: researcher quality, triage SLA, geographic reach, integration with internal tools (Jira, ServiceNow), pricing model (subscription vs payout-only).

+ How do bug bounty payouts work?

Payouts vary widely by programme and severity (CVSS-based or programme-specific). Typical 2026 ranges: (1) **Low/Informational** — $50-500 (configuration issues, info disclosure), (2) **Medium** — $500-5,000 (CSRF, low-impact XSS, IDOR), (3) **High** — $5,000-25,000 (SQL injection, authenticated RCE, account takeover), (4) **Critical** — $25,000-200,000 (unauthenticated RCE, full account takeover with no MFA bypass, infrastructure compromise), (5) **Top-tier exceptional** — $200,000-$2M+ (Apple Security Bounty for kernel/SecureBoot bypass, Google Vulnerability Reward Program for Android remote, ZDI for browser RCE chains). Largest single payout: $2M+ from Apple for full kernel-mode persistence chain. Many programmes also offer reputation points, swag, and 'Hall of Fame' recognition.

+ Bug bounty vs penetration testing — which is better?

Both have distinct strengths and should be combined. **Penetration testing** — time-boxed (1-4 weeks), small expert team, narrow scope, covers everything in scope methodically; produces a comprehensive report; ideal for compliance (PCI-DSS, ISO 27001), pre-launch validation, third-party audits. **Bug bounty** — continuous, large crowd, broad scope, opportunistic (depends on what researchers pursue); produces individual findings; ideal for ongoing assurance, finding edge-case bugs pentest missed, leveraging diverse adversarial perspectives. Mature programmes use: annual external pentest + continuous bug bounty + internal red team + SAST/DAST in CI/CD. Each finds different classes of bugs. Don't see them as competitors; use both.

+ How do you start a bug bounty programme?

Six-phase rollout (typical 6-18 months): (1) **Maturity assessment** — only after established SAST/DAST/pentest programme; bug bounty without that drowns engineering in known issues, (2) **Vulnerability Disclosure Programme (VDP) first** — publish security.txt + safe harbour terms; receive free reports for 6-12 months to test triage capacity, (3) **Define scope** — start narrow (one product, one domain); expand gradually, (4) **Choose platform vs self-managed** — most start on HackerOne/Bugcrowd for triage support; large mature programmes (Apple, Google) self-manage, (5) **Set payouts** — benchmark against similar programmes; underpaying drives away top researchers, (6) **Internal alignment** — engineering must commit to fix SLA (typically 30-90 days); legal must commit to safe harbour; PR ready for inevitable disclosure. Common mistake: starting bug bounty without engineering bandwidth to fix findings.

+ What is responsible / coordinated vulnerability disclosure?

Coordinated Vulnerability Disclosure (CVD), sometimes called responsible disclosure, is the process of reporting a vulnerability privately to the affected vendor, giving them time to fix it, and publishing details only after a patch is available. Standard timeline: 90 days from disclosure to public release (Google Project Zero standard, widely adopted), with extensions for complex fixes. Modern practice (ISO/IEC 29147, US CISA Coordinated Vulnerability Disclosure): vendor must have a clear reporting channel (security.txt, VDP), researcher must avoid extortion or unauthorised access beyond proof-of-concept, both parties communicate transparently. Legal frameworks like the US Computer Fraud and Abuse Act (CFAA) historically chilled research; safe harbour clauses in VDPs/bug bounties protect researchers acting in good faith.

Tags:

bug bounty vulnerability disclosure ethical hacking vdp responsible disclosure

Want to Reduce IT Risk and Costs?

Book a free consultation - we respond within 24h

Response in 24h Free quote No obligations

Or download free guide:

Download NIS2 Checklist