How Can Companies Build Trust With Ethical Hackers?

251 views
•
February 27, 2020
by
RSAC Cybersecurity
YouTube video player
How Can Companies Build Trust With Ethical Hackers?

TL;DR

Companies should begin with a vulnerability disclosure program that gives hackers clear contact information, readable policies, defined scope, and transparent reward expectations. Consistent communication then builds bilateral trust, reduces fear of prosecution, and encourages researchers to report vulnerabilities instead of withholding findings that organizations could have fixed earlier.

Transcript

Good afternoon. We are here at RSA 2020. We're back with Chloe Messdaghi. Did I- You said that right ... pronounce that correctly? You did a good job. Okay, good. Good. I, I'll give you a elbow- ... since this is the trend now. Oh, yes, yes. There we go. So Chloe, your, your, your title is Vice President of Strategy? Yes. At Point3, right? Yes. Uh,... Read More

Key Insights

  • Point3 is an education-focused security company that provides capture-the-flag challenges, hundreds of training modules, and assessments for security teams. Its exercises are intended primarily to strengthen red-team skills, although blue and purple team members can also benefit from understanding offensive methods.
  • Role swapping is a practical way for security professionals to understand opposing perspectives. Blue team members benefit from learning how red team members think and operate, while offensive practitioners can gain insight into defensive work and the reasoning used by security hunters.
  • Gamified security education helps teams identify both strengths and missing capabilities. Point3 uses challenges and leaderboards so practitioners can see where they stand, while managers can review performance and recognize skill gaps that could leave their organizations vulnerable.
  • Fear of prosecution discourages many hackers from reporting vulnerabilities. Messdaghi cites a figure of about 60% and argues that outdated laws can stop well-intentioned researchers from disclosing weaknesses that organizations might otherwise have corrected much earlier.
  • Hackers' rights require cooperation among media, organizations, and legislators. Media and marketing can improve public awareness, companies can establish responsible disclosure practices, and politicians can pursue legal changes that protect organizations and researchers while supporting beneficial security work.
  • A vulnerability disclosure program is the recommended first step before launching a bug bounty. It should publish clear contact information so researchers know exactly where to report a weakness instead of spending hours or days searching for someone who can receive it.
  • Good communication is essential to a sustainable bug bounty relationship. Organizations and any platform they hire should keep hackers informed because clear, current communication makes researchers more willing to participate again and helps preserve trust between all parties.
  • Clear policies should explain scope, reporting contacts, and any available rewards in language that is easy to understand. Disclose.io is recommended as a source for readable disclosure policies and information about organizations considered safer for researchers who remain within scope.

Install to Summarize YouTube Videos and Get Transcripts

Explore YouTube Video Summarizer or Get YouTube Transcript Extractor

Questions & Answers

Q: How should a company start working with ethical hackers?

A company should begin by creating a vulnerability disclosure program and publishing clear contact information online. Researchers need to know exactly where to submit a vulnerability and who can help get it fixed. Without an obvious reporting channel, finding the correct recipient can take hours or days, increasing anxiety about prosecution and making researchers less likely to disclose their findings.

Q: Why do some hackers avoid reporting security vulnerabilities?

Many hackers worry that reporting a vulnerability could expose them to prosecution, even when they intended to help. Messdaghi cites a figure of about 60% who will not report a vulnerability because of this concern. She argues that outdated laws contribute to the problem, leaving weaknesses unresolved even though they might have been fixed much earlier through responsible reporting.

Q: What information should a vulnerability disclosure policy include?

A vulnerability disclosure policy should provide a clear reporting contact, readable instructions, the permitted scope, and information about any rewards a researcher might receive. The language should be easy to understand, particularly because English is not the first language of many hackers. These elements clarify expectations and begin building bilateral trust between researchers and organizations.

Q: Why is communication important in a bug bounty program?

Good communication keeps hackers informed about their submissions and encourages them to participate in the program again. Organizations, researchers, and any hired bug bounty platform need to communicate consistently across the process. Clear updates also help address whether a report is a duplicate, outside the defined scope, or a vulnerability that requires action from the company.

Q: What do bug bounty platforms do for organizations?

Bug bounty platforms such as HackerOne, BugCrowd, or Synack can act as intermediaries between hackers and organizations. According to the discussion, a platform can assess how significant a vulnerability is, determine whether it duplicates an earlier report, identify submissions that fall outside scope, and work directly with researchers so the organization does not have to manage every part alone.

Q: Why should blue and red security teams exchange roles?

Exchanging roles helps each side understand how the other thinks and operates. A blue team member can become more effective by studying offensive techniques, while someone working offensively can benefit from seeing the defender's perspective. The interview frames this cross-training as especially useful for security hunters, who need to anticipate the thinking and behavior of the opposing side.

Q: How does gamified cybersecurity training help security teams?

Gamified training gives practitioners structured challenges that test and develop their capabilities. Leaderboards allow participants to see where they stand, while performance information helps managers discover skills that employees possess and areas where the team still needs improvement. Point3 uses this approach to educate security professionals and identify missing capabilities that could create organizational vulnerabilities.

Q: Who must cooperate to improve protections for hackers?

Messdaghi identifies three parties that need to work together: media, organizations, and legislators. Media, including news and marketing, can increase public awareness. Companies can improve their policies and relationships with researchers. Politicians can become involved in changing laws. Their combined efforts can support protections for both organizations and hackers engaged in beneficial vulnerability research.

Summary & Key Takeaways

  • Chloe Messdaghi describes Point3 as an education-focused security company offering capture-the-flag challenges and hundreds of training modules. Its platform helps red, blue, and purple team members improve their abilities, compare performance through leaderboards, and reveal skill gaps that managers might otherwise overlook when assessing the strength of a security team.

  • Messdaghi became a hackers' advocate after observing that researchers often avoid reporting vulnerabilities because they fear prosecution. She cites a figure of about 60% and argues that outdated laws can prevent well-intentioned hackers from helping organizations fix security problems before those weaknesses create more serious situations.

  • Organizations considering bug bounties should first establish a vulnerability disclosure program with clear contact details and accessible policies. They must define scope, explain possible rewards, maintain timely communication, and understand the operational demands. Third-party platforms can serve as intermediaries by evaluating submissions, duplicates, severity, and scope while coordinating with researchers.


Read in Other Languages (beta)

Share This Summary 📚

Explore More Summaries from RSAC Cybersecurity 📚