Security News > 2024 > February > Crowdsourced security is not just for tech companies anymore

Crowdsourced security is not just for tech companies anymore
2024-02-02 05:00

There is a misconception that only software and technology companies leverage crowdsourced security.

Companies across various sectors are increasingly adopting crowdsourced security, as reported by Bugcrowd.

The government industry sector saw the fastest growth for crowdsourced security in 2023 compared to 2022, with a 151% increase in vulnerability submissions and a 58% increase in Priority 1 rewards for finding critical vulnerabilities.

The "Human risk factor" will also become more dangerous based on actions by malicious insiders and misguided employees who fall prey to social engineering attacks or bypassing internal controls operationally, countering the "Cyber talent skills gap" and help their security teams "Scale" - organizations will certainly and more broadly adopt the crowdsourcing of human intelligence to continuously weed out unique or previously unidentified vulnerabilities that smaller, less diverse, budget, or talent strapped teams just can't.

In the past year, enterprises also increasingly favored public crowdsourced programs over private ones, while programs with open scopes received 10X more P1 vulnerabilities than those with limited scopes.

The crowdsourced security industry has matured over the course of the last decade, and even though many still view it as a new part of the security technology stack, there is no denying that the industry is evolving.


News URL

https://www.helpnetsecurity.com/2024/02/02/crowdsourced-security-growth/