FinAi News

No products in the cart.

Subscribe
  • News
  • AI News Tool
  • Data
  • Transactions
  • Events
    • FinAi Banking Summit
    • FinAi Lending Summit
  • Podcast
  • WEBINARS
    • Webinar Library
Log In
No Result
View All Result
  • Banking
  • Lending
  • Payments
  • Risk & Security
  • Strategy
FinAi News
  • News
  • AI News Tool
  • Data
  • Transactions
  • Events
    • FinAi Banking Summit
    • FinAi Lending Summit
  • Podcast
  • WEBINARS
    • Webinar Library
BAN PLUS
Log In
No Result
View All Result
FinAi News
No Result
View All Result

More FIs Paying More for Bug Bounties, Report Says

Jake MartinbyJake Martin
October 31, 2018
in Risk & Security
Reading Time: 3 mins read
0
Share on Facebook

It’s no secret financial services and insurance companies hold some of the most sensitive personal and financial data that hackers desire and target regularly.

Although the entire industry has paid just $1.4 million in bug bounties to date, more than half that amount was paid out in just the past year, according to a recent report from HackerOne.

The Hacker-Powered Security Report for 2018 includes analysis of 78,275 security vulnerability reports filed over the past year by ethical hackers through more than 1,000 HackerOne programs.

Financial services and insurance ranked fourth among all industries, accounting for 8% of all new programs launched, far behind technology but well ahead of government, retail, and transportation.

“While adoption of hacker-powered security is growing faster than ever, there is significant room for improvement,” the report said. “This is especially true in this industry, considering the potentially devastating impact—to individuals, organizations, and entire economies—any security breach could have.”

The industry pays low bounty amounts for critical bugs. An average reward this year of $1,118 may be double what it was the previous year, at $646, but it’s still lower than what one-third of the top industries are paying out. For comparison, the government pays an average of $3,892 and the tech industry pays an average of $3,635.

However, the industry posted the second-fastest average time to resolve bugs.

“This reflects a desire to fix bugs as soon as possible, quickly mitigating any potential risk,” the report said. “It also reflects a significant increase from the previous year, nearly cutting the average in half.”

Payment to hackers is also pretty fast, at an average of 19 days, which is within days of the fastest industries. Rewards typically come less than 3 weeks after a bug is first reported.

“This speed attracts more and better hackers, and is literally weeks faster than some other industries,” the report said. “It’s also more than a week faster than the previous year’s average.”

The top bounty awarded the past year by a financial services or insurance organization is near the middle of the pack. The industry’s top award was neither high nor low, at $18,000, but well below the $75,000 top bounty paid by the tech industry.

“It did, however, nearly double year over year,” the report continued.

According to the 2017 Cost of Cyber Crime Study by Accenture and Ponemon Institute, financial services had the highest average annualized cost of cybercrime, at nearly $18.3 million, out of 15 major industries.

The study also found companies deploying security intelligence systems, on average, can experience a cost savings of $2.8 million. Investment in other security technologies and measures can save companies lesser amounts, the study said.

The HackerOne report says more financial companies are prioritizing hacker-powered security against cyber risk, including Goldman Sachs, American Express, Lending Club, Coinbase, and Augur.

According to the report, Goldman Sachs is one of the few financial services and insurance organizations with a public vulnerability disclosure policy (VDP), commonly called the “see something, say something” of the internet.

“Their security team is extremely fast at following up with discoverers, with an average response time of just 5 hours,” the report said of Goldman Sachs. “And a full resolution of bugs is typically completed in just 29 days. In the first 3 months of their public VDP being listed on HackerOne, Goldman Sachs resolved 20 vulnerabilities and thanked 9 hackers.”

The report said the industry overall has just 7% public VDP coverage, compared to the 47% of technology companies that have public VDPs.

A VDP essentially tells hackers how to submit vulnerability reports and how those reports will be handled by an organization.

Nearly 1 in 4 hackers have not reported vulnerabilities they found because the company didn’t have a channel for disclosure, according to the report.

“Having a VDP in place reduces the risk of a security incident and places the organization in control of what would otherwise be a chaotic or nonexistent workflow,” the report said.

Tags: cybercrimecybersecurityExclusiveGoldman SachshackingPremium
Previous Post

Zelle Considers a Better Way for Digital Gifting

Next Post

Can QR Codes Make It in America? SwiftPass Thinks So

Related Posts

Two people, who are made of data streams, shake hands
Risk & Security

Implementing AI for AML requires resolute leadership, comprehensive data

July 22, 2026
The OpenAI logo on a laptop computer arranged in the Brooklyn borough of New York, US, on Thursday, Jan. 12, 2023. Microsoft Corp. is in discussions to invest as much as $10 billion in OpenAI, the creator of viral artificial intelligence bot ChatGPT, according to people familiar with its plans. Photographer: Gabby Jones/Bloomberg
Risk & Security

OpenAI models breach Hugging Face, sparking cyber alarms

July 22, 2026
data streams being bottlenecked
Risk & Security

Implementing AI can relieve bottlenecks amid growing AML complexity

July 20, 2026
Next Post
© Can Stock Photo / bizoon

Can QR Codes Make It in America? SwiftPass Thinks So

EMERGING FINTECH DIRECTORY

Emerging Fintech Directory

The Buzz Podcast

SPONSORED

Build an Antifragile Strategy to Outperform the Market

July 14, 2026

How AI and Product Experts Turn Fuzzy Requirements Into Focused Dev-ready Roadmaps

April 19, 2026

Is Your Technology Supplier There for You?

April 1, 2026

  • About Us
  • Help Center
  • Contact Us
  • Privacy Terms
  • ADA Compliance
  • Advertise

 [wt_cli_manage_consent]

Connect

twitter linkedin podcast podcast podcast
© 2026 Royal Media
No Result
View All Result
  • NEWS
    • All News
    • Banking
    • Lending
    • Payments
    • Risk & Security
    • Strategy
  • AI News Tool [Beta]
  • DATA
  • TRANSACTIONS
  • EVENTS
    • FinAi Banking Summit
    • FinAi Lending Summit
  • PODCAST
  • WEBINARS
    • Webinar Library
  • SUBSCRIBE
  • Log In / Account

Welcome Back!

Login to your account below

Forgotten Password?

Retrieve your password

Please enter your username or email address to reset your password.

Log In

Unlock This Article

Create your free FinAi News account to access this article and stay informed on how AI is transforming financial services including banking, lending, payments, and risk.

Yes, I'd like to receive FinAi News updates, breaking news, and exclusive AI insights for financial services leaders.

Continue Reading with FinAi News Premium - Less than $2/Day

Upgrade to FinAi News Premium for unlimited access to news, insights, trends, and intelligence on how AI is transforming financial services including banking, lending, payments, and risk.
Upgrade to FinAi News Premium Subscription
No Result
View All Result
  • NEWS
    • All News
    • Banking
    • Lending
    • Payments
    • Risk & Security
    • Strategy
  • AI News Tool [Beta]
  • DATA
  • TRANSACTIONS
  • EVENTS
    • FinAi Banking Summit
    • FinAi Lending Summit
  • PODCAST
  • WEBINARS
    • Webinar Library
  • SUBSCRIBE
  • Log In / Account