The Good, the Bad, and the Bounty: 10 Years of Buying Bugs at Microsoft

By Aanchal Gupta , Katie Moussouris on 09 May 2024 @ Rsac
🔗 Link
vulnerability-management bug-bounty risk-management security-governance
Focus Areas: Compliance & Governance , DevSecOps , Risk Management , Security Awareness , Security Governance , Vulnerability Management

Abstract

Bug bounties weren’t always popular, especially not at Microsoft. As Microsoft celebrates 10 years of its bug bounty program, join the creator of its bounties and the current CVP and Deputy CISO to hear never-before shared tales of overcoming institutional and industry-wide reluctance to pay for bugs, lessons learned over the years, and how best to evolve bounties in the future.