Which of the following vulnerability management services, if any, do you use at your organization?

HackerOne18%

Bugcrowd29%

Synack14%

Intigriti6%

We're not using a bug bounty platform right now.28%

Other (please comment below!)3%


558 PARTICIPANTS

2.6k views3 Comments

CIO in Software, 51 - 200 employees
Microsoft Defender for Endpoint and Other Microsoft Defender Products
2
Director, Information Security in Education, 1,001 - 5,000 employees
We use Tenable & Defender for Endpoint for vulnerability mgmt on servers and endpoints, respectively.

We aren’t using any big bounty programs since we are phasing out what little in-house code we’ve got and everything else is really apps (on prem or in-cloud) from huge multi billion dollar corps while, as a school, our total budget is in tens of millions of dollars. We can’t really justify what would effectively be subsidizing but bounties for vendors with revenues hundreds to thousands times larger than us. These programs do have value and I think they’re great overall but in our case there isn’t much of such.
Director of IT, Self-employed
bugbane

Content you might like

CTO in Software, 201 - 500 employees
Without a doubt - Technical Debt! It's a ball and chain that creates an ever increasing drag on any organization, stifles innovation, and prevents transformation.
Read More Comments
42.6k views131 Upvotes319 Comments

Not at all15%

Experimenting67%

A fair amount16%

Extensively3%


227 PARTICIPANTS

917 views

Production45%

Backup64%

Replication34%

Non-production DBs (Dev, Training, QA, etc.)30%


210 PARTICIPANTS

1.2k views1 Upvote