luke
2018-01-23 17:00:00
www.hackerone.com
If any industry should readily grasp the concepts of economics and market-based forces, it’s the Financial Services industry. Yet, of the 7,000 or so financial organizations in the United States, only a small handful even have public vulnerability disclosure policies.
So why haven’t Financial Services firms been more open to hacker-powered security, especially given the sensitive financial and personal information they gather and store?
That’s exactly what Sean Sposito, Fraud & Security Analyst at Javelin Strategy & Research, asked a panel of Financial Services security leads during HackerOne’s Security@. The panel included Ty Sbano, Information Security Lead at LendingClub, Arun Agrahri, Product Engineering Executive at Twine by John Hancock, and Philip Martin, Director of Security at Coinbase.
From left to right: Sean Sposito, Arun Agrahri, Ty Sbano, and Philip Martin on stage at Security@ San Francisco
The biggest challenge, the panel explained, is their industry’s legacy approach to business in general. “Some of these companies are 100 years old,” said Arun. He added that even their own technology is built by others. So it’s not an industry problem, he explained, it’s a gap between incumbent firms and the newer Fintech companies.
Phillip, who mentioned that Coinbase just upped their top bounty award to $50,000, pointed to the Financial Services back office as part of the challenge. “You can’t just go to finance and tell them you’re paying 10 Bitcoin to some dude on the internet,” he added. The legal, financial, and regulatory hurdles are just too risky for most of these companies.
But the tide is shifting, and firms are realizing that the economics of hacker-powered security outweigh the risks. Arun explained how bounty programs are more cost-effective than expanding an internal security team. Ty mentioned incentives, and how bounty programs provide positive incentives for both sides. And, Phillip added that it also gives hackers a way to get a return on their own time investment.
Watch the full “Breaking the Bank” session to learn more about how progressive Financial Services companies are leveraging hacker-powered security to safeguard their customers.
HackerOne is the #1 hacker-powered security platform, helping organizations find and fix critical vulnerabilities before they can be criminally exploited. As the contemporary alternative to traditional penetration testing, our bug bounty program solutions encompass vulnerability assessment, crowdsourced testing and responsible disclosure management. Discover more about our security testing solutions or Contact Us today.
Keep your files stored safely and securely with the SanDisk 2TB Extreme Portable SSD. With over 69,505 ratings and an impressive 4.6 out of 5 stars, this product has been purchased over 8K+ times in the past month. At only $129.99, this Amazon’s Choice product is a must-have for secure file storage.
Help keep private content private with the included password protection featuring 256-bit AES hardware encryption. Order now for just $129.99 on Amazon!
Help Power Techcratic’s Future – Scan To Support
If Techcratic’s content and insights have helped you, consider giving back by supporting the platform with crypto. Every contribution makes a difference, whether it’s for high-quality content, server maintenance, or future updates. Techcratic is constantly evolving, and your support helps drive that progress.
As a solo operator who wears all the hats, creating content, managing the tech, and running the site, your support allows me to stay focused on delivering valuable resources. Your support keeps everything running smoothly and enables me to continue creating the content you love. I’m deeply grateful for your support, it truly means the world to me! Thank you!
BITCOIN bc1qlszw7elx2qahjwvaryh0tkgg8y68enw30gpvge Scan the QR code with your crypto wallet app |
DOGECOIN D64GwvvYQxFXYyan3oQCrmWfidf6T3JpBA Scan the QR code with your crypto wallet app |
ETHEREUM 0xe9BC980DF3d985730dA827996B43E4A62CCBAA7a Scan the QR code with your crypto wallet app |
Please read the Privacy and Security Disclaimer on how Techcratic handles your support.
Disclaimer: As an Amazon Associate, Techcratic may earn from qualifying purchases.