ABA Banking Journal
No Result
View All Result
  • Topics
    • Ag Banking
    • Commercial Lending
    • Community Banking
    • Compliance and Risk
    • Cybersecurity
    • Economy
    • Human Resources
    • Insurance
    • Legal
    • Mortgage
    • Mutual Funds
    • Payments
    • Policy
    • Retail and Marketing
    • Tax and Accounting
    • Technology
    • Wealth Management
  • Newsbytes
  • Podcasts
  • Magazine
    • Subscribe
    • Advertise
    • Magazine Archive
    • Newsletter Archive
    • Podcast Archive
    • Sponsored Content Archive
SUBSCRIBE
ABA Banking Journal
  • Topics
    • Ag Banking
    • Commercial Lending
    • Community Banking
    • Compliance and Risk
    • Cybersecurity
    • Economy
    • Human Resources
    • Insurance
    • Legal
    • Mortgage
    • Mutual Funds
    • Payments
    • Policy
    • Retail and Marketing
    • Tax and Accounting
    • Technology
    • Wealth Management
  • Newsbytes
  • Podcasts
  • Magazine
    • Subscribe
    • Advertise
    • Magazine Archive
    • Newsletter Archive
    • Podcast Archive
    • Sponsored Content Archive
No Result
View All Result
No Result
View All Result
Home Compliance and Risk

Overcoming the challenges of vulnerability disclosure programs 

May 19, 2022
Reading Time: 3 mins read
Overcoming the challenges of vulnerability disclosure programs 

By Ashish Gupta

At its core, security isn’t a technology problem—it’s a people problem. To compete against an army of malicious hackers and stay ahead of their strikes, what’s needed is an equivalent army of human allies who can dig into software code to find the root causes of security vulnerabilities.

This situation is somewhat comparable to communities with Neighborhood Watch programs that encourage neighbors to report any suspicious activities to maintain a shared sense of security. If you saw your next-door neighbors’ garage door was left open all night, you probably would notify them about it, and hope they would do the same for you.

rightwards arrow
View more
risk and compliance articles

In a similar way, vulnerability disclosure programs provide a secure platform for ethical hackers to report any security vulnerabilities to organizations including banks and financial institutions. A typical vulnerability disclosure program, or VDP, is based on a framework that compiles researcher findings whenever they discover new bugs or threats. Such programs also include a triage process to prioritize security risks, report them to the organization and provide workflows to remediate any problems that are found.

VDPs provide a publicly available channel for researchers to submit security vulnerabilities to an organization. Vulnerability disclosure programs are an effective way to report potential security risks in a formalized and consistent manner. They also include a channel for the reporter to be notified that the receiver got the message.

This approach helps establish a “see something, say something” mindset within an organization. In this way, VDPs mitigate risks by enabling the disclosure and remediation of vulnerabilities before they can be exploited by bad actors. For this reason, a VDP should be a baseline security standard for every organization, just as common as a firewall.

Overcoming complexity when creating a VDP

In the case of a bank, the potential attack surface grows as the organization increases in size. That escalation can quickly spiral out of control as security vulnerabilities proliferate, overwhelming security teams with a flood of incoming reports.

For this reason, VDPs require some method to triage the security risks coming from researchers and prioritize the most pressing problems for immediate attention and remediation. In cases known as “responsible disclosure,” the vulnerability is only disclosed after there has been enough time to patch or close the issue. Since developers require some time to create a fix, the disclosure timeframe can range from a few days to several months.

Other cases involve “full disclosure” when the vulnerability is disclosed as early as possible. Full disclosure makes the information accessible to the public, which increases the risk of exploitation, but it also provides for wider research support and advanced preparation. The goal with full disclosure is to notify affected parties immediately so they can take the needed precautionary steps.

Large financial organizations are recognizing that malware is a publicly available commodity that makes it easy for anyone to become an adversary. At the same time, many companies have maintained brittle security solutions that make it harder to defend against current attacks. Security researchers or hackers undergo a vetting period at Bugcrowd. VDPs are a great way to test skills, improve performance metrics and build reputation.

Creating a dynamic channel for shared communications

The solution to this ongoing security threat is to create a vulnerability disclosure program, an essential tool for any layered cybersecurity approach. In effect, a VDP opens a communication channel to external researchers, while also encouraging current customers who use a bank’s products and services to participate in the feedback loop. By opening such a reporting channel to an army of ethical security researchers and regular consumers, financial organizations can demonstrate their commitment to protecting their digital assets and customers, while also responding quickly to address known risks.

An effective VDP carves out a global channel for vulnerability reports and publicly demonstrates that your bank is doing everything possible to protect its customers, partners and suppliers. Use of VDPs is a great way to proactively get vulnerabilities reported. However, VDPs are not appropriate for continuous, active threat testing. They also are not intended to find the most serious security vulnerabilities. In addition, VDPs cannot focus testing on a particular area, and they cannot restrict researcher access.

VDPs encourage researchers to report any threats they find in internet-facing assets for a predictable cost. In contrast to bug bounties, submissions are not incentivized by cash rewards. Providing recognition after the vulnerability has been resolved is one way to incentivize a researcher. Publishing a vulnerability report after it has been fixed is another common attribute of a VDP, which gives researchers an opportunity to share their knowledge. Such VDP initiatives work to enhance an organization’s reputation for taking cybersecurity seriously, while also fulfilling its mandatory compliance requirements.

Ashish Gupta is CEO and president of Bugcrowd.

Tags: CybersecurityData security
ShareTweetPin

Related Posts

Treasury seeks comment on changes to foreign investor review process

Treasury seeks comment on changes to foreign investor review process

Compliance and Risk
February 6, 2026

The Treasury Department is seeking public input on the Known Investor Program and ways to potentially streamline aspects of its foreign investment review process.

Bessent fields lawmaker questions on crypto and deposits, CDFI Fund

Bessent fields lawmaker questions on crypto and deposits, CDFI Fund

Community Banking
February 5, 2026

In his second day of congressional testimony, Treasury Secretary Scott Bessent said he will work to ensure there is “no deposit volatility” associated with a market structure bill for digital assets currently before Congress.

Treasury Department awards grants to boost local economies after COVID

Bankers share ideas for strengthening communities in new report

Community Banking
February 5, 2026

The ABA Foundation unveiled a first-of-its-kind report capturing forward-looking ideas from bankers, community leaders and nonprofit partners on how financial institutions can drive meaningful economic and community impact in the decades ahead.

ABA Fraudcast: Taking the fraud prevention message directly to lawmakers

Podcast: How the SCAM Act would encourage platforms to go after scammers

ABA Banking Journal Podcast
February 4, 2026

Major tech platforms make billions of dollars from scammers who advertise on their sites, according to reporting from Reuters, and there’s not much incentive for them to change their practices — yet.

ABA, BPI seek transparency around Fed stress tests

Fed finalizes annual stress test scenarios for large banks

Compliance and Risk
February 4, 2026

The Federal Reserve finalized the hypothetical scenarios for its annual stress test for large banks. In addition, the Fed board voted to maintain the current stress capital buffer requirements until 2027.

Senators introduce bill requiring online platforms to crack down on scam ads

Senators introduce bill requiring online platforms to crack down on scam ads

Compliance and Risk
February 4, 2026

Two senators have introduced bipartisan legislation directing social media companies and other online media providers to take steps to fight fraudulent advertisements on their platforms. ABA supports the legislation.

NEWSBYTES

Treasury seeks comment on changes to foreign investor review process

February 6, 2026

ABA offers recommendations for mitigating risk in proposed ‘skinny’ accounts

February 6, 2026

Survey: Most Americans report stress over finances

February 5, 2026

SPONSORED CONTENT

How Instant Payments Can Accelerate B2B Payments Modernization

How Instant Payments Can Accelerate B2B Payments Modernization

February 3, 2026
Digital Banking: The Gateway to Customer Growth and Competitive Differentiation

Digital Banking: The Gateway to Customer Growth and Competitive Differentiation

February 1, 2026
Planning Your 2026 Budget? Allocate Resources to Support Growth and Retention Goals

Why Every Digital Interaction Defines Your Brand Experience

February 1, 2026
Seeing More Check Fraud and Scams? These Educational Online Toolkits Can Help

Seeing More Check Fraud and Scams? These Educational Online Toolkits Can Help

November 1, 2025

PODCASTS

Podcast: How the SCAM Act would encourage platforms to go after scammers

February 4, 2026

A new kind of ‘community bank’ for small businesses

January 22, 2026

Podcast: A Lone Star banking perspective

January 15, 2026

American Bankers Association
1333 New Hampshire Ave NW
Washington, DC 20036
1-800-BANKERS (800-226-5377)
www.aba.com
About ABA
Privacy Policy
Contact ABA

ABA Banking Journal
About ABA Banking Journal
Media Kit
Advertising
Subscribe

© 2026 American Bankers Association. All rights reserved.

No Result
View All Result
  • Topics
    • Ag Banking
    • Commercial Lending
    • Community Banking
    • Compliance and Risk
    • Cybersecurity
    • Economy
    • Human Resources
    • Insurance
    • Legal
    • Mortgage
    • Mutual Funds
    • Payments
    • Policy
    • Retail and Marketing
    • Tax and Accounting
    • Technology
    • Wealth Management
  • Newsbytes
  • Podcasts
  • Magazine
    • Subscribe
    • Advertise
    • Magazine Archive
    • Newsletter Archive
    • Podcast Archive
    • Sponsored Content Archive

© 2026 American Bankers Association. All rights reserved.