ABA Banking Journal
No Result
View All Result
  • Topics
    • Ag Banking
    • Commercial Lending
    • Community Banking
    • Compliance and Risk
    • Cybersecurity
    • Economy
    • Human Resources
    • Insurance
    • Legal
    • Mortgage
    • Mutual Funds
    • Payments
    • Policy
    • Retail and Marketing
    • Tax and Accounting
    • Technology
    • Wealth Management
  • Newsbytes
  • Podcasts
  • Magazine
    • Subscribe
    • Advertise
    • Magazine Archive
    • Newsletter Archive
    • Podcast Archive
    • Sponsored Content Archive
SUBSCRIBE
ABA Banking Journal
  • Topics
    • Ag Banking
    • Commercial Lending
    • Community Banking
    • Compliance and Risk
    • Cybersecurity
    • Economy
    • Human Resources
    • Insurance
    • Legal
    • Mortgage
    • Mutual Funds
    • Payments
    • Policy
    • Retail and Marketing
    • Tax and Accounting
    • Technology
    • Wealth Management
  • Newsbytes
  • Podcasts
  • Magazine
    • Subscribe
    • Advertise
    • Magazine Archive
    • Newsletter Archive
    • Podcast Archive
    • Sponsored Content Archive
No Result
View All Result
No Result
View All Result
Home Compliance and Risk

Overcoming the challenges of vulnerability disclosure programs 

May 19, 2022
Reading Time: 3 mins read
Overcoming the challenges of vulnerability disclosure programs 

By Ashish Gupta

At its core, security isn’t a technology problem—it’s a people problem. To compete against an army of malicious hackers and stay ahead of their strikes, what’s needed is an equivalent army of human allies who can dig into software code to find the root causes of security vulnerabilities.

This situation is somewhat comparable to communities with Neighborhood Watch programs that encourage neighbors to report any suspicious activities to maintain a shared sense of security. If you saw your next-door neighbors’ garage door was left open all night, you probably would notify them about it, and hope they would do the same for you.

rightwards arrow
View more
risk and compliance articles

In a similar way, vulnerability disclosure programs provide a secure platform for ethical hackers to report any security vulnerabilities to organizations including banks and financial institutions. A typical vulnerability disclosure program, or VDP, is based on a framework that compiles researcher findings whenever they discover new bugs or threats. Such programs also include a triage process to prioritize security risks, report them to the organization and provide workflows to remediate any problems that are found.

VDPs provide a publicly available channel for researchers to submit security vulnerabilities to an organization. Vulnerability disclosure programs are an effective way to report potential security risks in a formalized and consistent manner. They also include a channel for the reporter to be notified that the receiver got the message.

This approach helps establish a “see something, say something” mindset within an organization. In this way, VDPs mitigate risks by enabling the disclosure and remediation of vulnerabilities before they can be exploited by bad actors. For this reason, a VDP should be a baseline security standard for every organization, just as common as a firewall.

Overcoming complexity when creating a VDP

In the case of a bank, the potential attack surface grows as the organization increases in size. That escalation can quickly spiral out of control as security vulnerabilities proliferate, overwhelming security teams with a flood of incoming reports.

For this reason, VDPs require some method to triage the security risks coming from researchers and prioritize the most pressing problems for immediate attention and remediation. In cases known as “responsible disclosure,” the vulnerability is only disclosed after there has been enough time to patch or close the issue. Since developers require some time to create a fix, the disclosure timeframe can range from a few days to several months.

Other cases involve “full disclosure” when the vulnerability is disclosed as early as possible. Full disclosure makes the information accessible to the public, which increases the risk of exploitation, but it also provides for wider research support and advanced preparation. The goal with full disclosure is to notify affected parties immediately so they can take the needed precautionary steps.

Large financial organizations are recognizing that malware is a publicly available commodity that makes it easy for anyone to become an adversary. At the same time, many companies have maintained brittle security solutions that make it harder to defend against current attacks. Security researchers or hackers undergo a vetting period at Bugcrowd. VDPs are a great way to test skills, improve performance metrics and build reputation.

Creating a dynamic channel for shared communications

The solution to this ongoing security threat is to create a vulnerability disclosure program, an essential tool for any layered cybersecurity approach. In effect, a VDP opens a communication channel to external researchers, while also encouraging current customers who use a bank’s products and services to participate in the feedback loop. By opening such a reporting channel to an army of ethical security researchers and regular consumers, financial organizations can demonstrate their commitment to protecting their digital assets and customers, while also responding quickly to address known risks.

An effective VDP carves out a global channel for vulnerability reports and publicly demonstrates that your bank is doing everything possible to protect its customers, partners and suppliers. Use of VDPs is a great way to proactively get vulnerabilities reported. However, VDPs are not appropriate for continuous, active threat testing. They also are not intended to find the most serious security vulnerabilities. In addition, VDPs cannot focus testing on a particular area, and they cannot restrict researcher access.

VDPs encourage researchers to report any threats they find in internet-facing assets for a predictable cost. In contrast to bug bounties, submissions are not incentivized by cash rewards. Providing recognition after the vulnerability has been resolved is one way to incentivize a researcher. Publishing a vulnerability report after it has been fixed is another common attribute of a VDP, which gives researchers an opportunity to share their knowledge. Such VDP initiatives work to enhance an organization’s reputation for taking cybersecurity seriously, while also fulfilling its mandatory compliance requirements.

Ashish Gupta is CEO and president of Bugcrowd.

Tags: CybersecurityData security
ShareTweetPin

Related Posts

ABA faults banking regulators for confusing CRA rule rollout

FDIC, OCC release Q3, Q4 CRA exam schedules

Community Banking
May 29, 2026

The FDIC has released the schedules for Community Reinvestment Act examinations to be conducted in the third and fourth quarters of the year, while the OCC released its schedule of CRA evaluations for Q3.

FinCEN seeks feedback on real estate reporting form

Court vacates FinCEN residential real estate reporting rule

Compliance and Risk
May 28, 2026

A federal court has vacated FinCEN’s new anti-money laundering reporting requirements for residential real estate transfers. As a result, reporting requirements are suspended while the agency appeals the decision.

CFPB claims ‘complex’ pricing drives up cost of financial products

Consumer groups, vendors sue CFPB over changes to fair lending enforcement

Compliance and Risk
May 28, 2026

A coalition of consumer groups and fair lending compliance firms has filed a lawsuit to prevent the CFPB from removing disparate impact as a prohibited practice from Regulation B, which implements the Equal Credit Opportunity Act.

Trump administration proposes nondisclosure agreement for all government employees

Trump administration proposes nondisclosure agreement for all government employees

Compliance and Risk
May 26, 2026

The Trump administration is proposing the creation of a government-wide nondisclosure agreement for new and existing federal employees that agencies could elect to adopt.

Treasury Department seeks feedback on stablecoins, illicit activities

ABA, associations urge regulators to fully account for stablecoin risks in annual report

Compliance and Risk
May 26, 2026

Saying they are deeply concerned about the risk stablecoin payment issuers pose to the overall financial system, ABA and three other bankers associations submitted recommendations for what federal regulators should include in their annual report to Congress on...

FDIC approves new guidance for ‘living wills’

Banking agencies publish ‘living will’ feedback

Compliance and Risk
May 26, 2026

The FDIC and Federal Reserve recently published their feedback letters for the resolution plans submitted by the largest banks, although FDIC board member and Comptroller of the Currency Jonathan Gould abstained from voting for the letters’ release, as...

NEWSBYTES

ABA, associations reaffirm support for federal preemption of Illinois interchange law

May 29, 2026

ABA DataBank: Streamflation takes off

May 29, 2026

FDIC, OCC release Q3, Q4 CRA exam schedules

May 29, 2026

SPONSORED CONTENT

A Modern Blueprint for Serving High-Net-Worth Families

A Modern Blueprint for Serving High-Net-Worth Families

May 28, 2026
Why Your Systems Keep Slowing Down — and What to Do About It

AI Is in Your Bank. Is Your Cloud Contract Governing It?

May 20, 2026
Credit Memos at the Convergence Point

Credit Memos at the Convergence Point

May 1, 2026
Digital Account Opening: Think Outside the Box for Maximum Business Impact

Digital Account Opening: Think Outside the Box for Maximum Business Impact

April 29, 2026

PODCASTS

Podcast: Creating a feeling of welcome, for customers and new bankers

May 28, 2026

Podcast: How consumer deposits drive full relationship banking

May 14, 2026

Podcast: How an Ohio banker talks with policymakers about stablecoin issues

May 6, 2026

American Bankers Association
1333 New Hampshire Ave NW
Washington, DC 20036
1-800-BANKERS (800-226-5377)
www.aba.com
About ABA
Privacy Policy
Contact ABA

ABA Banking Journal
About ABA Banking Journal
Media Kit
Advertising
Subscribe

© 2026 American Bankers Association. All rights reserved.

No Result
View All Result
  • Topics
    • Ag Banking
    • Commercial Lending
    • Community Banking
    • Compliance and Risk
    • Cybersecurity
    • Economy
    • Human Resources
    • Insurance
    • Legal
    • Mortgage
    • Mutual Funds
    • Payments
    • Policy
    • Retail and Marketing
    • Tax and Accounting
    • Technology
    • Wealth Management
  • Newsbytes
  • Podcasts
  • Magazine
    • Subscribe
    • Advertise
    • Magazine Archive
    • Newsletter Archive
    • Podcast Archive
    • Sponsored Content Archive

© 2026 American Bankers Association. All rights reserved.