ABA Banking Journal
No Result
View All Result
  • Topics
    • Ag Banking
    • Commercial Lending
    • Community Banking
    • Compliance and Risk
    • Cybersecurity
    • Economy
    • Human Resources
    • Insurance
    • Legal
    • Mortgage
    • Mutual Funds
    • Payments
    • Policy
    • Retail and Marketing
    • Tax and Accounting
    • Technology
    • Wealth Management
  • Newsbytes
  • Podcasts
  • Magazine
    • Subscribe
    • Advertise
    • Magazine Archive
    • Newsletter Archive
    • Podcast Archive
    • Sponsored Content Archive
SUBSCRIBE
ABA Banking Journal
  • Topics
    • Ag Banking
    • Commercial Lending
    • Community Banking
    • Compliance and Risk
    • Cybersecurity
    • Economy
    • Human Resources
    • Insurance
    • Legal
    • Mortgage
    • Mutual Funds
    • Payments
    • Policy
    • Retail and Marketing
    • Tax and Accounting
    • Technology
    • Wealth Management
  • Newsbytes
  • Podcasts
  • Magazine
    • Subscribe
    • Advertise
    • Magazine Archive
    • Newsletter Archive
    • Podcast Archive
    • Sponsored Content Archive
No Result
View All Result
No Result
View All Result
Home Compliance and Risk

Overcoming the challenges of vulnerability disclosure programs 

May 19, 2022
Reading Time: 3 mins read
Overcoming the challenges of vulnerability disclosure programs 

By Ashish Gupta

At its core, security isn’t a technology problem—it’s a people problem. To compete against an army of malicious hackers and stay ahead of their strikes, what’s needed is an equivalent army of human allies who can dig into software code to find the root causes of security vulnerabilities.

This situation is somewhat comparable to communities with Neighborhood Watch programs that encourage neighbors to report any suspicious activities to maintain a shared sense of security. If you saw your next-door neighbors’ garage door was left open all night, you probably would notify them about it, and hope they would do the same for you.

rightwards arrow
View more
risk and compliance articles

In a similar way, vulnerability disclosure programs provide a secure platform for ethical hackers to report any security vulnerabilities to organizations including banks and financial institutions. A typical vulnerability disclosure program, or VDP, is based on a framework that compiles researcher findings whenever they discover new bugs or threats. Such programs also include a triage process to prioritize security risks, report them to the organization and provide workflows to remediate any problems that are found.

VDPs provide a publicly available channel for researchers to submit security vulnerabilities to an organization. Vulnerability disclosure programs are an effective way to report potential security risks in a formalized and consistent manner. They also include a channel for the reporter to be notified that the receiver got the message.

This approach helps establish a “see something, say something” mindset within an organization. In this way, VDPs mitigate risks by enabling the disclosure and remediation of vulnerabilities before they can be exploited by bad actors. For this reason, a VDP should be a baseline security standard for every organization, just as common as a firewall.

Overcoming complexity when creating a VDP

In the case of a bank, the potential attack surface grows as the organization increases in size. That escalation can quickly spiral out of control as security vulnerabilities proliferate, overwhelming security teams with a flood of incoming reports.

For this reason, VDPs require some method to triage the security risks coming from researchers and prioritize the most pressing problems for immediate attention and remediation. In cases known as “responsible disclosure,” the vulnerability is only disclosed after there has been enough time to patch or close the issue. Since developers require some time to create a fix, the disclosure timeframe can range from a few days to several months.

Other cases involve “full disclosure” when the vulnerability is disclosed as early as possible. Full disclosure makes the information accessible to the public, which increases the risk of exploitation, but it also provides for wider research support and advanced preparation. The goal with full disclosure is to notify affected parties immediately so they can take the needed precautionary steps.

Large financial organizations are recognizing that malware is a publicly available commodity that makes it easy for anyone to become an adversary. At the same time, many companies have maintained brittle security solutions that make it harder to defend against current attacks. Security researchers or hackers undergo a vetting period at Bugcrowd. VDPs are a great way to test skills, improve performance metrics and build reputation.

Creating a dynamic channel for shared communications

The solution to this ongoing security threat is to create a vulnerability disclosure program, an essential tool for any layered cybersecurity approach. In effect, a VDP opens a communication channel to external researchers, while also encouraging current customers who use a bank’s products and services to participate in the feedback loop. By opening such a reporting channel to an army of ethical security researchers and regular consumers, financial organizations can demonstrate their commitment to protecting their digital assets and customers, while also responding quickly to address known risks.

An effective VDP carves out a global channel for vulnerability reports and publicly demonstrates that your bank is doing everything possible to protect its customers, partners and suppliers. Use of VDPs is a great way to proactively get vulnerabilities reported. However, VDPs are not appropriate for continuous, active threat testing. They also are not intended to find the most serious security vulnerabilities. In addition, VDPs cannot focus testing on a particular area, and they cannot restrict researcher access.

VDPs encourage researchers to report any threats they find in internet-facing assets for a predictable cost. In contrast to bug bounties, submissions are not incentivized by cash rewards. Providing recognition after the vulnerability has been resolved is one way to incentivize a researcher. Publishing a vulnerability report after it has been fixed is another common attribute of a VDP, which gives researchers an opportunity to share their knowledge. Such VDP initiatives work to enhance an organization’s reputation for taking cybersecurity seriously, while also fulfilling its mandatory compliance requirements.

Ashish Gupta is CEO and president of Bugcrowd.

Tags: CybersecurityData security
ShareTweetPin

Related Posts

White House pushes state policymakers to restrict ‘junk fees’

White House report downplays risk to banks from stablecoin interest payments

Newsbytes
April 8, 2026

A prohibition on paying interest or yield on payment stablecoins would do “very little” to protect bank lending “while forgoing the consumer benefits of competitive returns on stablecoin holdings,” according to a new report by the White House...

Agenices propose anti-money laundering, sanctions requirements for stablecoin issuers

Agenices propose anti-money laundering, sanctions requirements for stablecoin issuers

Compliance and Risk
April 8, 2026

The Financial Crimes Enforcement Network and Office of Foreign Asset Control jointly proposed a new rule to establish BSA and sanctions compliance obligations for payment stablecoin issuers.

CISA, federal agencies issue advisory on Iran-related cyberattacks

CISA, federal agencies issue advisory on Iran-related cyberattacks

Compliance and Risk
April 8, 2026

The Cybersecurity and Infrastructure Security Agency has issued a joint advisory with other federal agencies warning critical infrastructure to be on heightened alert for cyberattacks related to the Iranian conflict.

Ransomware in the financial sector

ABA Fraudcast: Big tech’s ad business is fueling a scam ecosystem

Compliance and Risk
April 8, 2026

Why accountability, ad transparency and KYC rules could begin to rein in platform-enabled fraud.

International task force updates lists of countries with AML deficiencies

FinCEN, banking agencies propose to overhaul Bank Secrecy Act compliance

Compliance and Risk
April 7, 2026

FinCEN and the banking agencies proposed new rules to “fundamentally reform” compliance with the Bank Secrecy Act by setting standards for what financial institutions should include in their anti-money laundering programs.

Treasury Department seeks feedback on stablecoins, illicit activities

FDIC proposes rulemaking to implement Genius Act

Newsbytes
April 7, 2026

The FDIC board advanced proposed rulemaking to implement certain provisions of the Genius Act, including requirements for reserve assets, risk management, and stablecoin-related custodial and safekeeping services.

NEWSBYTES

White House report downplays risk to banks from stablecoin interest payments

April 8, 2026

Agenices propose anti-money laundering, sanctions requirements for stablecoin issuers

April 8, 2026

FOMC minutes show skepticism in taming inflation in near term

April 8, 2026

SPONSORED CONTENT

Check Fraud Is Outpacing Legacy Controls. What Banks Should Evaluate Now.

Check Fraud Is Outpacing Legacy Controls. What Banks Should Evaluate Now.

April 1, 2026
How top agricultural lenders are approaching AI, automation and innovation in 2026

How top agricultural lenders are approaching AI, automation and innovation in 2026

March 2, 2026
Top 7 FP&A Trends in Banking for 2026

Top 7 FP&A Trends in Banking for 2026

March 1, 2026
How Instant Payments Can Accelerate B2B Payments Modernization

How Instant Payments Can Accelerate B2B Payments Modernization

February 3, 2026

PODCASTS

Podcast: Are credit union commercial loans risky business?

March 30, 2026

Podcast: Risk and strategy in sponsor banking

March 19, 2026

Podcast: From stablecoin to fraud, top takeaways from the 2026 ABA Summit

March 13, 2026

American Bankers Association
1333 New Hampshire Ave NW
Washington, DC 20036
1-800-BANKERS (800-226-5377)
www.aba.com
About ABA
Privacy Policy
Contact ABA

ABA Banking Journal
About ABA Banking Journal
Media Kit
Advertising
Subscribe

© 2026 American Bankers Association. All rights reserved.

No Result
View All Result
  • Topics
    • Ag Banking
    • Commercial Lending
    • Community Banking
    • Compliance and Risk
    • Cybersecurity
    • Economy
    • Human Resources
    • Insurance
    • Legal
    • Mortgage
    • Mutual Funds
    • Payments
    • Policy
    • Retail and Marketing
    • Tax and Accounting
    • Technology
    • Wealth Management
  • Newsbytes
  • Podcasts
  • Magazine
    • Subscribe
    • Advertise
    • Magazine Archive
    • Newsletter Archive
    • Podcast Archive
    • Sponsored Content Archive

© 2026 American Bankers Association. All rights reserved.