HackerOne
Excellent CSM Support and an Ever-Improving Automation Platform
Strong Bug Bounty Platform
One of the best BB platform
Straightforward, Practical Vulnerability Management with Clear Visibility
Powerful Bug Bounty Platform with Room for Improvements
Competent Triaging, but Automation Needs Improvement
Vital for Security with Top Hackers
Streamlined Security with Expert Support
Crowdsourced security has strengthened our bug discovery and improved vulnerability response
What is our primary use case?
Our main use case for HackerOne is to create a bridge between the organization and a global community of ethical hackers where we ask them to find bugs in our environment, and based on that, they provide us the bugs we have.
A quick example of how I've used HackerOne is that it provides us bug bounty programs and vulnerability disclosure programs where multiple bug bounty hunters submit their findings about the organization, and those vulnerabilities or bugs are fixed by us. For instance, we received many alerts about expired or mismatched SSL certificates.
We utilize HackerOne's web page where we log in to see what vulnerabilities are there and what else has been discovered, and based on that, we pick and work on the issues we need to fix.
What is most valuable?
HackerOne offers bug bounty programs, vulnerability disclosure programs, red teaming, attack surface management, and other valuable features.
I find bug bounty programs most valuable for our organization because they invite researchers from around the globe to find bugs in our environment, allowing us to fix various severity vulnerabilities or bugs that, if left unaddressed, could lead to losing customers.
HackerOne has positively impacted my organization as hiring red teamers to find vulnerabilities would have taken a lot of time, but through HackerOne, we access a vast number of ethical hackers who help identify bugs, which is invaluable for us.
What needs improvement?
HackerOne is already doing well, although I believe implementing stricter SLAs for the time to first response and time to bounty would help prevent researchers' burnout, especially regarding duplicate submissions.
I suggest systematic bug rewards because currently, if a researcher finds one bug in multiple places, they often only get paid for one. Improving the handling of systemic vulnerabilities would encourage deeper research. Additionally, improving multi-currency and crypto payout options would help make the platform more accessible globally.
For how long have I used the solution?
I work in my current field for 7.5 years.
What do I think about the stability of the solution?
HackerOne is stable.
What do I think about the scalability of the solution?
HackerOne's scalability is designed to solve noise problems that typically kill security programs as they grow. It maintains a high signal-to-noise ratio and addresses scalability through infrastructure, triage services, and AI automation, ensuring it handles more reports effectively.
How are customer service and support?
Customer support can improve, as there are instances of ghosting that need to be addressed. I would rate customer support a six out of ten.
Which solution did I use previously and why did I switch?
I am using HackerOne only, with no previous solutions.
How was the initial setup?
I'm not very sure about pricing, setup costs, and licensing, as those are managed by our management team.
What about the implementation team?
We are just a customer of HackerOne, without any business relationship beyond that.
What was our ROI?
I notice a return on investment through the group of researchers at HackerOne identifying vulnerabilities, saving us money, time, and manpower, with the efficiency of HackerOne allowing them to accomplish in three to four hours what would take two red teamers a whole day.
What's my experience with pricing, setup cost, and licensing?
I'm not very sure about pricing, setup costs, and licensing, as those are managed by our management team.
Which other solutions did I evaluate?
Before choosing HackerOne, we evaluated competitors such as Bugcrowd and Intigriti but opted for HackerOne due to its typical rating of 8.5 out of 10 and its enterprise-grade programs.
What other advice do I have?
My advice for others looking into using HackerOne is that it stands above competitors such as Bugcrowd, Intigriti, and Synack, making HackerOne preferable. We covered all the important points regarding HackerOne. I gave this review a rating of 8 out of 10.