Katie Moussouris

lore

securitygovernance & risk

The researcher who created Microsoft's bug bounty programme and helped create the first one at the US Department of Defense, and who has spent the years since arguing about how they should be run.

The contribution is institutional rather than technical, and it is the harder kind: persuading a company that paying outsiders to find its defects is cheaper than not knowing about them. Her later argument is the one worth carrying - that a bounty is not a security programme, and an organisation that cannot fix what it already knows about will not be helped by learning more. Bounties reward finding; nothing in them rewards repairing, which is why the mature version pairs them with a disclosure policy and a fix pipeline.

Also known as: moussouris, bug bounty

All glossary entries