Bugcrowd Blog

Casey Ellis

Executive Chairman, Founder and CTO of Bugcrowd

Recent Posts

Bug Bounty: Part of This Complete Breakfast

Posted by Casey Ellis on Oct 4, 2016 4:40:45 PM

In the past several months, bug bounties have gained popularity in the press and have been adopted with increasing velocity by enterprise organizations. Along with this popularity, the bug bounty model has also received some criticism, and various actors within the industry have raised some very good questions. In keeping with our commitment to transparency, honesty, and education, we thought it was as good as time as any to discuss two specific areas that have cropped up in the past several months, quality and impact, through examining some misconceptions about bug bounties.

Read More

Fiat Chrysler - The First Full-Line Automaker to Launch a Paid Public Bug Bounty Program

Posted by Casey Ellis on Jul 13, 2016 6:56:39 AM

2015 was the year the public perception of automobile safety changed forever… Chris Valasek and Charlie Miller’s notorious Jeep Cherokee hack transformed the idea of the humble automobile into a 2-tonne computer that can be hacked just like any other. In recent years, automakers are realising that hackers just like Charlie and Chris are already at the table, ready and willing to help, and are leveraging the work coming out of this community to make their products safer from cyber threats.

We are excited to announce that Fiat Chrysler Automobiles is joining the ranks of those pioneering this relationship, by becoming one of the first automakers to launch a bug bounty program.

Read More
Bugcrowd News

Bugcrowd's 2nd Annual State of Bug Bounty Report - A Note from the CEO

Posted by Casey Ellis on Jun 8, 2016 8:45:37 AM

Bugcrowd has always held education and sharing as a core value, which is why I’m very pleased to announce the release of our second annual State of Bug Bounty Report.

This 22-page document gives the reader an up-close and personal look at the evolving dynamics of the bug bounty market, and deeper insight into the early stages of the “unlikely romance” blossoming between hackers and organizations. Read the full report

Read More
Bugcrowd News, Research and Reports

$15M to Connect Hackers and Companies… Why, and What’s Next?

Posted by Casey Ellis on Apr 20, 2016 1:30:00 PM

Today is a great day for hackers, defenders, Bugcrowd as a company, and for Aussie founders with a dream to execute on the world stage. We’re very proud to have Blackbird Ventures, the same firm that pioneered the Startmate incubator where Bugcrowd began, taking the lead on our $15M Series B alongside existing investors Rally, Costanoa and Paladin. We’re just as pleased to welcome Salesforce Ventures and Industry Ventures to the family.  

Read More
Bugcrowd News

In the Name of Transparency

Posted by Casey Ellis on Mar 31, 2016 5:28:44 PM

At the beginning of the year, we made a decision to put some stakes in the ground.


We decided it was time to talk, write, argue, and share about sides of the bug bounty space that we interact with every day, but would otherwise rarely see the light of day... The kinds of things that some would consider as Bugcrowd's "secret sauce."

Why? Read on.


Read More
Bugcrowd News

On the U.S. Government and Bug Bounties

Posted by Casey Ellis on Mar 2, 2016 2:07:02 PM

My favorite thing about going to conferences is establishing the underlying trends behind the questions I’m asked. We’re only half-way through RSAC/BSides week, and already the dominant question is clear:

When is the government going to start a bug bounty program?

Here’s my answer:

The government has no choice but to adopt a crowdsourced model for vulnerability discovery, it’s more a question of when will the pain of staying the same exceed the pain of change.

Read More
Interesting, Conferences

Building Bugcrowd: Our First Principles

Posted by Casey Ellis on Dec 31, 2015 7:25:27 AM

About 12 months after Bugcrowd started, one of our team pulled me aside and made a suggestion that truly altered the course of the company:

Read More
Bugcrowd News

Art Coviello Joins Our Board of Directors

Posted by Casey Ellis on Oct 27, 2015 5:15:34 AM

We are excited to announce the newest member of the Bugcrowd Board of Directors, industry icon and veteran driver of cybersecurity innovation, Art Coviello Jr.

Bugcrowd’s view has always been that the economic and resourcing model of the bug bounty programs pioneered by Netscape, Google and Facebook is more that just the “latest and greatest tech-company fad.” It’s a necessary and inevitable evolution in security assessment, and it’s benefits will impact the entire IT ecosystem.

Read More

3 Years, 20,000 Security Researchers, and Nearly 200 Clients Later...

Posted by Casey Ellis on Oct 8, 2015 8:19:28 AM

2012 was the year that almost every industry, banking, education, government, big tech and even security, was hacked. Many, if not all of these companies were doing “all" they could to protect themselves against these hacks, and yet they were still left vulnerable. In direct response to this, 2012 was also the year we built Bugcrowd to beat an army of adversaries with an army of allies.

Read More
Interesting, Bugcrowd News

On Oracle, Mary Ann Davidson, and the dark side of security research

Posted by Casey Ellis on Aug 11, 2015 7:09:43 AM

Let me say clearly and upfront: As the founder of a company that manages a community of security researchers, I empathize with Mary Ann Davies’ frustrations… but I also strongly disagree with her approach.

Read More