MSSP, MSP, Generative AI, Bug Bounties, Penetration Testing

CISOs Turn to Crowdsourced Security as Duties Expand: HackerOne

AI and network security

The CISO’s job has always been challenging, and it doesn’t seem to be getting any easier.

From managing a rapidly evolving and expanding threat landscape to a widely distributed IT environment with a chronic shortage of skilled security talent, CISOs are now being asked to take on the responsibility of securing AI workloads including ensuring data privacy and security.

The added duties are putting a tremendous amount of pressure on CISOs, according to Kara Sprague, CEO of crowdsourced security platform company HackerOne.

"It’s not just a few more tasks; it’s a fundamental change in their role,” Sprague told MSSP Alert. "This means they're tasked with securing technologies like AI, which are evolving at an incredible speed, often driven by different parts of the business eager for a competitive advantage. This rapid adoption creates entirely new attack surfaces and unique vulnerabilities that internal teams, no matter how skilled, may not have the specialized knowledge to address.”

Responsibilities, Challenges Grow

While their responsibilities are growing, their struggles with budgets and talent continue. CISOs are now turning to crowdsourced security, which includes proactive elements such as bug bounties, vulnerability disclosure programs, and third-party penetration testing that organizations can tap into, to identify vulnerabilities in applications, systems, and infrastructures.

In addition, MSSPs and MSPs – which are increasingly being leaned on by enterprises and SMBs to supply some or all security functions and to take on a more strategic role – are seeing the advantage, she said.

"What we’re seeing is that MSSPs and MSPs are increasingly recognizing that crowdsourced security helps them scale,” the CEO said. "It provides specialized, on-demand expertise without the need to increase internal staff. And yes, adoption is accelerating. As more CISOs embrace crowdsourced models, their service providers are following suit, either by integrating these capabilities directly or by partnering with companies like HackerOne to deliver them as part of a broader security portfolio.”

15% of CISOs are All In

The San Francisco-based company discussed the issue in its recent report, The 15% Advantage: How High-Performing CISOs Leverage Crowdsourced Security, which explored how CISOs are adopting crowdsource programs. Among the 400 leaders surveyed, 15% reported using the full range of these program and saw a significant advantage - doubling their ability to identify and remediate vulnerabilities compared to those who only implemented some elements.

The report also found that while 73% of CISOs using crowdsourced security say it’s effective for finding and fixing vulnerabilities, with even stronger results in areas like data privacy and AI-related threats. That effectiveness rises to 89% among CISOs who adopt all three elements, which are, ug bounty
programs, VDPs, and pentesting,

That is true when addressing the newest responsibilities of AI security and data privacy. According to the report, 84% of CISOs say they are now in charge of securing AI, and 82% now oversee data privacy. Of those, 88% find crowdsourced security effective for data privacy vulnerabilities, and 81% for AI flaws.

'They Need the Right Partner'

It shows that crowdsourced security is "significantly boosting detection where internal expertise may be scarce,” Sprague said. "What we hear from CISOs is that they don’t need a bigger team; they need the right partner. This approach is also cost-effective, with bug bounties offering a pay-for-results model, making it strategic for CISOs to proactively secure critical new attack surfaces.”

Like most sectors in the cybersecurity space, the crowdsourced security market is also expected to grow quickly, from $9.8 billion this year to $41.38 billion by 2034, driven by the increasing sophistication of cyberthreats, the expanded attack surface with cloud and Internet of Things (IoT) adoption, and the shortage of skilled cybersecurity talent.

The list of key vendors not only includes HackerOne, but also Bugcrowd, Intigriti, and Synack.

All Three Elements are Necessary

Crowdsourced security is not a hidden cybersecurity tool anymore, according to the study. 94% of CISOs are familiar with crowdsourced security and more than three-quarters are using it in some way, including with AI security and data privacy. Additionally, 86% of those not using it now, plan to in the next year.

Still, only 56% use all three key aspects of crowdsourced security, though adoption is picking up.

“The primary driver is the unique nature of new responsibilities, especially securing AI systems where specialized expertise is critical,” Sprague said. “Over half of those planning to adopt crowdsourced security intend to use it for AI. Also, when tied to measurable risk reduction, implementing crowdsourced security becomes a board-level win.”

She added that the momentum is also being driven by the ongoing skills gap and a growing recognition at the board level of the need for proactive security. Notably, every leader who has fully adopted the model views it as critical to their overall strategy.

Crowdsourcing Scales MSSPs' Capabilities

Security services providers are key to the model adoption.

“MSSPs and MSPs are central to the evolution of modern security delivery,” the CEO said. “For many small and mid-sized businesses, these partners are the de facto security team. That puts them in a unique position to extend the reach of crowdsourced security, whether through vulnerability disclosure programs, bug bounties, or curated testing engagements.”

They also help with HackerOne’s push to make the internet safe, an effort that requires scale.

“Channel partners, especially MSSPs, are key to reaching organizations that may not have the internal resources to run a full-fledged security program but still face the same threat landscape,” Sprague said. “These partners help operationalize crowdsourced security for their clients. They bring the context, the relationships, and the trust. And when paired with HackerOne’s platform and community, they can deliver outcomes that are faster, more cost-effective, and more aligned with real-world risk.”

Jeffrey Burt

Jeffrey Burt has been a journalist for almost 40 years, moving from general-circulation newspapers to IT news sites in 2000. He’s an expert analyst and writer on cybersecurity, data center infrastructure, AI, and a host of other subjects for a range of organizations, including CyberRisk Alliance, eWEEK, Techstrong Group, The Next Platform, and The Register.

You can skip this ad in 5 seconds