The National Australia Bank was seeking new solutions to reduce its security risks, accelerate digital transformation, and make better decisions through contextual visibility.
Vulnerability Disclosure Program
Financial Institution
No formal or uniform way for security researchers to disclose potential vulnerabilities to NAB
National Australia Bank (NAB) is a financial services institution. We’re here to serve customers well and help our communities prosper. Today, we have more than 32,000 colleagues at NAB, serving over eight million customers at more than 900 locations. As Australia’s largest business bank, our business experts work with small, medium and large businesses to help them grow.
The partnership with Bugcrowd marked NAB’s first venture into crowdsourced security testing. It provided a complementary layer of assurance alongside a suite of existing assurance and testing controls. In addition, NAB has since expanded its penetration testing services with Bugcrowd, having previously worked with several other service providers.
After seeing success with the Vulnerability Disclosure Program (VDP), NAB implemented a bug bounty program to solicit potential vulnerabilities from the security community. As the attack surface expanded, NAB needed more eyes on its assets to help keep them safe for customers, colleagues, and shareholders. While NAB saw value in the VDP, it is by nature a passive program. So, in order to seek active testing and increase the coverage of assurance across all services, NAB created a bounty program and engaged an army of broadly skilled researchers on an ongoing basis. Going forward, NAB plans to expand its bounty programs to cover the software development lifecycle as well.
National Australia Bank wanted to establish a formal and uniform way for security researchers to disclose potential vulnerabilities.
NAB found that Bugcrowd offered a comprehensive service which allowed room for growth and complemented its existing security controls. The option to start with a VDP helped NAB understand the workflow and develop its internal processes. The management overlay that Bugcrowd provided across the VDP and bug bounty program, with a team of engineers to triage submissions, helped alleviate potential pressure on internal processes. In addition, Bugcrowd was commercially competitive and NAB was encouraged by the company’s responsiveness to suggestions for ideas and enhancements to drive product development.
Organizations of all kinds need to do everything proactively possible to protect themselves, their reputation, and their customers from being blindsided by cyber attacks. The Bugcrowd Security Knowledge Platform finds hidden vulnerabilities before attackers do by uniquely orchestrating data, technology, and human intelligence including tapping into the global security researcher community (“the Crowd”) for solutions that span Pen Testing as a Service, Vulnerability Disclosure, Bug Bounty, and Attack Surface Management.
ActiveCampaign is a SaaS marketing technology platform that helps businesses meaningfully connect with customers using solutions designed to support the...
For the Barracuda security team, working closer with the security research community was a great way for them to improve...
TX Group AG is a media company headquartered in Switzerland. Through a portfolio of daily and weekly newspapers, magazines and...
Hackers aren’t waiting, so why should you? See how Bugcrowd can quickly improve your security posture.