More and more buyers are discovering the immense value that crowdsourcing brings to penetration testing, for several reasons. For example:
That’s great news! Now, the penetration testing industry is also discovering crowdsourcing–but unlike customers, not always for all the right reasons.
We’ve seen this movie before: In the recent past, legacy IT vendors struggling to win the mindshare battle with cloud-native upstarts adopted the word “cloud” to re-brand their status-quo offerings. That strategy gave rise to the term cloud washing, defined by TechTarget as “the purposeful and sometimes deceptive attempt by a vendor to rebrand an old product or service by associating the buzzword ‘cloud’ with it.” Now, we’re seeing some pen testing vendors adopt that same playbook, using a crowd washing strategy to make their offerings sound more modern and impactful than they really are.
Here are some crowd washing warning signs to look for:
Now that you know what to look for, make sure you only buy crowdsourced pentesting from providers with a credible track record!
Bugcrowd invented crowdsourced pen testing when we introduced our original offering, Next Generation Pen Tests, in 2018. Today, our Security Knowledge Platform delivers PTaaS for everything a customer might need for testing web and mobile apps, networks, APIs, cloud infra, IoT devices, and even crypto and web3, whether for a time-boxed duration or continuously. And the proprietary CrowdMatch ML technology in our platform can curate precisely the right trusted pen test team to support those tests on demand, and then buyers can pay them for their time at a fixed rate or based on the number and criticality of the issues they find.
Platform services like CrowdMatch, best-in-class triage, reporting and analytics rooted in a rich Security Knowledge Graph, and integration with DevSec workflows are what power our crowdsourced PTaaS, managed bug bounties, VDPs, attack surface management, and perhaps most important, our ability to innovate in response to emerging needs. Furthermore, our approach lets researchers align with a platform that offers clear, explicit rewards for solving challenging problems that match their skills and interests–and that leads to long-term success for them, and for customers.