DOI: 10.1287/mnsc.2022.02682 ISSN: 0025-1909

Crowdsourcing from Hackers: Strategic Coopetition and Governance in Bug Bounty Programs

Jiali Zhou, Kai-Lung Hui

In a bug bounty program (BBP), organizations incentivize hackers—who could otherwise be “enemies”—to report security vulnerabilities by publicly offering monetary rewards. This paper develops an analytical framework to characterize BBPs and their strategic and economic impacts. Strategically, BBPs induce some hackers to self-select into cooperative vulnerability discovery and reporting, diverting them away from attacking (attack diversion) and delegating part of the protection effort to them (protection delegation). We show that (i) BBPs can be beneficial even when hackers are inefficient at vulnerability identification, yet more participants might make BBPs less attractive to firms. (ii) Although BBPs improve security, they might encourage competitive hackers (i.e., attackers) to exert more efforts. (iii) The coopetition dynamics can render a firm’s provision of rewards and in-house efforts socially inefficient. Common cybersecurity regulations, such as breach penalties and bounty reward subsidies, may exacerbate the inefficiency. We find complementarity between bounty subsidies and breach penalties, suggesting that combining and customizing them according to firm characteristics could enhance BBP efficiency. (iv) Contrary to the conventional wisdom that crowdsourcing rewards increase with participant size, we identify scenarios in which a firm should reduce or make nonmonotonic adjustments to a bounty reward as participant size increases. (v) Legal safe harbor for security testing or policies that reduce duplicate report submissions can lower firm payoffs under BBPs. We draw related implications for research and practice in information security and crowdsourcing.

This paper was accepted by Hemant Bhargava, information systems.

Funding: This research is supported in part by the HKSAR General Research Fund Project 16503620.

Supplemental Material: The online appendix is available at https://doi.org/10.1287/mnsc.2022.02682 .

More from our Archive