To Pay or Not to Pay? The Battle Between Bug Bounty & VDPs
Aaron Guzman (Program Owner)
Bug Bounty Village @ DEF CON 33 · Day 1 · Bug Bounty Village
Overview
In "To Pay or Not to Pay? The Battle Between Bug Bounty & VDPs," Aaron Guzman, a Program Owner at Cisco, delves into the intricate challenges and strategic imperatives of managing both bug bounty (BB) and vulnerability disclosure programs (VDPs) within a large enterprise. The talk addresses the inherent complexities faced by security teams in processing a high volume of vulnerability submissions, particularly when dealing with diverse product scopes and varying levels of criticality. Guzman, drawing from his extensive experience as a researcher, pen tester, and program manager, highlights the "cognitive dissonance" researchers often experience when trying to determine the correct submission channel for their findings.

Key moments
- 0:00 Speaker's journey and bug bounty evolution
- 2:00 Cisco's dual bug bounty and VDP programs
- 4:00 Common frustrations experienced by bounty hunters
- 5:50 Introducing VDP as a 'welcome mat' for submissions
- 6:50 Differentiating bounty vs. VDP scope and benefits
To Pay or Not to Pay? The Battle Between Bug Bounty & VDPs
Speakers: Aaron Guzman, Program Owner, Cisco
Conference: Bug Bounty Village
YouTube: https://www.youtube.com/watch?v=-FMwi_V6XeY
Overview
In "To Pay or Not to Pay? The Battle Between Bug Bounty & VDPs," Aaron Guzman, a Program Owner at Cisco, delves into the intricate challenges and strategic imperatives of managing both bug bounty (BB) and vulnerability disclosure programs (VDPs) within a large enterprise. The talk addresses the inherent complexities faced by security teams in processing a high volume of vulnerability submissions, particularly when dealing with diverse product scopes and varying levels of criticality. Guzman, drawing from his extensive experience as a researcher, pen tester, and program manager, highlights the "cognitive dissonance" researchers often experience when trying to determine the correct submission channel for their findings.
The presentation outlines Cisco's journey in evolving its vulnerability management strategy over more than a decade, from rudimentary internal tracking systems to sophisticated dual-program operations. Guzman emphasizes the critical need for clear intake channels and robust internal processes to effectively handle everything from high-paying, in-scope bounties to non-monetized, but equally important, infrastructure and operational findings. The talk culminates in the introduction of the Cisco Researcher Toolkit, an open-source initiative designed to empower researchers with better submission quality, streamlined triage, and AI-assisted vulnerability discovery.
This talk is particularly relevant for both cybersecurity researchers and security program owners. For researchers, it demystifies the submission process for large organizations, offering insights into what constitutes a high-quality report and how to navigate the distinctions between bounty and VDP scopes. For program owners, it provides a blueprint for building a comprehensive vulnerability management ecosystem that not only addresses immediate risks but also fosters long-term relationships with the security community, leverages external talent, and strategically expands its defensive posture across an ever-growing attack surface.
Background
▶ Watch: Speaker's journey and bug bounty evolution (0:00)
Aaron Guzman's journey in cybersecurity provides a compelling backdrop to the challenges discussed in his talk. He began his career as a hacker, researcher, and pen tester in an era preceding the widespread adoption of bug bounties. This early experience involved the arduous process of manually coordinating vulnerability disclosures with vendors, often through email, leading to significant "pain and suffering" in follow-ups, waiting 180 days for resolution, and struggling to obtain CVEs. This firsthand exposure to the difficulties of responsible disclosure instilled in him a deep empathy for the researcher's perspective.
His career then transitioned to managing vulnerability reports on the corporate side at companies like Belkin and Linksys. Here, he encountered the inverse challenge: a massive volume of submissions from researchers without the sophisticated tool capabilities available today. His team was forced to customize internal tracking systems, such as RT, a "painful" endeavor for a small security team at a consumer company. This period highlighted the operational overhead and complexity of managing inbound vulnerability reports.
As the market evolved over the last decade with the proliferation of bounty platforms, Guzman participated in both public and private bounties, gaining further insights into the researcher experience. Now, as a Program Owner at Cisco, he leads a team managing a "modern security product security program" that integrates both bounty and VDPs. This evolution reflects a broader shift in the industry, where proactive engagement with the security community has become a cornerstone of enterprise security.
Cisco, a company with a massive global presence, faces unique challenges due to the sheer scale and diversity of its products and services. Guzman points out that Cisco invests "millions" in owning and advocating for its security programs, covering both operational costs and researcher payouts. Despite this investment, the company previously encountered a "breaking point" where numerous submissions were out-of-scope for their bug bounty program, leading to them being "kicked around" to support teams or account managers. This created immense frustration for researchers, who might opt to blog about their findings or pursue a CVE independently, and taxed internal business units with escalations. The lack of a clear path for these valuable, albeit out-of-scope, findings meant Cisco lacked a comprehensive understanding of risks beyond its defined bounty scope. This problematic scenario underscored the necessity for a more inclusive and structured approach to vulnerability disclosure, prompting Cisco to introduce a "welcome mat" in the form of a VDP to complement its established bug bounty program.
Key Findings
▶ Watch: Cisco's dual bug bounty and VDP programs (2:00)
The talk reveals several pivotal findings and strategic insights gleaned from Cisco's extensive experience in vulnerability management:
- Dual Program Necessity: Operating both a Bug Bounty Program (BBP) and a Vulnerability Disclosure Program (VDP) is not merely beneficial but essential for comprehensive risk management in a large enterprise. BBPs cover high-impact, in-scope product vulnerabilities with monetary rewards, while VDPs provide a crucial "welcome mat" for out-of-scope, infrastructure, or operational issues (e.g., dangling DNS, subdomain takeovers) that still pose significant risk and require attention, fostering relationships and offering non-monetary recognition.
- Consolidated Intake is Paramount: For program owners, having a single, clear intake point for all vulnerability submissions dramatically reduces "cognitive dissonance" for researchers and prevents reports from being "untriaged" or lost in a "perpetual cycle" across different internal teams. This consolidation is vital for gaining the necessary visibility and control to manage vulnerabilities effectively.
- Researcher Relationships as a Strategic Asset: Fostering strong, empathetic relationships with the security research community goes beyond transactional bug finding. These relationships can lead to a unique talent pipeline, as demonstrated by Cisco hiring two of its top bounty hunters (Edwin and Bryce) into its security team. These hired experts not only reduce risk by systematically addressing architectural weaknesses but also provide invaluable internal perspective.
- Structured Submissions Drive Efficiency: High-quality, detailed vulnerability reports with clear descriptions, impact assessments, technical details, and reproduction steps (as outlined in the Bug Bounty Bootcamp methodology) are critical. They enable faster triage, quicker payouts for researchers, and more effective remediation for program owners, helping to identify and address underlying "diseases" rather than just "symptoms."
- AI/LLM Augmentation for Researchers: The introduction of tools like the Cisco Researcher Toolkit demonstrates the potential of integrating AI capabilities (e.g., Claude, Gemini, OpenAI) to assist researchers in identifying potential attack vectors, generating report templates, and improving submission quality. This innovation aims to lower the barrier for entry and enhance the productivity of all researchers.
- Top Vulnerability Patterns: Cisco's highest-paid submissions consistently fall into categories related to access control and authorization, specifically IDORs (Insecure Direct Object References), authentication bypass, and access to sensitive information. This highlights these areas as persistent, high-value targets for both attackers and ethical hackers, and critical areas for defensive investment.
- Significant ROI from Comprehensive Strategy: Combining BB/VDP with internal Attack Surface Management (ASM) yields a substantial return on investment, with Cisco reporting a 20x ROI. This integrated approach ensures both reactive vulnerability discovery and proactive risk identification and remediation, leading to a more robust security posture.
- Scope Expansion as a Continuous Process: As technology evolves (e.g., AI acceleration, generative AI, Wi-Fi 7), and product lines grow (from 3 million to over 10 million devices, a handful to 85+ product lines), security programs must continually expand their scope to cover new attack surfaces, including enterprise devices like Catalyst switches and wireless controllers.
Technical Deep Dive
▶ Watch: Common frustrations experienced by bounty hunters (4:00)
Cisco's approach to vulnerability management is characterized by a sophisticated, dual-program architecture designed to address the vast and varied attack surface of a global technology giant. At its core are two distinct, yet complementary, programs: the Cisco Meraki Bug Bounty and the Cisco Responsible Disclosure (VDP).
The Cisco Meraki Bug Bounty focuses on high-impact vulnerabilities within defined product scopes, offering monetary rewards up to $10,000. This program is geared towards critical findings in core products and services, where direct financial incentives drive top-tier research. In contrast, the Cisco VDP acts as a "welcome mat" for a broader range of findings, particularly those that are out-of-scope for the bounty program but still present risk. This includes configuration issues, operational issues, dangling DNS records, and subdomain takeovers. While the VDP does not offer direct monetary rewards, it provides recognition, points, and even the shipment of hardware to researchers, fostering a long-term relationship and enabling deeper research into Cisco's ecosystem. Cisco's PSIRT (Product Security Incident Response Team) also manages responsible disclosures for specific products not covered by these programs, further segmenting the intake process.
A significant aspect of Cisco's strategy is its ongoing scope expansion. The program has grown from covering 3 million active devices to over 10 million, and from a "handful" of product lines to over 85. This expansion now includes enterprise-grade devices such as Catalyst devices, wireless controllers, and specifically the C9200 series switches and campus gateway controllers (e.g., the APs visible in the conference hall). The program also encompasses emerging technologies like Wi-Fi 7 (through private bounties focusing on hardware, secure boot implementations, and the Wi-Fi 7 specification itself) and AI acceleration and generative AI development, reflecting Cisco's commitment to integrating security into cutting-edge innovation.
Cisco's success in risk reduction is partly attributed to an "unorthodox" hiring pipeline: recruiting top bounty hunters from their Hall of Fame. Edwin, a former bounty hunter, was hired for his expertise in systematically finding issues in the device-to-dashboard architecture and SaaS management interface for Meraki devices. Bryce (exalted), another hire, specialized in access control issues and IDORs. These individuals, having a deep understanding of common attack patterns and Cisco's architecture, transition from merely reporting symptoms to actively "treating the disease" by helping address systemic vulnerabilities, thus significantly reducing exposure.
To help researchers navigate the complex submission landscape, Guzman introduces the PIIR framework:
- Product Impact: Typically routed to the bounty program for high-impact findings.
- Infrastructure: Directed to the VDP for issues related to cloud platforms or data center assets.
- Investment / Research / Relationship Building: Primarily handled by the VDP, emphasizing non-monetary rewards and collaboration.
- Revenue Risk: Critical issues with direct business impact, sent to the bounty program.
The talk then unveils the Cisco Researcher Toolkit, a new open-source tool designed to simplify vulnerability discovery and submission. This toolkit, available via a QR code, features five key components:
- Suggest Research Areas: Provides guidance on potential targets.
- OWASP Testing Guides: Integrates standard testing methodologies, customizable with a researcher's own tips and tricks.
- Vulnerability Triage Routing: A core feature that helps researchers determine the correct program (Bounty, VDP, or PSIRT) for their findings. Users input details like product, impact (critical, low, medium), and business criticality to receive a program recommendation. For example, a critical subdomain takeover on a Meraki device with business-critical impact would be routed to the Meraki Bug Bounty, while a low-impact infrastructure issue would go to the VDP. If a device like a Nexus switch is out of bounty scope but exploitable, it would be routed to Cisco PSIRT.
- Better Submission Quality: A workflow that generates structured report templates. This module focuses on five key areas: title, version, Proof of Concept (POC), business impact, and screenshots. It provides a starting point for drafting comprehensive reports for specific bug types, such as a command injection on a Catalyst device, ensuring that essential details like subject, impact, technical details, and timelines are included. This is particularly beneficial for beginners to ensure high-quality, actionable submissions.
- AI Capabilities: Integrates with various LLM (Large Language Model) providers like Claude, Gemini, and OpenAI. Users can input their API keys (data is processed locally and not stored) to leverage AI for suggesting research areas and identifying potential bugs. The tool also highlights "high-value releases" (e.g., Cisco AI Assistant, Wi-Fi 7 devices) and suggests attack vectors based on guides like the OWASP IoT security testing guide.
Cisco's analysis of its highest-paid submissions reveals a consistent pattern: IDORs, authentication bypasses, and access to sensitive information. These are all fundamentally related to access control and authorization, underscoring the critical importance of these vulnerability classes. The toolkit, by streamlining the process and guiding researchers, aims to enhance the discovery and reporting of these complex, yet high-impact, issues.
Demo / Proof of Concept
▶ Watch: Introducing VDP as a 'welcome mat' for submissions (5:50)
While Aaron Guzman's talk did not feature a live, interactive demonstration of the Cisco Researcher Toolkit, he effectively provided a detailed walkthrough of its capabilities using a series of screenshots from its web interface. This visual "proof of concept" illuminated the tool's design and functionality, making its utility clear to the audience.
The presentation commenced by showcasing the toolkit's general interface, highlighting its five integrated tools. A key aspect demonstrated was the AI provider setup, where users can input their API keys for LLMs like Claude, Gemini, and OpenAI. Guzman emphasized that this processing is entirely local, with no data stored or hosted externally, addressing privacy and security concerns.
The core of the demonstration focused on the Vulnerability Triage Routing tool. Screenshots illustrated the input fields where a researcher would specify the product (e.g., Cisco Meraki, Catalyst device, Nexus switch), the impact level (critical, low, medium), and whether it poses a business-critical risk. The tool's output, a clear recommendation for the appropriate program (Cisco Meraki Bug Bounty, Cisco Security VDP, or Cisco PSIRT), along with a direct link, was prominently displayed. Specific scenarios were walked through:
- A subdomain takeover with critical impact and business-critical risk was shown to be routed to the Meraki Bug Bounty.
- A low-impact, non-business-critical infrastructure issue was routed to the VDP.
- A vulnerability in a Nexus switch (not covered by bounty) but with business impact was routed to the Cisco PSIRT team.
Another significant part of the demonstration covered the Submission Quality Analyzer. Guzman walked through a workflow where a researcher could select a bug type, such as a command injection on a Catalyst device, and the tool would generate a structured report template. This template included placeholders for critical information like the subject, business impact, technical details, timelines, and a Proof of Concept (POC), along with reminders for screenshots. This illustrated how the toolkit could guide researchers, especially beginners, in crafting high-quality, actionable reports that accelerate triage and payment.
Finally, the demonstration touched upon the "Suggest Research Areas" feature. Screenshots showed how the tool could integrate information about recent high-value Cisco releases (e.g., Cisco AI Assistant, Wi-Fi 7 devices) and suggest relevant attack vectors, drawing from resources like the OWASP IoT security testing guide or custom methodologies. This capability aims to help researchers identify promising targets and initial testing approaches, streamlining the discovery process within a large enterprise's vast attack surface.
Through these detailed visual explanations, Guzman effectively conveyed the practical benefits and operational flow of the Cisco Researcher Toolkit, positioning it as a valuable asset for both the research community and internal security teams.
Defensive Implications
▶ Watch: Differentiating bounty vs. VDP scope and benefits (6:50)
The insights shared by Aaron Guzman carry significant implications for both security program owners and general cybersecurity defenders striving to fortify their organizations against evolving threats.
For Program Owners and Security Teams:
- Embrace a Hybrid Vulnerability Management Strategy: The most crucial takeaway is the necessity of operating both a Bug Bounty Program (BBP) and a Vulnerability Disclosure Program (VDP). A BBP effectively incentivizes the discovery of high-impact, in-scope vulnerabilities with monetary rewards, while a VDP provides a critical "welcome mat" for a broader range of findings—such as configuration issues, operational issues, or out-of-scope infrastructure flaws (e.g., dangling DNS, subdomain takeovers)—that, while not monetized, still pose significant risk and require attention. This dual approach ensures comprehensive coverage of the entire attack surface, preventing valuable findings from being lost or ignored.
- Consolidate Intake Channels: To mitigate "cognitive dissonance" for researchers and streamline internal processes, program owners must strive for a single, clear intake point for all vulnerability submissions. Dispersed intake across multiple email addresses, support channels, or internal teams leads to "untriaged perpetual cycles" and a severe lack of visibility, making effective management impossible. A unified intake, potentially facilitated by tools like the Cisco Researcher Toolkit, ensures that all reports are routed correctly and efficiently.
- Invest in Researcher Relationships: Beyond transactional bug hunting, cultivating strong, empathetic relationships with the security research community is a strategic imperative. These relationships can lead to a deeper understanding of systemic vulnerabilities and even serve as a unique talent pipeline, as demonstrated by Cisco hiring top bounty hunters. These internal experts can then help address root causes (the "disease") rather than just patching individual instances (the "symptoms"), leading to more sustainable risk reduction.
- Prioritize Quality in Submissions: Encourage and, if possible, enable researchers to submit high-quality, detailed reports. Clear subjects, business impact, technical details, reproduction steps, and screenshots (as emphasized by the Bug Bounty Bootcamp methodology) significantly reduce triage time, accelerate remediation, and ensure that the full extent of a vulnerability is understood. Tools that provide report templates and quality assessment can be invaluable here.
- Integrate Security with Quality: As Guzman notes, security is a "facet of quality." Program owners should integrate security practices into broader quality assurance processes. This proactive integration ensures that security considerations are embedded throughout the product development lifecycle, rather than being an afterthought.
- Complement with Attack Surface Management (ASM): Bug bounties and VDPs are powerful reactive tools, but they must be complemented by proactive measures. Internal Attack Surface Management (ASM), including continuous scanning and remediation, is crucial for identifying known vulnerabilities and managing the organization's digital footprint. Cisco's experience shows a 20x return on investment when combining these strategies. Program owners "got to know what's out there, right? You got to know where your net blocks are."
- Expand Scope Proactively: As the technological landscape evolves (e.g., AI acceleration, generative AI, Wi-Fi 7) and product portfolios grow (e.g., Catalyst devices, wireless controllers), security programs must continuously expand their scope to cover new attack surfaces. This includes both public bounties for critical products and private programs for emerging technologies, ensuring that new risks are identified early.
For General Cybersecurity Defenders:
- Recognize the Value of "Out-of-Scope" Findings: Understand that even vulnerabilities deemed "low impact" or "out-of-scope" for a bug bounty can accumulate to indicate larger architectural or operational weaknesses. VDPs provide a channel for these findings, and their analysis over time can highlight systemic issues that warrant significant investment in resolution.
- Focus on Systemic Issues: Instead of merely patching individual vulnerabilities, strive to understand and address the underlying patterns and root causes. For instance, if IDORs are a recurring issue, the focus should shift from fixing one instance to re-evaluating and hardening the entire access control framework across applications.
- Adopt Proactive Measures: Don't solely rely on external researchers to find vulnerabilities. Implement robust internal Attack Surface Management (ASM) tools and processes to proactively identify and remediate risks across your environment. Knowing your net blocks and assets is foundational.
- Stay Informed on Common Vulnerability Types: Pay close attention to high-impact vulnerability classes like IDORs, authentication bypasses, and access to sensitive information. These are consistently high-value targets for attackers and should be prioritized in defensive efforts, secure coding practices, and security reviews.
By implementing these defensive strategies, organizations can build more resilient security programs that effectively leverage both internal capabilities and the vast talent of the global security research community.
Key Takeaways
- Dual Program Necessity: Implementing both a Bug Bounty Program (BBP) for high-impact, in-scope vulnerabilities and a Vulnerability Disclosure Program (VDP) for broader infrastructure or operational issues is crucial for comprehensive risk management and covering the entire attack surface.
- Consolidated Intake & Relationships: A single, clear vulnerability intake point is vital for efficient triage. Fostering strong, empathetic relationships with researchers can lead to a unique talent pipeline and a deeper understanding of systemic security weaknesses.
- Researcher Toolkit & AI Assistance: Tools like the Cisco Researcher Toolkit, integrating AI capabilities, can significantly streamline vulnerability discovery, improve submission quality, and simplify triage routing for researchers, benefiting both parties.
- Quality Submissions Matter: Detailed, well-structured vulnerability reports with clear impact, technical details, and Proof of Concept (POC) are essential for faster payouts for researchers and more effective, targeted remediation for program owners.
- Strategic Scope Expansion: Continuously expanding program scope to include new technologies (e.g., AI, Wi-Fi 7) and enterprise devices, coupled with proactive Attack Surface Management (ASM), yields a significant return on investment in risk reduction.
- Prioritize Access Control: Common high-value vulnerabilities like IDORs, authentication bypasses, and access to sensitive information consistently represent critical security gaps and should be prioritized in defensive strategies and security testing.
About the Speaker(s)
Aaron Guzman is a Program Owner at Cisco, where he leads the strategy for a modern product security program encompassing both bug bounty and vulnerability disclosure initiatives. His career trajectory provides a unique perspective on the evolving landscape of cybersecurity. Guzman began his professional journey as a hacker, researcher, and pen tester, experiencing firsthand the challenges of coordinating vulnerability disclosures in the pre-bug bounty era, including the manual process of vendor coordination and the arduous pursuit of CVEs over 180-day timelines.
He later transitioned to the corporate side, managing vulnerability reports at companies like Belkin and Linksys. During this time, he gained significant empathy for program managers, dealing with high volumes of submissions and the operational pain of customizing internal tracking systems like RT. Guzman has also been an active participant in public and private bug bounties, further deepening his understanding of the researcher's perspective.
Beyond his role at Cisco, Aaron Guzman has contributed significantly to the cybersecurity community as a technical reviewer for several notable No Starch Press publications, including "Bug Bounty Bootcamp," "Practical IoT Hacking," and "Engineering Secure Devices." His extensive experience across all facets of vulnerability management—from researcher to program manager to program owner—underpins his advocacy for a balanced and comprehensive approach to security, including the strategic investment of millions in Cisco's security programs and researcher payouts.
Reviews
Dr. Zero (Offensive Security Researcher) — SOLID
Competent program-management talk from someone who clearly lives this work daily — the dual BBP/VDP architecture rationale is well-argued, and the PIIR framework plus the Researcher Toolkit are concrete deliverables that lift it above pure war-story territory. But it never escapes the gravitational pull of 'here's how our program works,' and nothing here would surprise anyone who's run a mature disclosure program.
Heather Calloway (CISO) — SOLID
A competent, practitioner-level talk on structuring vulnerability disclosure programs at enterprise scale. Guzman knows his material and the Cisco Researcher Toolkit is a genuine contribution, but the talk operates entirely within program management — it never surfaces to governance, accountability, or institutional risk in a way that would move a security leader's thinking.