Serving Those Who Serve Logo

Federal Agencies Now Allowed to Use HackerOne for Cybersecurity

By Benefits Ben
05/23/2020

The ethical hacking company, HackerOne, has been contracted by the DoD since 2017 – it recently received authorization for use across all Federal Agencies-

Over the past decade, professional hackers have found legitimate jobs through what are known as “vulnerability coordination” and “bug bounty” platforms. These crowd-sourced sites connect cybersecurity researchers-also referred to as “ethical hackers”- with businesses that wish to fix their public websites as to make them less impenetrable by criminal hackers that have more malicious intentions. The largest of these types of companies is HackerOne, a company that originated in 2011. On May 18th of this year, the programs serviced by HackerOne received authorization from The General Service Administration’s (GSA) FedRAMP service, which approves cloud software for use in the Federal Government. Ethical hackers will now be allowed to probe public-facing government websites so long as they disclose all discovered vulnerabilities to the respective agency.

As of the end of 2019, HackerOne has awarded a total of over $90 million in “bug bounties” across a network of over 700,000 hackers- solving over 160,000 cybersecurity vulnerabilities for 1,800 clients- including the Department of Defense (DoD) since 2017. The community of ethical hackers found roughly 12,000 vulnerabilities in DoD digital services, having partnered with the Air Force, Army, Marine Corps, and other military branches. HackerOne currently has a $2 million, five-year contract with the GSA, which sponsored the FedRAMP approval.

Until Next Time,

**Written by Benjamin Derge, Financial Planner. The information has been obtained from sources considered reliable but we do not guarantee that the foregoing material is accurate or complete. Any opinions are those of Benjamin Derge and not necessarily those of RJFS or Raymond James. Links are being provided for information purposes only. Expressions of opinion are as of this date and are subject to change without notice. Raymond James is not affiliated with and does not endorse, authorize, or sponsor any of the listed websites or their respective sponsors.

HackerOne for Cybersecurity

PODCASTS

FEDLIFE Podcast

The FedLife Podcast is your in-depth, biweekly deep dive into the world of federal benefits and retirement planning. Hosted by federal benefits expert Ed Zurndorfer and Dan Sipe of Serving Those Who Serve, each 30-minute episode unpacks the complexities of FERS and CSRS retirement, FEHB and Medicare, survivor benefits, tax planning, and more. Designed for federal employees and retirees who want more than just the basics, FedLife goes beyond the headlines to explore the rules, nuances, and strategies that can make a meaningful difference in your retirement. Remember: it’s your Fed life, make it a great one.

 

Image28

FED15 Podcast

The Fed15 Podcast is your weekly 15(ish)-minute briefing on federal benefits and financial planning, built specifically for federal employees and retirees. Hosted by Dan Sipe and Katelyn Murray of Serving Those Who Serve, each episode delivers clear, actionable guidance on topics like FERS and CSRS retirement, TSP strategies, FEHB, survivor benefits, tax planning, and more! Whether you’re five years from retirement or already there, The Fed15 helps you cut through the noise, avoid costly mistakes, and make confident decisions about your federal benefits.

 

Image29

GET MORE FROM YOUR
BENEFITS PACKAGE

SCHEDULE AN INITIAL CONSULTATION TODAY!