HackerOne, the pioneer in human-powered security, announced Essential VDP — a free, entry-level tier of HackerOne Response, its Vulnerability Disclosure Program (VDP) product.

Any organisation can now establish a VDP with HackerOne to help address compliance requirements and maintain a direct channel for the global researcher community to report high-impact vulnerabilities.

Regulatory requirements

Adopting a vulnerability disclosure program ensures that an organisation is prepared to handle security vulnerabilities effectively,” said Jason DeBord, CISO, Ohio Secretary of State. “Our VDP gives us a communication channel with security researchers so they can report vulnerabilities before bad actors find them.”

A growing list of standards and regulatory requirements from governments recognise VDPs as essential security best practices, including NIST 800-53, ISO 27001, and the Product Security and Telecommunications Infrastructure Act (PSTI).

Cybersecurity risk

Thousands of pioneering organisations have already adopted, and continue to adopt, VDPs because they work. They are a proven and fundamental best practice that reduces cybersecurity risk,” said Ilona Cohen, Chief Legal and Policy Officer at HackerOne.

Improving access to VDPs will make it easier for individual organisations to meet compliance standards and collectively improve the safety of the internet for everyone.”

VDP on HackerOne’s platform

Essential VDP gives organisations new to vulnerability disclosure free access to set up a VDP on HackerOne’s platform with the tools to:

  • Launch quickly through a guided onboarding experience, which includes training, product documentation, templated disclosure guideline support, and integration with a HackerOne inbox for easier vulnerability tracking and remediation.
  • Access industry-pioneering policy guidance and best practices informed by the thousands of programs on the HackerOne Platform.
  • Address compliance requirements with in-platform attestation reports as proof that you maintain a VDP for common frameworks and mandates.

HackerOne Essential VDP

We found that handling reports via email was becoming difficult to manage,” said Arthur Weibe, Site Reliability Engineer, ADAMnetworks. “HackerOne Essential VDP resolves this issue by providing a structured way to track all reports from triage to resolution. We get better reports, and the team has better visibility.”

HackerOne continues to support thousands of programs for pioneering brands, including established VDPs for The Ohio Secretary of State, Department of Defence, John Deere, and Adobe.

In case you missed it

Responsible AI adoption starts with governance
Responsible AI adoption starts with governance

The eagerness to adopt AI in physical security is increasing as teams want to implement technology solutions for faster, smarter operations. At the same time, the conversations sur...

How AI-enabled cameras are becoming operational sensors that power safety, automation, and business intelligence
How AI-enabled cameras are becoming operational sensors that power safety, automation, and business intelligence

The biggest return on investment from an AI-enabled camera might have nothing to do with security. Organisations are increasingly discovering that the same cameras installed to pro...

Solink's AI agents boost efficiency of existing infrastructure with automation
Solink's AI agents boost efficiency of existing infrastructure with automation

Deploying artificial intelligence (AI) tools should be seen as a business initiative rather than a technology initiative, says Martin Soukup, CTO of Solink, a cloud-based video sec...