TL;DR: A survey of more than 1,700 ethical hackers found 66% are considering bug bounty hunting full time, while 96% want to spend more time on it and 88% of testers say a single penetration test cannot provide year-round assurance, according to INTIGRITI. The shift points to continuous pressure, not point-in-time testing, as the practical benchmark for modern security programmes.
NHIMG editorial — based on content published by INTIGRITI: Ethical Hacker Insights Report 2022 coverage of bug bounty careers and continuous assurance
By the numbers:
- 66% of cybersecurity talent are considering bug bounty hunting as a full-time career.
- 96% of ethical hackers would like to dedicate more time to bug bounty hunting in the future.
- 50% of respondents say they turn to bug bounty hunting to learn the most relevant and useful knowledge.
Questions worth separating out
Q: How should security teams use bug bounty programs alongside penetration tests?
A: Use penetration tests for targeted, scoped validation and bug bounty for continuous external pressure between change events.
Q: Why do bug bounty findings often expose identity and access problems?
A: Because many exploitable weaknesses sit in authentication, authorisation, token handling, and privilege design rather than in the visible application layer.
Q: What do organisations get wrong when they rely on one-off security testing?
A: They assume a point-in-time result still describes a live environment after code changes, configuration drift, and new integrations.
Practitioner guidance
- Adopt continuous assurance for internet-facing control points Use bug bounty and continuous testing to validate authentication flows, exposed APIs, and access boundaries between formal review cycles.
- Prioritise identity findings over cosmetic application issues Triage leaked secrets, OAuth scope errors, service account overreach, and session weaknesses ahead of lower-impact user-interface defects.
- Map external findings back to IAM and NHI controls Convert recurring bug bounty issues into control themes such as credential rotation, entitlement review, and third-party access governance.
What's in the full report
INTIGRITI's full report covers the survey detail this post intentionally leaves for the source:
- Breakdowns of why respondents prefer bug bounty work, including the career and lifestyle factors behind the shift.
- Survey methodology and the profile of more than 1,700 ethical hackers, useful for understanding the sample behind the findings.
- Additional sentiment data on how researchers compare bug bounty learning value with traditional employment.
- Practical context on how the report interprets continuous testing versus one-off penetration assessments.
👉 Read INTIGRITI's ethical hacker insights report on bug bounty careers and continuous testing →
Bug bounty hunting is rising, but are your controls keeping up?
Explore further
Continuous assurance is now the real control objective. The report reinforces a basic but often ignored truth: security cannot be validated once and assumed safe for months. Continuous external testing is especially relevant where identity, secrets, and privilege change quickly. For IAM and NHI programmes, the practical conclusion is that assurance must be operational, not ceremonial.
A question worth separating out:
Q: How can organisations turn bug bounty results into better governance?
A: Map each recurring finding to a specific control owner, then track whether the fix changes the underlying behaviour, not just the reported instance. If the same class of issue keeps reappearing, the problem is usually lifecycle control, entitlement design, or remediation speed. That is where governance must change.
👉 Read our full editorial: Bug bounty is becoming a career path, but security assurance is still stale