TL;DR: Bug bounty participation is shaped as much by program responsiveness, scope hygiene, and researcher workflow as by technical skill, while AI hype is adding uncertainty to how hunters start and learn, according to INTIGRITI. The practical lesson is that response quality and program clarity now influence whether security researchers stay engaged long enough to surface meaningful findings.
NHIMG editorial — based on content published by INTIGRITI: Marketer by day, bug hunter by night. Interview with Stefan Goossens (G0053)
By the numbers:
- Only 20% have formal processes for offboarding and revoking API keys, and even fewer have procedures for rotating them.
- Only 5.7% of organisations have full visibility into their service accounts.
- 97% of NHIs carry excessive privileges, increasing unauthorised access and broadening the attack surface.
Questions worth separating out
Q: How should teams keep bug bounty or security programmes from losing researcher momentum?
A: Teams should reduce uncertainty, not just volume.
Q: Why do slow review cycles weaken security governance?
A: Slow review cycles create feedback latency, which makes it harder for participants to understand whether a control is working.
Q: What do teams get wrong about business logic testing?
A: They assume it can be fully automated.
Practitioner guidance
- Tighten triage SLAs Set measurable acknowledgement and resolution targets for reports, exceptions, and access review findings so stakeholders can see progress before trust erodes.
- Keep scope and known issues current Maintain a live programme page or control register that clearly separates in-scope items, fixed issues, and acknowledged exclusions, then review it on a fixed cadence.
- Test workflows for negative-path behaviour Validate identity and access processes by checking what happens when users, services, or applications do the opposite of the expected action.
What's in the full article
INTIGRITI's full interview covers the operational detail this post intentionally leaves for the source:
- Stefan Goossens' full workflow for balancing web development with bug bounty hunting and how that shapes his research habits.
- His practical approach to choosing programmes, including how he tests whether responsiveness and scope are worth continued effort.
- The specific tools and note-taking workflow he uses to carry ideas between work, home, and mobile contexts.
- His comments on AI-assisted hunting, including where he sees help versus where he still prefers manual judgement.
Bug bounty program hygiene: what keeps researchers engaged?
Explore further