TL;DR: Cybersecurity teams face persistent staffing shortages, with ISSA cited in INTIGRITI’s article as finding 38% of jobs remain open, while crowdsourced ethical hackers can add specialised testing capacity, practical learning, and better triage support. The structural value is not headcount replacement, but faster exposure detection and more resilient security operations.
NHIMG editorial — based on content published by INTIGRITI: 3 ways ethical hackers can help reduce cybersecurity skills gaps
By the numbers:
- 38% of cybersecurity jobs remain open, according to ISSA.
Questions worth separating out
Q: How should security teams use bug bounty programs alongside penetration tests?
A: Use penetration tests for targeted, scoped validation and bug bounty for continuous external pressure between change events.
Q: Why do skills shortages create more risk for identity and access controls?
A: When teams are short-staffed, they usually lose coverage in the places that require manual attention, such as access reviews, secret rotation, and third-party account oversight.
Q: What do organisations get wrong about incoming vulnerability reports?
A: They often treat reports as isolated tickets instead of repeated evidence about control failure.
Practitioner guidance
- Use bug bounty to test identity-adjacent attack paths Prioritise programmes that regularly probe authentication flows, OAuth integrations, service accounts, token handling, and privileged workflows rather than only surface-level application issues.
- Turn validated reports into control updates Require each accepted report to map to a specific remediation owner, a control family, and a follow-up check so fixes change the underlying process, not just the vulnerable instance.
- Strengthen triage around identity and secrets issues Make sure triage teams can quickly distinguish credential exposure, mis-scoped access, and privilege abuse from low-risk noise so scarce engineering time goes to material findings.
What's in the full article
INTIGRITI's full article covers the operational detail this post intentionally leaves for the source:
- How its bug bounty model helps organisations scale testing without adding internal headcount
- Examples of the educational resources and Hackademy materials mentioned in the article
- What makes a vulnerability report useful for internal security teams and triage
- Why dedicated triage support changes how quickly teams can act on valid findings
👉 Read INTIGRITI's analysis of how ethical hackers can help close cybersecurity skills gaps →
Ethical hackers and the skills gap: what teams can actually use?
Explore further
External ethical hacking works best as a control extender, not a staffing substitute. The article is right to frame bug bounty programmes as a way to add capacity, but the governance value lies in extending coverage where internal teams are thin, not replacing core security ownership. For identity teams, this matters because access paths, secrets, and privilege boundaries often fail in edge cases that external researchers are more likely to probe. Practitioners should treat crowdsourced testing as a complementary detection and validation layer.
A question worth separating out:
Q: Who should own remediation when ethical hackers find identity-related weaknesses?
A: The security team should coordinate, but ownership should land with the control domain that failed. For access and secrets issues, that usually means IAM, platform, or application owners working from a defined remediation path. Clear accountability prevents external findings from becoming long-lived backlog items.
👉 Read our full editorial: Ethical hackers can help close cybersecurity skills gaps