I found this interesting results from a survey conducted recently by Wakefield Research commissioned by code evaluation firm Veracode.
One of the big takeaways from the survey was the fact that 59% of IT decision makers (ITDMs) think it’s more expensive to fix code flaws found in bug bounty programmes than to secure code during development.
I thought this was very interesting and surely suggests that these companies should spend more money investing in testing rather than offering bigger rewards for bug bounty’s?
What do you think?