Our AI strategy for preemptive security
Many of our customers ask us some version of the same question: should we do a live hacking event, and if so, which kind? It’s a fair question, because live hacking events can take many forms. Bugcrowd runs four distinct formats depending on your goals, budget, and scope.
The good news is that the decision isn’t a guessing game. It comes down to three factors: how mature your existing bug bounty program is, what you actually need tested, and what you’re trying to accomplish. Here’s how to work through each one.
Live hacking events build on top of an existing testing program, not in place of one, and each format assumes a different starting point:
If you’re earlier in your program, that’s not a disqualifier—it just points you toward a Virtual event first, both as a lower-cost way to prove out live testing and as a natural lead-up to an in-person event down the road.
Once maturity is out of the way, the next filter is intent. What are you actually trying to get out of this?
Choose Virtual if you want a low-cost proof of concept for leadership, or you need to test a specific new feature before it’s added to your main program scope. Virtual events don’t require an open scope, which makes them a good way to let top hackers test something narrow without exposing everything else.
Choose Live in the Loop if you’re dealing with a sensitive business unit, or you need a highly specialized skill set—like social engineering—and want to prove that live hacking works without the scale (and cost) of a full production. This format applies the principle of least privilege: a smaller, more curated hacker group gets access to more sensitive targets, which keeps the signal-to-noise ratio high and minimizes incidents.
Choose Bug Bash if you want a high-visibility marketing moment alongside broad testing coverage, and you’re ready to invest in a larger hacker cohort. Bug Bashes default to a wide-open scope specifically to maximize participation—generally 10 to 50 hackers—which is also why they’re better suited to programs with a year or more of maturity behind them.
Choose ReCON if you want to invest in the broader security research community with a multitrack event that includes talks and workshops, or you need to bring multiple stakeholders—including other vendors—together around shared infrastructure. ReCON events are typically run as annual flagship events rather than a recurring product, and can even be sponsored across multiple customers.
Once you’ve picked a format, scope should be driven by two things: what actually needs testing and how sensitive that target is. Web, AI, and crypto assets are well suited to Virtual events. Hardware, operational technology, and social engineering all require physical or in-person access, which means Live in the Loop or Bug Bash. ReCON events typically span web, hardware, and AI given their scale.
Costs generally cover the hacker reward pool plus event production—travel, food and beverage, venue, custom swag, on-site operations, and priority triage. They scale up with the size of the hacker cohort and the complexity of on-site logistics; hardware or OT testing, for instance, needs a more specialized setup than a standard web-focused event.
Whichever format fits, the underlying case for live hacking events holds across all four. Organizations see faster, higher-quality vulnerability discovery, with a lasting effect on program quality well after the event ends. In-person formats surface coverage for assets that can’t be tested remotely. These events draw a different, often more specialized pool of hackers than a standing program; they tend to surface vulnerabilities a standard program might miss entirely. At Indeed’s first live hacking event, over 63% of the findings were net new, even with an established bug bounty program already running.
As Steve Kain, Director of Adversary Emulation at the Maryland Department of Information Technology, put it: “There’s a fear of, ‘What happens when we do this? What happens when we find out?’ But ignorance isn’t bliss. You want to know where the problems are.”
Matching your program’s maturity, your goal, and your scope to the right event format is exactly the kind of thing that’s easier with a framework in front of you than a blank page. We put together a full breakdown—including decision trees, hacker and timeline commitments by asset type, and more customer results—in our new solution brief, Live hacking events: Everything you need to know.