If you run a vulnerability response or bug bounty program (or both), there's a good chance you're experiencing substantial growth year over year. In this talk, Pieter Ockers of Adobe's PSIRT will tell the story of how incremental steps to mature a vulnerability management framework can help decrease the average number of unresolved vulnerabilities, as well as reducing the average age of unresolved cases.
Pieter will share tips on:
Developing productive relationships with resource-constrained engineering teams
Leveraging vulnerability submission platforms to scale your team
Developing vulnerability taxonomies to consistently score risk
Implementing an escalation protocol to improve response outcomes
Selecting the right data for the executive audience
Applications of the 80/20 rule for vulnerability response
Speaker:
Pieter Ockers is a Senior Security Program Manager and runs Adobe’s Product Security Incident Response Team (PSIRT). Based in San Francisco, Pieter is passionate about engaging with the security research community to build a stronger, more secure and resilient ecosystem.