# Championing CyberSecurity: Grab's bug bounty programme in 2023

[Grab](https://yomu.fyi/company/grab) · Nathaniel Callens · Dec 19, 2023

**Type:** Explainer

## Summary

Grab reviewed the performance and milestones of its security bug bounty programme for 2023, marking eight years of running the initiative. Operating quarterly campaigns through HackerOne alongside dedicated internal teams, the company processed approximately 1,000 vulnerability submissions over the year, including 400 reports during Q1 alone. Cumulative payouts to external security researchers surpassed $700,000 since the programme's 2015 launch. To adapt to an expanding service portfolio, Grab broadened its scope to encompass joint ventures and acquisitions while introducing diversified financial and recognition-based rewards.

## Context

Grab needed to fortify its evolving product portfolio, ecosystem expansion, and emerging security challenges through continuous engagement with external security researchers.

## Approach / What changed

Grab ran quarterly HackerOne campaigns, enriched monetary incentives, added a targeted Threatcon Nepal campaign, expanded internal bug bounty staff, and widened testing scope to include joint ventures and acquisitions.

## Takeaways

- Grab processed roughly 1,000 bug bounty submissions in 2023, with 400 arriving during the Q1 campaign alone.
- Cumulative payouts to security researchers have exceeded $700,000 since the programme began in 2015.
- The scope of the bug bounty programme expanded to include joint ventures and acquisitions to secure Grab's growing ecosystem.

**Tags:** [Reliability](https://yomu.fyi/topic/reliability), [Testing](https://yomu.fyi/topic/testing)

[Read original post](https://engineering.grab.com/cybersec-bug)
