Security Magazine logo
search
cart
facebook twitter linkedin youtube
  • Sign In
  • Create Account
  • Sign Out
  • My Account
Security Magazine logo
  • NEWS
    • Security Newswire
    • Technologies & Solutions
  • MANAGEMENT
    • Leadership Management
    • Enterprise Services
    • Security Education & Training
    • Logical Security
    • Security & Business Resilience
    • Profiles in Excellence
  • PHYSICAL
    • Access Management
    • Fire & Life Safety
    • Identity Management
    • Physical Security
    • Video Surveillance
    • Case Studies (Physical)
  • CYBER
    • Cybersecurity News
    • More
  • BLOG
  • COLUMNS
    • Career Intelligence
    • Cyber Tactics
    • Cybersecurity Education & Training
    • Leadership & Management
    • Security Talk
  • EXCLUSIVES
    • Annual Guarding Report
    • Most Influential People in Security
    • The Security Benchmark Report
    • Top Guard and Security Officer Companies
    • Top Cybersecurity Leaders
    • Women in Security
  • SECTORS
    • Arenas / Stadiums / Leagues / Entertainment
    • Banking/Finance/Insurance
    • Construction, Real Estate, Property Management
    • Education: K-12
    • Education: University
    • Government: Federal, State and Local
    • Hospitality & Casinos
    • Hospitals & Medical Centers
    • Infrastructure:Electric,Gas & Water
    • Ports: Sea, Land, & Air
    • Retail/Restaurants/Convenience
    • Transportation/Logistics/Supply Chain/Distribution/ Warehousing
  • EVENTS
    • Industry Events
    • Webinars
    • Solutions by Sector
    • Security 500 Conference
  • MEDIA
    • Interactive Spotlight
    • Photo Galleries
    • Podcasts
    • Polls
    • Videos
      • Cybersecurity & Geopolitical Discussion
      • Ask Me Anything (AMA) Series
  • MORE
    • Call for Entries
    • Classifieds & Job Listings
    • Newsletter
    • Sponsor Insights
    • Store
    • White Papers
  • EMAG
    • eMagazine
    • This Month's Content
    • Advertise
  • SIGN UP!
CybersecuritySecurity Enterprise ServicesSecurity Leadership and ManagementLogical Security

Why this moment in cybersecurity calls for embracing hackers

By Marten Mickos
Hacker in a hoodie

Image via Pixabay

August 25, 2023

When the pandemic hurled us into a cybersecurity crisis, there were some who held out hope that things would eventually return to normal. By now, we know those hopes were misguided, and the picture has only grown darker with time. According to the World Economic Forum, cybercrime now poses the greatest threat to businesses today. Populations of entire countries are at heightened risk, with Microsoft finding that nation states are increasingly targeting critical infrastructure. Today's digital threat actors have attained a degree of sophistication and savvy that has boggled cybersecurity veterans, who are struggling to keep up with their advanced and increasingly destructive methods.

Given this pressure to compete with cybercriminals, you’d expect organizations to make eager use of every cybersecurity tool at their disposal. And yet countless organizations continue to ignore one of the most effective and time-tested cybersecurity tools we have: the ethical hacker.

By 2023, I’d have hoped the global hacker community would be a widely accepted, routine part of every company's cybersecurity toolkit — as mundane and uncontroversial as firewalls or security hygiene training. After all, hackers have been a respectable part of the cybersecurity world for nearly 30 years now, ever since Netscape pioneered the first bug bounty program in 1995. In the years since, companies like Microsoft, Facebook, and Google have all implemented — and doubled down on — their own hacker-driven programs. 

These tech giants are not the kinds of organizations known for willingly putting themselves at risk. Neither, for that matter, is the U.S. Department of Defense (DoD), which, over the years, has received more than 46,000 actionable vulnerability reports from a worldwide community of nearly 5,000 hackers. We are talking about some of the best-advised, best-fortified, most technologically advanced organizations, staffed by intelligent people who are highly incentivized not to screw things up for their employers.  

Hackers are good enough for them. So why, after all this time, are so many still hesitant to trust hackers? 

On one level, it's a branding problem: for too many, the term “hacker” still brings to mind people with malicious intent. However, given how much hackers have contributed to the safety of our current cybersecurity landscape, to prepetuate this outdated image in 2023 is no longer just misinformed, it hinders the future safety of the internet. As Gartner has pointed out, cybersecurity programs must be human-centric, or else they will fail. 

Put otherwise: companies that don't make use of hackers are putting themselves at higher risk. 

Why hackers thrive where technology fails

You can't plan for the things you can't know in advance. Yes, every sensible company tests its code before production, but many security vulnerabilities don't exist until the code is actually deployed — until it's really out there in the world. Allowing an outdated fear of hackers to prevent you from getting a comprehensive picture of your security vulnerabilities is fundamentally irrational — and self-defeating. Real-life testing — the kind only hackers can offer —i s indispensable. You simply cannot get the same results from any other method. 

Secondly, there's the human element to consider: where testing software can only find known unknowns, humans are gifted with the ingenuity to find the unknown unknowns, the vulnerabilities you wouldn’t even know to look for in the first place. And because these hackers are not part of your organization — because they're coming in from the outside, their sight is unclouded by the bias that builds from working on the same product month after month, year after year. This is no small thing in light of the fact that 95% of applications or systems have at least one vulnerability.

But potential bias isn't the only in-house limitation. There is also the fact that, owing at least in part to the ongoing IT skills gap, most companies do not have the personnel to accommodate the kinds of continuous testing that true safety requires. The supply of hackers, on the other hand, is nearly unlimited—the worldwide community is so large that testing can be conducted continuously by a wide range of experts equipped with different yet complementary skill sets.  

Hackers get results 

The potential results here are far from abstract. 

For one thing, hackers will inevitably surface vulnerabilities that are unfindable by any other method. Also, hackers won’t inundate your IT teams with irrelevant and distracting false positives, which are endemic to most cybersecurity programs.

Fewer and fewer companies are still holding out on hackers: by now, their indispensability to security practices is the common consensus. According to a survey HackerOne conducted at RSA, 88% of cybersecurity professionals believe that ethical hackers can have a positive impact on cybersecurity. Among those holdouts, you continue to hear one common concern — namely, that these places don't want to have to deal with finding and coordinating the relevant hackers. But this concern, too, is outmoded, as many companies now exist that can take care of all of this work for them.

All this would be important even if things were relatively calm in the world of cybersecurity. Cybercrime has entered its steroid era: the enemy is stronger than ever, and even a moment's lapse in vigilance can spell disaster for a company. If hackers were just a third as effective as long experience has demonstrated them to be, it would be malpractice not to make use of them. hackers’ research and responsible reporting has managed to avert thousands of crises over the years and continue to do so. Don’t let false, obsolete notions about hackers imperil your company’s safety.

KEYWORDS: cyber threats ethical hacking hackers threat actor

Share This Story

Looking for a reprint of this article?
From high-res PDFs to custom plaques, order your copy today!

Marten Mickos, CEO of HackerOne.

Recommended Content

JOIN TODAY
To unlock your recommendations.

Already have an account? Sign In

  • Cyber tech background

    Security’s Top Cybersecurity Leaders 2026

    Security magazine’s Top Cybersecurity Leaders 2026 award...
    Cybersecurity
  • Iintegration and use of emerging tools

    Future Proof Your Security Career with AI Skills

    AI’s evolution demands security leaders master...
    Columns
    By: Jerry J. Brennan and Joanne R. Pollock
  • The 2025 Security Benchmark Report

    The 2025 Security Benchmark Report

    The 2025 Security Benchmark Report surveys enterprise...
    The Security Benchmark Report
    By: Rachelle Blair-Frasier
Manage My Account
  • Security Newsletter
  • eMagazine Subscriptions
  • Manage My Preferences
  • Online Registration
  • Mobile App
  • Subscription Customer Service

More Videos

Popular Stories

Person in red hoodie

When Metal Theft Becomes a Life Safety Crisis

Stacked books

Safe Learning 101 Program Supports Schools in Strengthening Campus Security

Diverse Team Collaborating on Business Analysis

12 Tips for Building an Effective Security Budget

Nurse

Why De-Escalation Must Be Part of a Layered Safety Strategy in Healthcare

Two women consulting with a group in background

5 Skills That Will Serve You in Your Security Career

SEC 2026 Benchmark Banner

Events

May 21, 2026

From Referral to Response: Managing Domestic Violence Threats in the Workplace

Domestic violence remains a complex driver of workplace violence, creating high-risk scenarios that require coordination across departments without clear ownership. Learn how threat management teams can manage domestic violence referrals from the start.

June 3, 2026

The Role of AI and Video in Measuring Health, Safety, and Security Standards

OSHA fines grab headlines, but most compliance issues start with everyday operational gaps: missed protocols, unsecured areas, or slow response. Learn how emerging technologies & AI can be leveraged towards a more proactive model of compliance.

View All Submit An Event

Products

Security Culture: A How-to Guide for Improving Security Culture and Dealing with People Risk in Your Organisation

Security Culture: A How-to Guide for Improving Security Culture and Dealing with People Risk in Your Organisation

See More Products
Solutions by Sector webinar promo


The Role of AI and Video - Free Webinar - June 3, 2026

Related Articles

  • Cybersecurity Bill in U.S. Senate Calls for Industry Rules

    See More
  • Healthcare Data Compliance: Maintaining Integrity, Privacy and Security

    Why hospitals can’t ignore this cybersecurity awareness month

    See More
  • technology-freepik

    Why embracing tech can boost safety and productivity for your team

    See More

Related Products

See More Products
  • security culture.webp

    Security Culture: A How-to Guide for Improving Security Culture and Dealing with People Risk in Your Organisation

  • Photonic Sensing: Principles and Applications for Safety and Security Monitoring

  • Physical Security and Safety: A Field Guide for the Practitioner

See More Products
×

Sign-up to receive top management & result-driven techniques in the industry.

Join over 20,000+ industry leaders who receive our premium content.

SIGN UP TODAY!
  • RESOURCES
    • Advertise
    • Contact Us
    • Store
    • Want More
  • SIGN UP TODAY
    • Create Account
    • eMagazine
    • Newsletter
    • Customer Service
    • Manage Preferences
  • SERVICES
    • Marketing Services
    • Reprints
    • Market Research
    • List Rental
    • Survey/Respondent Access
  • STAY CONNECTED
    • LinkedIn
    • Facebook
    • YouTube
    • X (Twitter)
  • PRIVACY
    • PRIVACY POLICY
    • TERMS & CONDITIONS
    • DO NOT SELL MY PERSONAL INFORMATION
    • PRIVACY REQUEST
    • ACCESSIBILITY

Copyright ©2026. All Rights Reserved BNP Media, Inc. and BNP Media II, LLC.

Design, CMS, Hosting & Web Development :: ePublishing