Connect with us

Hi, what are you looking for?

SecurityWeekSecurityWeek

Application Security

Singapore Government Launches New Bug Bounty Program

The Singapore Government Technology Agency (GovTech) on Tuesday introduced a new Vulnerability Rewards Programme (VRP) on HackerOne that offers bug bounty rewards of up to $150,000.

The Singapore Government Technology Agency (GovTech) on Tuesday introduced a new Vulnerability Rewards Programme (VRP) on HackerOne that offers bug bounty rewards of up to $150,000.

GovTech already runs a Government Bug Bounty Programme (GBBP) and a Vulnerability Disclosure Programme (VDP), but aims to further expand its cybersecurity capabilities to better protect the Government’s Infocomm Technology and Smart Systems (ICT&SS).

By running three crowdsourced vulnerability discovery programs, GovTech aims to ensure it can take advantage of continuous reporting and seasonal in-depth testing that complement routine pen testing operations run by the government.

The expanded VDP is open to all members of the public to identify and report security holes in Internet-facing systems, but only white hat hackers who meet strict criteria are allowed to participate in the GBBP and VRP, because higher-value systems are involved.

[ Related: Google Paid $30M in Bug Bounty Rewards Over 10 Years ]

Selected systems are open for testing for each iteration of the seasonal GBBP, while the new VRP is meant to ensure continuous testing of a broad range of critical ICT systems that support the delivery of essential digital government services.

Advertisement. Scroll to continue reading.

Vulnerability reports submitted through the VRP may qualify for monetary rewards ranging between $250 and US$5,000, based on vulnerability severity. Security flaws that could cause “exceptional impact on selected systems and data” may qualify for a special bounty of up to $150,000.

“The special bounty is benchmarked against crowdsourced vulnerability programmes conducted by global technology firms such as Google and Microsoft. This signals the Singapore Government’s commitment to secure critical ICT systems and sensitive personal data,” GovTech says.

Initially, the VRP will cover three systems, namely Member e-Services (Ministry of Manpower – Central Provident Fund Board), Singpass and Corppass (GovTech), and Workpass Integrated System 2 (Ministry of Manpower).

With the VRP running on HackerOne, the platform will be responsible for vetting the white hat hackers who will be allowed to participate. Testing will be performed through a designated virtual private network (VPN) gateway that HackerOne will provide. Participants who break the permitted Rules of Engagement (ROE) may have their VPN access revoked.

Related: Singapore Ministry of Defence Launches New Bug Bounty Program

Related: Singapore Government Announces Third Bug Bounty Program

Written By

Ionut Arghire is an international correspondent for SecurityWeek.

Daily Briefing Newsletter

Subscribe to the SecurityWeek Email Briefing for the latest cybersecurity threats, trends, and expert insights.

Click to comment

Trending

Daily Briefing Newsletter

Subscribe to the SecurityWeek Email Briefing to stay informed on the latest threats, trends, and technology, along with insightful columns from industry experts.

Today’s attackers are no longer breaking in — they’re logging in. Join this live webinar as we break down the modern identity attack chain and examine how recent breaches exploited weaknesses in authentication, identity verification, and access management processes.

Register

AI has accelerated both sides of the fight. Adversaries are weaponizing vulnerabilities faster, while defenders are racing to ship detections and configurations. Join this live webinar as we explore how to prove your controls actually hold against new threats, map your security maturity, and unite breach simulation with automated pentesting into a single, coordinated program.

Register

People on the Move

Jonathan Trull has joined Oracle as Global Head of Cyber Defense.

Plaid has appointed Sean Cassidy as Chief Information Security Officer.

Ann Barron-DiCamillo has been named Executive Vice President and Global Chief Information Security Officer at U.S. Bank.

More People On The Move

Expert Insights

Daily Briefing Newsletter

Subscribe to the SecurityWeek Email Briefing to stay informed on the latest cybersecurity news, threats, and expert insights. Unsubscribe at any time.