Maryland Deploys Ethical Hackers to Probe State Systems | #hacking | #cybersecurity | #infosec | #comptia | #pentest | #hacker


Maryland brought in a group of ethical hackers for its Hack the State 2 event, resulting in the discovery and repair of more than 200 cybersecurity vulnerabilities, according to the Department of Information Technology (DoIT).

The event brought together 12 security researchers vetted by Bugcrowd, a vendor that connects organizations with a global community of ethical hackers and security researchers. This group worked alongside DoIT in May, hunting and finding vulnerabilities on public-facing websites. This is one way the state is taking on vulnerability management, along with a new vulnerability disclosure program.

“We’re able to have available to us some of the best security researchers across the nation who have a single dedicated focus of making Maryland systems more secure,” said state CISO James Saunders.


The first iteration of the event took place in October 2024 and uncovered about 40 bugs. Saunders said that he would advise against focusing solely on numbers because there is more than one factor at play. For instance, how long is the event, how many are involved and how is each vulnerability prioritized? It’s also possible AI might impact discoveries.

Aside from vulnerabilities, the security team and researchers also discovered business processes that needed work.

These are “logical business process issues … you may have perfect code, but that process needs further strengthening,” Saunders said.

To make this event happen, Maryland engaged with Bugcrowd through a traditional procurement process. DoIT chose a timeframe and a scope for the hacking event — this one being public-facing websites — and the vendor coordinated the vetting of security researchers, making sure that appropriate rules of engagement were in place.

Bugcrowd is also involved with the state’s related vulnerability disclosure program, which creates a public safe-harbor channel for researchers to report weaknesses in Maryland’s domains and connected networks. The program has yielded roughly 400 reports so far, which are triaged centrally and routed for rapid remediation. It has also helped the state fix flaws before they are exploited. Researchers who make a legitimate find are awarded a digital certificate or a challenge coin. Participants range from university students to full-time professionals.

The vulnerability disclosure program concept is found in the private and public sectors. Other governments that have launched them include California, Iowa and New York City.

“This is not a model where we pay for anyone to commit to this,” Saunders said. “They’re doing this out of the goodwill. They’re doing it out of their want to make Maryland a more secure state.”

Saunders was officially named CISO in May after a year of serving in an acting role. He is responsible for cybersecurity, privacy, and AI governance policies and standards in the executive branch, which serves more than 100 state entities and 80,000 users. DoIT also serves counties, school boards and more than 150 municipalities in a whole-of-state model.

“You still need your human-based testing, which could be through vulnerability disclosure programs or bug bounty. You need your automated scanning capabilities, let’s say using artificial intelligence yourself or using one of your automated vulnerability scanners,” he said. “And of course, you can continue to engage with your business leaders to make sure everyone’s on the same page around business logic to make sure it’s being coded appropriately. To me, it’s more like a six-sided die. It’s all one die, just different parts, so that you can have a solid vulnerability and patch management program.”





Click Here For The Original Source.

——————————————————–

..........

.

.

National Cyber Security

FREE
VIEW