
The Decibel Podcast: Founders Helping Founders · 2025-08-13 · 44 min
Key moments - from our scoring
Substance score
44 / 100
Five dimensions, 20 points each
Casey Ellis built BugCrowd by identifying three key market failures: inefficient penetration testing economics (companies paying 2,500% markups), the lack of legitimate pathways for hackers to apply their skills legally, and the need to democratize access to security expertise. After experimenting with white-label security and pen testing in Argentina and the Philippines, Ellis realized that vulnerability discovery could be gamified and crowdsourced more effectively than traditional consulting. The lightbulb moment came during a client meeting in Melbourne when customers expressed interest in bug bounties but cited barriers: fear of hackers, payment logistics, and team capacity. Ellis registered BugCrowd.com that day and validated the model by onboarding 3,000+ security researchers within weeks, proving that both community appetite and customer demand existed. His insight was reframing bug bounties not as a new service category but as a fundamental shift in vulnerability economics and the future of security work, where incentive structures and distributed talent could outperform traditional hourly models.
Ellis recognized that paying 20-200 hackers to find vulnerabilities in a system would yield better results than paying one hourly consultant, combined with observing that customers wanted bug bounties but lacked the platform and operational infrastructure to run them safely.
He posted a simple webpage asking 'do you want to hack stuff' and tweeted it, onboarding 3,000-4,000 security researchers in 1-2 weeks, then ran a pilot program with a live customer before even entering an accelerator.
Market failure in penetration testing economics (companies paying 2,500% markups), the lack of legitimate career paths for hackers to apply their skills legally, and the need to discover vulnerabilities before threat actors do as threat landscape expands.
Instead of paying one consultant hourly, companies can pay rewards proportional to vulnerability impact to a distributed community of hackers, allowing for better coverage of the attack surface at comparable cost.
It was the metric of how many hackers needed to apply to a target in order to find something the customer didn't already know about, measuring the effectiveness of distributed testing versus traditional methods.
Our reviewer’s read on each dimension, with quotes from the episode.
The episode has a handful of genuinely useful framings for B2B operators - the 'puppy mill pen testing' market-failure critique, the VDP-vs-bug-bounty distinction, and the antifragility of transparency - but they are buried under extended origin story, music philosophy, nuclear physics digressions, and a long health narrative that carries almost no operational signal for a practitioner.
you can pay someone a hundred dollars an hour, mark it up to 2,500 and sell it to the street, and then everyone walks away from that happy. This is a zero sum game that we're playing here
I personally actually don't believe that every organization should run a public bug bounty program. I don't think that everyone's ready for that. I do think that everyone needs to have a vulnerability disclosure program
'Criminal creativity' as a distinct lens on attacker thinking and the explicit argument that industry competitiveness slowed category adoption are genuinely fresh; however, the episode also leans on worn founder-culture tropes ('just do it', 'no perfect time', 'have grace for yourselves') and the transparency-as-antifragile framing is borrowed rather than developed.
criminal creativity. Just the idea of like this is entrepreneurship and invention, like without rules
I do feel like the category itself probably could have got more done had we not been as competitive with each other
Casey Ellis is a legitimate category-creating founder who built Bugcrowd from zero, ran the Hack the Pentagon program, and shaped government vulnerability-disclosure policy - genuine practitioner credentials; the transcript, however, keeps him mostly at anecdote and analogy level rather than drawing out the operational depth his experience should yield.
I saw it as like basically being in a position to alter the fundamental economics of vulnerability discovery, like full stop
we did a little like, do you want to hack stuff? Webpage? And I kind of tweeted it and we onboarded like three or 4,000 people
A handful of concrete data points appear - the $100/hr marked up to $2,500, 3-4k early signups, 21% cardiac capacity, a 2016 automotive live-hacking event - but there are no revenue figures, customer counts, bounty payout data, or program ROI evidence that a practitioner could actually act on or benchmark against.
you can pay someone a hundred dollars an hour, mark it up to 2,500 and sell it to the street
we onboarded like three or 4,000 people
The host rarely probes or challenges: questions are mostly leading or biographical, the health section is handled gently with no follow-up on business impact, and the closing question ('do you think your parents are finally proud?') is pure PR. One creative metaphor question about technical debt shows potential but is immediately answered without pushback.
And just to come full circle, now that you've turned hacking into not just a profession for yourself, but also a profession for over a million other hackers, do you think your parents are finally proud?
Is part of your life story a metaphor for how software is built? Early on we have to run hard, we've got to ship things quickly, but eventually we have to take on the technical debt
Computed from the transcript - who did the talking, and the words that came up most.
Casey Ellis is the founder of BugCrowd, the first open marketplace for vulnerability disclosure and commercial bug bounties. On today’s episode, Jon Sakoda speaks with Casey on the early economics of paying people to hack companies, why ethical hackers are an amazing source of criminal creativity, and why every founder needs to ultimately fix their known vulnerabilities: Why the Economics of Bug Bounties are 20x the Status Quo [11:23-14:42] - Casey had global access to talent around the world and saw that there was a huge opportunity to empower the best and brightest hackers to be paid for finding vulnerabilities. This was a 20x improvement on traditional pen testing and opened the floodgates on bringing traditional hacking out of the dark and into the light. How the Best Hackers and Companies Find Success Together [15:04-24:30] - Bugcrowd early on attracted some of the best hackers onto its platform, but ultimately needed to teach companies how to engage. Setting the right reward incentives, the right targets, and offering responsive feedback were key to getting the right level of engagement on the marketplace in the early innings.
Transcribed and scored by The B2B Podcast Index.
Speaker A: My favorite definition of a founder is someone who gets irrationally pissed off about a problem they think they can solve. Right. That was the irrationally pissed off part because it's like these are just dumb problems for the Internet to have and we're getting hosed by the baddies when they want to do bad things. And that's only going to get more and more true as the Internet expands, as threat actors diversify. So these are all the things that are kind of bouncing around my head before I pulled the trigger on Bug Crab.
Speaker B: Welcome to the Decibel Podcast. I'm excited to welcome my friend Casey Ellis to the show. Casey is the founder of Bug Crowd. He is the pioneer of commercial bug bounties. He's also a friend of many founders and made hacking a, uh, legitimate profession for so many of us. Casey, welcome, um, to the Decibel Podcast.
Speaker A: Thanks, John. Excited to be here. G'.
Speaker B: Day. I guess that is a great segue to where did you grow up? Tell me about what your parents did, how you eventually found computers. Give me all the details.
Speaker A: Yeah, sure. Uh, backstory wise, I am from, originally from Sydney, Australia. I live now in, in the Bay Area. But yeah, that's where you hear the funny accent from. It's, it's definitely curved off a little bit. I get crap for sounding like an American when I go back home now because I, you know, roll the R's and do do all those different things. But yeah, so how did I get started? Probably the biggest thing was, you know, I was very obviously a super curious kid from, from a very young age. And my parents, to their credit, kind of identified that and just pretty much did whatever they could to, to foster it and give me opportunity. Right. Like my, my dad at the time was a, uh, science teacher. He would take me out of school in kind of elementary school and bring me to high school and different things like that. And then at some point a computer came home and that's, that's when that all started. But prior to that, I was tearing apart, you know, electronics and radios and, and all that other stuff. There was just a really strong set of really good conditions to kind of nurture that, that sort of creativity and that sort of hacker side of thinking. Mum's a clinical psychologist, you know, they're both very much kind of entrepreneurs in their own right. So there was a little bit of that DNA that, you know, I figured out kind of later on in life. So that's, that's how that all got kind of got kicked off.
Speaker B: How did you eventually Learn how to hack things. And then how did your parents feel about that?
Speaker A: Yeah, the second one's probably a little bit more interesting. Look, it was bbs. Uh, that's kind of the generation, of course. Yeah, I finished school in 99. So that' that sort of gives you an idea of part of the uh, Oregon Trail generation that kind of started school completely analog and ended basically digital. You know, kind of prior to that I was just monkeying about with stuff like learning how to code in basic, you know, figuring out that there was some sort of program backdoors in Apple IIe's that you could use to get the computer to do stuff it wasn't necessarily designed to do or design in an obvious way to do. And you know, once I started sort of discovering that stuff in computer science land, I was kind of hooked. Parts of that kind of coincided with, you know, teenage years and just getting a little bit rebellious generally. Like I was in the crowd that were all very much kind of rebels and didn't really care too much about rules and took as many opportunities as we could to break rules just based on them being there in the first place. And I think you know, hacking kind of folded into that. There was, there was a lot of, you know, bypassing of filters on school computers and, and different things like that. And my parents were definitely not super happy about that.
Speaker B: This sounds really familiar. A lot of our guests started out hacking and sounds like you were also an irreverent child. Mom didn't sound super happy. But I think I remember reading somewhere that you somehow went to school eventually to get a degree in nuclear medicine. How exactly did that come about?
Speaker A: Yeah, it was so um, nuclear physics. And to me like physics is like basically applied math, right? So you know, the idea of, of like nuclear physics, I for some reason got kind of caught up on that when I was probably in uh, a year six or year seven maybe. And it was just, I was just fascinated by it. I just loved it. It just kind of gripped me because this idea of, of being able to distill things down to their most primitive kind of fundamentals, but then not going any further than that to the point where you actually alter the nature of what you're talking about. Like that's a uh, principle that I still apply today that's probably more of a brain wiring thing than it is anything else. And then went to university for like six weeks. Loved it, loved learning, loved like the social aspect, loved the community, all those different things. But it was just a matter of like eh, this Just doesn't feel like it in terms of what I want to spend the next six years of my life doing to kind of get to the end of. I think partly it was just a uh, like I actually don't think that tertiary education was for me in the first place. Just the idea that like my learning style is pretty non linear and trying to cram it into like a linear system for the next six, six years after I just spent 12 years in high school kind of, you know, basically skirting around the edges of all of it as much as I possibly could. It just didn't seem to make sense.
Speaker B: That's why a lot of founders drop out of school, right? Is they sort of feel I'm going to learn, but I can't really learn this way.
Speaker A: Yeah, if you're doing the founding thing, you know, you're already like definitely crazy to begin with because that's just, that's just what you've got to be in order to do this, right. Like we're not normal kind of by definition of the things that we're taking on. Pretty much the next part of that actually I'll just. Because this is the fun bit, you know, really had no idea what, what I wanted to do when I grow up. Just knowing that I could do lots of different things. I didn't realize that hacking was a skill set or a career or even a mindset that I could actually do useful non criminal things with. And a, uh, friend of mine had an IT consulting shop to his credit. He basically identified all of what I just said in terms of potential and lack of directionalized different things and offered me an apprenticeship there, which was cool. That got me into IT proper. But then not long after I started like hacking stuff on behalf of customers to sort of demonstrate where I saw vulnerabilities and issues in their systems. And that's when I realized that, oh okay, this is actually a career. I could do this, not be criminal, make money off it, do these things that I love, you know, actually figure out, you know, what I'm meant to do with the rest of my life in the process.
Speaker B: Wait, before we get too much further, I think you once told me that part of your founding story is also derived from your love of music. I don't think anyone really understands this connection. Can you describe how hacking and music work together in your mind?
Speaker A: So I can play pretty much anything that I sort of pick up if you give me a bit of time, but drums and audio engineering and actually back in the day I'd sing As well. That's the kind of stuff I'd actually do as a, as a performance thing in front of, in front of audiences. So that's sort of, you know, backstory. I think the singing part is pretty crazy because it's like, to me, one of the most vulnerable musical things that you can do because it's just literally your voice and yeah, drums to me is I've just drawn a ton of analogies. Like, I've had a lot of conversations with folk and security about this, but it's sort of popped out more and more in the founder and entrepreneurship community as well. Because to me, like, music, music's amazing because it's like on one side, the like, purest math you could think of. Right? When you think about like, what sound is and how sounds work together and what an interval is and all those different like, timing, rhythm, all of it, it's like, it's just math, but it's like almost to me, the purest form of math. But then on the other side you've got the fact that like communicating that math is not actually the purpose of music. Do you know what I mean?
Speaker B: Like, absolutely.
Speaker A: To me, the purpose of music is actually to speak. It's almost to bypass the intellect and speak to someone at a level and you're using math to do that.
Speaker B: It's a higher order form of communication.
Speaker A: And I think, yeah, back on the math thing, like, there's, there's this sort of reconciliation of the creative and the deeply technical that happens in music that I actually think is really like the kind of wiring that naturally gravitates towards that I think is the kind of wiring that actually does well in, in security in particular. Like it feels like musicians are kind uh, of overrepresented in the security community, if that makes sense.
Speaker B: I'm glad you're unboxing this for everyone I know. Doug Song, the founder of Duo who came on our show, talked about how hip hop artists had inspired him early in his career. He talked about how he could see that they would build on each other as creators. Is there some similar connection in the hacking world? Do you feel if you can connect with music that you can also connect with software?
Speaker A: Yeah, look, I think some of the best hackers, in terms of how prolific they are or how creative their output is, they're the ones that like, uh, kind of understand the creator of the thing that they're attacking through the course of attacking it. So it's not just like, I know how to test for this type of phone or even Like I know how there are consistent any patterns in this type of implementation or whatever. It's like, no, I actually can sort of start to step into the shoes of the person who wrote this thing.
Speaker B: Absolutely. It's like the people that create great software are also the people that can break great software. Right. You know what the creator was intending. So in some ways you're inside their mind.
Speaker A: Yeah, there's a, there's an empathy component to it, but it does interface through that technical layer.
Speaker B: Before we get to the bug crowd story, take me back. I know you had a lot of different entrepreneurial experiments and eventually started Top Poppy Group, which I think was your first official startup. And that ultimately led to the idea which led to bugcrowd. But take us back there. What was going through your mind back then?
Speaker A: Yeah, so Tall Poppy Group was basically, you know, when I realized, oh yeah, I want to be an entrepreneur. The name really is, uh, coming from Tall Poppy syndrome, which, if you, if you haven't heard about that, it's. It's essentially like the Commonwealth tendency to cut down people that are trying to do something overachieving. I do think that that is a feature of Australian culture that actually really, really holds us back. Like culturally, we're pretty much just genetically good at solving things with whatever's within arm's reach, but we suck at sales and marketing. So it's like, all right, yeah, how do I kind of tip the hat to my, my thesis there? The first thing I did was a ebay analytics tool because it's like, I read Four Hour Work Week and Tim Ferriss told me it'd be easy. And yeah, I went and spent some money. This is like vibe coding in 2006 or whatever. And actually it worked really well like that. That gave me the opportunity to learn principles of virality and network effect and all that kind of stuff. And it was actually working quite well. But then ebay decided that they wanted to do it and they basically killed it overnight. At which point I learned about platform risk and building for acquisition and a bunch of other kind of MBA principles.
Speaker B: And then it really became the Four Hour Work Week.
Speaker A: Yeah, uh, yeah, then it was. Yeah, exactly. So there was that one. And then. Yeah, probably the one that's a precursor or was a precursor to bugcrowd was white label security, which was essentially just white labeled, kind of outsourced penetration testing. So I put together a team of hackers and pen testers out of Argentina and the Philippines and me and my business partner. Partner basically front ended the work that they did locally. And then we white labeled it through organizations in Australia that had the opportunity and the need to sell and deliver that type of thing, but didn't have the resources to get it done.
Speaker B: And this is one of the first big aha, uh-huh moments that you have is that there's these groups of people out and about who have this bespoke expertise. And you've got to find a way to network them in a legitimate way to people that really could use those services. Because we're at this point moving from a world where it's really only elite pen testing firms for hire, hired largely by those who have the money to hire them. We don't yet have this concept of networking the world together to bring the best hackers.
Speaker A: So the world kind of wasn't flat at that point for sure. And that was a part of what I wanted to do was to flatten out access to talent and kind of democratize that. I think another part of it was seeing because you mentioned there was really good pen testing firms around at the time, and there still is. Right. But there's also this kind of larger market in a lot of ways that is basically just someone referred to it as puppy mill pen testing. And it's a little bit harsh. But the idea that you can pay someone a hundred dollars an hour, mark it up to 2,500 and sell it to the street, and then everyone walks away from that happy. This is a zero sum game that we're playing here. If you're talking about discovering a, uh, vulnerability before the adversary does. So if everyone's kind of happy with that margin structure, someone's paying the bill and it's ultimately the user, right? It's like, okay, if our job is to be smarter and to be able to apply creativity, you know, more effectively to the attack surface than the adversary is, then this whole idea of being able to extract like 2000% markup on services, like, that's just clearly that's a market failure. So that was just bugging me. I think the third part was like, really, I grew up during the period where it was scary to be a hacker. There was this sense of camaraderie, I think, amongst the communities at that point in time, because we were all doing this thing that most people saw as being completely illegal. And even if we're trying to do it for reasons that were in good faith or trying to benefit folk, there was still this lingering sense that we could get our door kicked in. So it's like these are three stupid problems for the Internet to have. And it was, that was the thing that was kind of getting me like my favorite definition of a founder is someone who gets irrationally pissed off about a problem that they think they can solve. Right? And that was the irrationally pissed off part because it's like these are just, these are dumb problems for the Internet to have. And like we're getting hosed by the baddies when they want to do bad things. And that's only going to get more and more true as the Internet expands, as threat actors diversify as like da da da da. Uh, so these are all the things that are kind of bouncing around my head before I pulled the trigger on bugcrow.
Speaker B: It is amazing to look back and see that hacking was actually borderline illegal. Now it's obviously a huge market, but if we go back to 2010, we had the concept of bug bounties. Some companies had experimented with paying people to hack you. But what actually made this widespread, uh, market when you founded the company?
Speaker A: I think what made this a, ah, commercial opportunity or made it obvious as a commercial opportunity to me was, you know, I'd been watching, you know, vulnerability reward programs. I'd always been an avid kind of student of vulnerability economics, mostly on the offensive side, but then starting to see that applied into a defensive context. It's like, oh, this is cool. So I started in white label security, actually basically almost creating like a sales incentive for, you know, the folks I had working for me. It's like, okay, we're going to pair you guys up and whoever finds the best issue as judged by me and my, my partner in that business will get a bonus based on that. So like, we're starting to experiment with gamification. Like it worked, it was super effective because people just behave differently when you've got that kind of incentive like in, in play. So yeah, the actual lightning rod moment was, was a trip that I took down to Melbourne from Sydney to, to meet up with a bunch of clients that we had. And, and they all wanted to talk about bug bounty because what had just happened was I think Google or uh, Facebook, one of them was making a bunch of noise about it. And the customers I was meeting up with, they wanted to, they wanted to talk about it. They're like this, this just seems to make sense. So I started prompting the question. It's like, well, okay, if you've got, you know, if you've got like 200 people testing your thing or 20 people even testing your thing and you can pay the same amount of money for that Compared to one person by the hour, like, which do you think you're going to get better results from? It's like, oh, 20. Because math, that just makes total sense. And yeah, so you know, the follow on was like, why aren't you doing it? Like, ostensibly all you got to do is put a website up or put a page up on your website that offers a reward, open an email inbox and like the Internet will respond and off you go. And you, uh, know, they all said the same things. It's like, okay, I'm, I'm scared of hackers. You know, I don't know how to pay someone in Uzbekistan or whatever. You know, my, my team's overloaded as it is. I don't know how I'd listen to the Internet. Like that seems like a hectic thing to do. And yeah, it was a few other things. It was literally on the flight home where it's like, okay, they all said the same things, like, there seems to be early appetite. There's definitely proof of pain in market, there's definitely proof of problem solution fit because that's sort of self evident in the model. But now we're hearing like tech platforms that we look up to talk about it. If we can sort of deal with these objections in terms of actually building a platform to basically handle that and solve that, then all of a sudden we've got the opportunity to not just introduce like I never saw this as introducing bug bounty to the market. I saw it as like basically being in a position to alter the fundamental economics of vulnerability, uh, discovery, like full stop. And almost more as like a future of work thing than just kind of a bug bounty thing as it's talked about these days. So fun end of that story is that I actually registered Bugcrowd.com that day. So I sort of cooked up the name on the fly. This is before there was such intense competition for domain names. Drove home as quickly as I could and registered the Internet. The Twitter handle the domain.
Speaker B: Nice. And then as I recall, you got into an accelerator, you came over to the us you started building the company, but you still had some early fears that maybe this wasn't really going to work. When did it really start taking off?
Speaker A: Yeah, we did early problem solution validation. Like um, yeah, the first part was like, okay, is the community going to actually step up and respond to the call when we put it out there? And they did like we, we did a little like, do you want to hack stuff? Webpage? And I kind of tweeted it and we onboarded like three or 4,000 people.
Speaker B: Oh, amazing.
Speaker A: You know, week or two, which was, okay, that's going to work, that's cool.
Speaker B: You knew the army would be there.
Speaker A: Yeah. The appetite was there, the trust was there. We were kind of ready to go. And there was folk in that, that initial list that was like, what the hell is HD Mo doing here? And like, oh, there's John Cran and like all these folks that were legends to me at that point in time signing up. I'm like, okay, this seems to be working. And then ran, uh, a pilot program and then actually ran a program for a live customer actually before we got accepted into the accelerator. Because that was like, let's just, let's just prove that this thing's going to work at all. Then we got into Start main and off it went from there.
Speaker B: A lot of companies would say, gosh, this is kind of crazy, inviting everybody to hack us and then paying them to do so.
Speaker A: Yep.
Speaker B: So how did you overcome, I guess like the initial obvious objections when you began to push this out commercially and is it easier to attract hackers to this platform or is it easier to attract customers at this point? Take us back in time.
Speaker A: Oh, yeah, no, we were definitely demand constrained for a long time there. Uh, where it's, it's like there's just a lot of people signing up, wanting to do stuff and it's, you know, like looking at the, the effectiveness, thinking about it through the lens of like, how many people do you need to apply to a target in order to get something that they haven't, you know, known before? We called it like the oh crap moment. Right. How do we, how do we kind of measure against that as the, the metric of like the metric point of success in, in what we're doing? There was a lot more hackers than there were, uh, were people on the customer side for, for quite some time there. I still think that's true now. I think the economics of it has shifted a little bit, but.
Speaker B: Yeah, well, walk us through that story. So how, how the economics of bug bounties and what I would call like the open clearinghouse for vulnerabilities, like what are the economics and how does it work? Uh, demystify this for people.
Speaker A: Yeah, sure. So if you're talking about just a pure bug bounty program, really the idea of it is that it's an incentive. I mean the way I describe bug crowd and really what I'm doing is describing bug bounty on that side is to say, yeah, we've got this huge community of hackers but the good kind. So think locksmiths, not burglars, but with the same skill set. Right. And then the platform, what it does is it allows us to put on contests where our customers basically invite all or a part of that community to find vulnerabilities in their systems. And in exchange for that, the people that participate, they get, you know, a reward and social recognition that's proportional to how important the thing they've found is, like, how impactful it is. I think it's different and distinct from a vulnerability disclosure program. Actually, I see it as a subset of a vulnerability disclosure program because what, what a vulnerable disclosure program is is basically acknowledging the fact that, like, if you've got humans writing your code and that code is exposed to the Internet, other people outside your organization are going to find those things and you have zero control over that. Like, that's just a physics issue. So, all right, how do you make sure that, you know, if someone who's helpful happens to find an issue, you know, wants to get that to you, that they're able to do that, that they feel like they're safe in the process, that they understand what the expectations are around what you will do and not do in response to that type of thing. That, to me is a vulnerability disclosure program. And then a bug bounty is when you basically add an incentive for doing that starts to directly encourage the kind of behaviors that you want.
Speaker B: And so when you're sitting down with people who are designing these programs for the first time, I mean, in some way there's no better person than you to ask this question. What do you get right and what do you get wrong with the economics of, uh, bug bounties and vulnerability disclosure? And then I got a similar question for the researcher side, which is what's in it for them? And, you know, how is the game played?
Speaker A: Yeah, I think, I think again, on the bug bounty side, it's really for both sides, actually. It's, it's about treating it like it's a marketplace. Like, one of the questions I love this is like, it's kind of a theoretical question, but you can wrap things around it that make it easier to answer the idea of like, what is a bug worth? Right. And the follow on questions that is, well, to whom? Because the buyer is going to alter, you know, the value. But ultimately, you know, for, uh, customers, like thinking about setting bug pricing, like, they've, they've got to understand that they're competing for the attention of the skills that are needed to get the information that they want. And like, logically, the higher you can push that, the more attention and kind of the higher quality, uh, set of skills you'll be able to kind of reliably attract to your program. But obviously there's limits to that, right? Because you don't want to go broke chasing bugs. That, that's like another risk as well. Like it's not just about doing this right. I think on the researcher side, you know, the whole idea of like, go to the programs that are going to reward you best for the skills that you've got and they're uh, going to acknowledge, you know, your contribution of time, your contribution of data. You know, a lot of that's going to be expressed in the size of the incentive. Like there's other parts of other aspects of it as well, you know, in terms of how responsive a program is, like how, you know, frankly respected the researchers feel when they participate. Because if they're not getting paid unless they're successful, then they're kind of doing work for free until that happens. So like, programs that understand that and operate with that sort of in mind, uh, are the kind of ones that tend to attract more and better kind of talent and bugs.
Speaker B: Well, I was going to say if I look back, you know, you created this concept of, you know, every hacker can sign up and get paid for finding important vulnerabilities across the Internet. And in many ways you can look back and be very proud of that. If you go back in the movie, what were some of the things that you're most proud of? And then also what were some of the obstacles that have gotten in the way or some of the unsolved problems?
Speaker A: I think, you know, just seeing the hacker community kind of reveal itself as a strategic asset and like a force of good, like all the different things that kind of helped that along the way to me, uh, are the high points, you know, the uh, hack the Pentagon program, like that was I think, a real turning point in the market's awareness of this as a potential solution. And the fact that it sort of vindicated hackers at that point in time because it's like if the apex predator of the planet is relying on a 16 year old kid, then maybe that's something I should think about as well. That was neat. And being involved in that was awesome. Continuing to be involved in that as well. One of the first bounty programs that we ran was actually an experiment in terms of charity bounties. So the idea of like, can we, you know, get people to do work for free or like create some Sort of point system to incentivize them. You know, if we're working with 501C3s or charities that don't have the ability to pay. And that was just a random opportunity that came in, but we figured we'd try it out. And it was actually an organization that basically raised money to combat sex trafficking in Southeast Asia. And once the people that were invited to that program got the invite and kind of understood, you know, what this was for, once we opened it up, like, we literally knocked them off the Internet for, like, a day or two because of the response, right? Like, there was so much interest in trying to help these folk out that we actually took them offline. So the fact that we took them offline wasn't a good thing. And we learned how to not do that, if that makes sense. But the thing to me that was really cool and kind of heartwarming about that was like, just, you know, these folk that do incredibly valuable work, basically showing up for free to support, like, a really important cause. So, like, that's another one. Getting messages from, like, people in all sorts of parts of the world these days. Like, oh, yeah, I've just. I've just, you know, bought my mum a house or I just bought my first car or, you know, this has completely changed my life.
Speaker B: That is really the best part of the story, right? It's like just how many people could make, you know, yeah, Bug bounties a career. And it really did Change their career.
Speaker A: 100. Seeing the consistency of that and just. Just the gratitude, do you know what I mean? Because it's like the other side of that is getting, you know, messages. There's a golden one from someone that we, like, I first met when we invited him to an automotive security program, like a live hacking event back in, like, 2016, I want to say. And, you know, he's young punk, got in there, did his thing, like, super talented, all that other stuff that actually formed a crew that, that hacks hardware that is still together today, which is amazing.
Speaker B: That's amazing.
Speaker A: Yeah. But the other part was, like, literally, I think it was maybe two years ago, he reached out just completely out of the blue and said, hey, yeah, I just wanted to say thank you for. For inviting me to that thing. Like, the bit that you probably didn't know is that, like, I come from, uh, a crime family and, yeah, I would have become a car thief, because that's just what you get taught to do, you know, where I'm. Where I'm from. And this is like, diverted you know, this has created an opportunity for me to not go to jail basically and actually work in automotive security and do all these sorts of cool things.
Speaker B: Oh man, that's an amazing story.
Speaker A: That was, that was just super cool to hear. That doesn't happen every day, but it does every now and then. And it's, it's always, you know, wonderful to get kind of hero stories like that.
Speaker B: Uh, well, I have heard you use the term criminal creativity when you think about like what it takes to really like unlock the genius of a hacker.
Speaker A: Yeah, I mean, look, I think it's partly like growing up on an island that was kind of populated in terms of, you know, my culture there by a bunch of convicts that got kicked out for stealing stuff. So like there's, there's definitely an anti establishment bent that you just kind of learn as a, as an Aussie. I think I do think of criminal creativity. Just the idea of like this is entrepreneurship and invention, like without rules. Right. So like, I don't like the part of that that harms people and I don't necessarily like the part of that that's breaking the law or whatever else. But the idea of like the creative options that it sort of opens up for someone if they just sort of throw the rules out the window for a second and think about what they want a thing to do, if they can sufficiently like, master, it'll have a version of that, that, that we, you know, ultimately as defenders have to compete with. So, uh, to me, that's like one of the richest sources of the things that we're going to need to be thinking about next. From like a vulnerability standpoint that's turned out to be pretty accurate. Like that's a, that's a thesis I kind of developed like early 2000s, honestly. But it's, it's something that's been kind of a guiding principle in terms of how I think about just how to fix the problem.
Speaker B: Yeah, no, man. Bug bounties and vulnerability disclosure is now pretty much table stakes for everybody. It's hard to imagine a big company that doesn't have some form of bug bounty and VDP at this point. So congratulations on that. When you think about the evolution of the space, in some ways, in my mind, this really should be everywhere, right? We should have way more people hacking, we should have way more money flowing through the system. There should just be way more awareness as to the power of the crowd. What are some of the things that you think are still getting in the way of this? Having the broad based adoption that we all know it should. And then what's been your vision for how this space evolves over time?
Speaker A: Yeah, that's a great question. I think in terms of things that get in the way, I do feel like the category itself probably could have got more done had we not been as competitive with each other. And, and like that's, that's like everyone who's participated because there was this, this kind of early phase where we're, you know, we're all pretty focused on just convincing the market that we weren't insane and that hackers were okay. Right. But then, you know, once, once that kind of horse left the stable, it got very competitive very quickly. And I do think that was somewhat of a distraction from kind of solving the bigger mission, uh, of normalization and just making this being a table stakes part of how people do what they do. And I can't be too mad at that because we participated in that. Right. And capitalism is going to capitalism, so that's fine too. But yeah, the amount of confusion, I think that exists around what is the difference between a vulnerability disclosure and a bug bounty program. Because personally I actually don't believe that every organization should run a public bug bounty program. I don't think that everyone's ready for that. I do think that everyone needs to have a vulnerability disclosure program, which is a big part of a lot of what I've done on the policy side. Just because this is how the Internet works, you don't get a choice. You don't get to walk outside and scream at the thunderstorm and ask it not to hit your house with lightning. That's not how this works. So the thing that's sensible is you, you put a lightning rod up and you know, anticipate the fact that there's going to be an issue. And when that happens, you're routing what could cause damage around where it will cause damage and getting it to a place where you can deal with it. So like, that's a fun physics weather analogy that I kind of often throw in to try to explain that. So yeah, it's, you know, there's definitely just term confusion in the market. You know, to be honest, I do think that everyone can benefit from private crowdsourcing and multi sourcing as well. But you know, then folk get confused between that and a public bug bounty, which they're not sure that they want to run, so on, so forth. So there's a few things that sort of go into that and I think we've all tried to work out how to sell and market and develop product past that. But I do still think it's kind of holding us back.
Speaker B: I usually invite guests on the show if they've had an exit for their company or have had some other life changing event that they want to share back with other founders. In your case, you haven't exited your company but you did have to shift gears after having quite a serious health incident that uh, we've talked about and also you recently wrote about. This is a really important life changing event for any founder. Would you mind taking everyone through exactly what happened?
Speaker A: Yeah, basically, I mean first things first, like heart issues do run in my family. So I had been like keeping an eye on this and getting checked up and all those different things and it got to the point where this is not going to be a problem because I'm older than when the kind of issues that I'm prone to would normally present. So great. All right, onto the next thing and we're good to go. But basically what happened was I'm trying to think of the time frame here, midway through 23, I want to say I just felt my health start to decline and it was weird because it wasn't anything kind of dramatic. It was just feeling kind of older, quote unquote. And you know, I just kind of pushed through it, you know, still working hard on the bug crowd stuff and you know, thinking about what I'm going to build and blah blah, blah, all these different things. But yeah, really kind of not paying attention to what in hindsight were a bunch of warning signs that my, my heart was actually starting to fail. So that was sort of what was going on. I started getting like a really fast rhythm that had sort of pop up every now and then. You know, talk to doctors about it, they never caught it in the act so they just assumed that it was like a panic attack or stress or work related or whatever. It's like, oh, you do, you do hectic, high stress stuff. So it's probably just that which I, you know, listen to. It's like, all right, well I just need to kind of adjust lifestyle, think about getting older or whatever else and not actually digging in and re asking the question to actually figure out, you know, if there was something kind of deeper in play.
Speaker B: Well and you're in a startup so obviously you, you always feel like this comes second. Right? It's like startup comes first. And um, yeah, solving these problems come
Speaker A: second and there is a degree of physical sacrifice involved. Right. So there's, it's like I think, you know, the idea of like burning the candle at both ends. I don't necessarily see anything wrong with that as long as you're not. If you've got adrenaline as like a diet, like, that's bad. But, you know, it's. It's a thing that you have to use every now and then. So this, you know, kind of hustle and grind aspect of it. Yeah, it just really wasn't balancing that out right. Against, like, proactive preventative health, I think is really kind of the net. Net there. Ah. But yeah, I was in. In Australia on vacation, and it happens like one of these arrhythmias happens while I was driving the car. And it was actually the first time my wife had seen. Seen it. And, you know, they were pretty dramatic. Like, I was pushing, you know, upper hundreds and holding it there for. For an hour or two, which is tiring. Like, anyone who's had this kind of condition would understand what that's like. It doesn't feel like you. You're dying or any of that kind of stuff. It just feels like you've got a fast heartbeat. You can't kind of really do much else while that's happening. So pulled over, we ended up deciding to drive to the hospital. They caught it in the act and they're like, oh, whoa, hang on. This is not like a panic attack. This is actually a thing called super ventricular tachycardia, which is basically, uh, a wiring issue that suggests that there's a structural problem with the heart. And, yeah, it kind of went from there. But, you know, we figured out pretty quickly that, like, it wasn't just a matter of like a, you know, ablation on a damaged thing on the outside of the heart, which is usually how you solve svt. It was actually that my mitral valve, which is kind of one of the main valves in the heart, had basically completely failed. So my heart was operating at 21% capacity, and it was enlarging as a. As a result of that, which is something that the heart's really good at, is actually compensating for stuff like this. But because I'd let it do that for so long, it was now causing these secondary issues. And yeah, basically, you know, though, doctors were basically saying, like, you need to have surgery now because if it expands anymore, you're going to reach the point of no return and you're actually at risk of cardiac arrest. So, yeah, it was a fun time.
Speaker B: I know online you showed everyone that you have a huge scar on your chest from open heart surgery, which obviously has a really Long recovery time. We're all very grateful that you're healthy and back in the game. I think my question though is founders just don't usually prioritize health. Looking back, is there some message you could send to yourself or to others that would somehow make this a priority?
Speaker A: Look, I think self care is just really underrated and a big part of what prompted that sort of follow up post, you know, part of it was just to let people know kind of what, what happens if they hadn't already heard about it. Because I did post at the time, just before I had the surgery. And you got a, just a wonderful response to that. But that was partly because it's like, I don't know what's going to happen now. Like this is, this is sort of life or death stuff and you know, feel very blessed and very fortunate to have come out the other side to begin with, to be honest. But yeah, so you're posting it, uh, was really in response to the fact that like a lot of people, particularly in the founding role, um, and a lot of people in cyber security as well, kind of reached out and said hey, like I've been sort of worried about, you know, my risk factors for this type of thing, but I just haven't really gone off and looked at it because I'm sort of scared of what I'll find. And it's particularly like there's a lot of blokes in particular, kind of came back with that particular question or answer off the, off the back of it. So that was what prompted me to write the follow up. It's like, okay, here's some of the lessons learned, here's some of the things that I would do differently, like integrating management of your health and self care and all the things that we talked about with having a support network and community around you and all those different things, integrating that with like doing extraordinary stuff that moves at a million miles an hour. Just a thing that I just didn't do very well for a period of time there. And I think like being open about that and saying, hey, this is a thing that happens and this is a thing that a lot of folk have come up and asked about subsequently. Like this is me saying it's important, like don't ignore, don't ignore that because really in, in reality, like I did and got me pretty close to punching my clock like twice last year.
Speaker B: So you mentioned the word balance. And I think this is a very polarizing world in the land of founding companies because I feel like everybody, when they look back Says man could have had more balance. And in the moment, in the war, I think everyone realizes that there's just a lot of trade offs being made. So what is the cheat code? Is there one like is there some massive breakthrough that you've had now where like the version of yourself now can look back and say this is what it takes to have balance or help people that are going through this right now?
Speaker A: Yeah, I uh, mean honestly I would say like uh, the cheat code, you know, my cheat code was basically don't ignore like proactive preventative health maintenance. Especially if you've been doing this for a while, especially if you're over 40. And I think some people that have chimed in and say yeah, no, actually over 35 is probably good too. So it's, you know, uh, I think your 20 somethings that are out there doing the founding thing, like they should be thinking about this too, but they're probably thinking about different like elements of self care that come into it. I shouldn't have stopped getting checked is really what it comes down to. And that's just a function of being, you know, someone who's high performing, who works their ass off, who tries to like, you know, keep myself healthy and all those different things, but can tend to balk at preventative maintenance if it's a thing that's going to be inconvenient or just gets in the way or I don't feel like I need to make the time for it. It's like, no, make the time is really the net net.
Speaker B: Kasey, hearing this story, I've been meaning to ask you a question. Is part of your life story a metaphor for how software is built? Early on we have to run hard, we've got to ship things quickly, but eventually we have to take on the technical debt and fix all the points of vulnerability.
Speaker A: Yeah, I think that's absolutely right. Basically transparency is anti fragile. So secrecy or the equivalent of that I think in a lot of ways on the health side, ignorance or just denial. Right, yeah, that'll work. But when it fails, it'll more likely than not fail catastrophically because you've got debt that that's built up on top of it.
Speaker B: Right.
Speaker A: Whereas like transparency is, is just inherently antifragile. I think this is sort of an extension of that same idea.
Speaker B: No, absolutely. And then you know, in some ways only when you've been attacked and hacked and breached and you have that ransomware incident, do you suddenly realize how important this all is.
Speaker A: Yeah.
Speaker B: But until then, everything feels like everything else is a priority, you can just
Speaker A: put it off and do it later.
Speaker B: And since you advise a lot of founders, and a lot of founders come to you for advice.
Speaker A: Yeah.
Speaker B: What advice do you have for founders today who are starting a company?
Speaker A: I mean, the big one would be just do it, like, get in. Get in the game. There's no perfect time, like, waiting for the right conditions and for everything to line up perfectly. It's never going to be like that. So especially in security, you know, if it fails, you can just go back and get a job that you don't like for. For a period and kind of regroup and, you know, keep the lights on in the process. So, like, just understanding that the risk that you're taking is. It's a big one, but it's not fatal in that sense. So I think just go like, uh, that's a lot of the encouragement that I, That I give to people, you know, if their first time is.
Speaker B: And just to come full circle, now that you've turned hacking into not just a profession for yourself, but also a profession for over a million other hackers, do you think your parents are finally proud?
Speaker A: Yes. Yeah, they're super proud. They dig into all the press releases and the hacker stories and all those different things. They're super proud of that, which is cool. But, yeah, the other piece of advice of founders is just literally have grace for yourselves. This is going to be a ride, and that's okay. It's actually kind of meant to be a ride. We're creating order from, you know, chaos and, and like, deriving value from that. That's literally the job that we take on as a founder. So the fact that things get kind of weird sometimes, that shouldn't be a shock. But if you're not prepared for it, it might be. So just, you know, be ready for that. And if you're. You're still wanting to take it on, then you're probably exactly the right person for the job.
Speaker B: Amen. And on that point, let's wrap this up. Uh, Casey, you've been an amazing, uh, guest. So happy to have you on the show, and I really, really appreciate you being here.
Speaker A: Thanks, John. I enjoyed the conversation.
Other episodes covering the same guests and topics, from across The B2B Podcast Index.