Key Findings
98% of professional pen testers prefer the PTaaS model over bug bounties.
30% of all bug bounty submissions are invalid or low-value "noise."
15% of professional pentesters rank public bug bounties as the most effective model for uncovering complex vulnerabilities.
1% of professional pentesters believe AI-only scanning is effective for uncovering high-impact, exploitable vulnerabilities.
58% of professional pentesters rank PTaaS as the most effective model for uncovering complex vulnerabilities.
54% of professional pentesters report having discovered a Zero-Day or N-Day vulnerability that had no existing public patch or advisory.
51% of professional pentesters cite the pressure to be the first to submit a finding as their primary frustration with bug bounty programs.