Ethical hackers in the bug bounty section of Gisec Global 2022 at the Dubai World Trade Centre. Antonie Robertson / The National
Ethical hackers in the bug bounty section of Gisec Global 2022 at the Dubai World Trade Centre. Antonie Robertson / The National
Ethical hackers in the bug bounty section of Gisec Global 2022 at the Dubai World Trade Centre. Antonie Robertson / The National
Ethical hackers in the bug bounty section of Gisec Global 2022 at the Dubai World Trade Centre. Antonie Robertson / The National

Gisec 2022: du plans to offer 'bug bounty' as a service to its customers


Alvin R Cabral
  • English
  • Arabic

Emirates Integrated Telecommunications Company, known as du, is planning to offer a bug bounty as a service to its customers following the success of its trial programme.

A bug bounty is a reward given to ethical hackers who are able to discover and report a vulnerability – a bug – in a computer app or software, enabling solutions to be programmed before the bug becomes widespread.

The pilot phase of du's bug bounty programme, which was completed in two months and included the participation of several “elite security people”, allowed the telecom company to explore vulnerabilities before the services go to market, said Jasim Al Awadi, head of government and key accounts at du.

“We have concluded our bug bounty programme and the results are phenomenal. Very soon we will start implementing it in our network. We will have an on-premises server, then we will offer it as a service to our customers,” Mr Al Awadi told The National in an interview at the Global Information Security Expo and Conference in Dubai.

The UAE National Cybersecurity Council launched the bug bounty programme in August 2020 with the goal of strengthening the country's cyber security systems.

Du, along with e& — then known as Etisalat Group — and the Telecommunications and Digital Government Regulatory Authority, were among the first to trial it.

Abu Dhabi-based telecom operator e& – which rebranded last month – completed the first bug bounty programme in October during Gitex Technology Week.

The two-month pilot was conducted in collaboration with Yogosha, a Paris-based crowdsourced bug bounty platform, and Abu Dhabi-based defence consulting firm Beacon Red.

The global bug bounty market was valued at $223.1 million in 2020 and is projected to hit almost $5.5 billion by 2027, growing at a compound annual rate of 54.4 per cent from 2017-2027, according to California-based data provider All The Research.

_____________________

Gisec day two - in pictures

  • Visitors on the second day of Gisec 2022, at Dubai World Trade Centre. All photos by Antonie Robertson/The National
    Visitors on the second day of Gisec 2022, at Dubai World Trade Centre. All photos by Antonie Robertson/The National
  • The Gulf Information Security Expo and Conference runs until March 23 in Dubai.
    The Gulf Information Security Expo and Conference runs until March 23 in Dubai.
  • People discuss at a stand at Gisec.
    People discuss at a stand at Gisec.
  • This year's event has been a key platform for international dialogue on increasingly sophisticated cyber crimes and warfare.
    This year's event has been a key platform for international dialogue on increasingly sophisticated cyber crimes and warfare.
  • Huawei and Microsoft are among the companies present.
    Huawei and Microsoft are among the companies present.
  • Delegates have been learning how international law enforcement agencies are working to fight cyber criminals.
    Delegates have been learning how international law enforcement agencies are working to fight cyber criminals.
  • The role of digital technologies amid the pandemic and a global shift online is another area of focus.
    The role of digital technologies amid the pandemic and a global shift online is another area of focus.
  • Ethical hacker Jayson Street speaks during the second day of Gisec.
    Ethical hacker Jayson Street speaks during the second day of Gisec.
  • A demonstration of the latest technology.
    A demonstration of the latest technology.
  • A visitor walks past the Armis Security stand.
    A visitor walks past the Armis Security stand.
  • The global cyber security industry needs to fill 2.5-million jobs, experts have said at this year's Gisec.
    The global cyber security industry needs to fill 2.5-million jobs, experts have said at this year's Gisec.
  • Delegates on the second day of Gisec.
    Delegates on the second day of Gisec.
  • Gisec is being organised in partnership with the UAE’s most influential cyber bodies.
    Gisec is being organised in partnership with the UAE’s most influential cyber bodies.

_____________________

By industry, internet and online services is the most served category with almost a quarter of market share, followed by computer software (16 per cent), financial services and insurance (8 per cent), media and entertainment (7 per cent) and cryptocurrency and blockchain (4 per cent), according to data from Statista.

Regionally, North America has the largest share of the market at almost 50 per cent, followed by Europe and Asia-Pacific each, with about 20 per cent. Latin America, and the Middle East and Africa account for roughly 3 per cent each, All The Research said.

Companies, most notably in Big Tech, have recruited the hacker community to assist them in this endeavour.

Google, the world's biggest internet company, handed out a record $8.7m in bounty payouts in 2021, with the biggest a $157,000 reward for a security issue found within its Android mobile operating system.

In 11 years, the company made almost $38m in payouts.

Apple's Security Bounty programme, meanwhile, is more lucrative. Successful hunters can earn as much as $1m, and the iPhone maker will even match donations of the bounty payment to qualifying charities, according to its website.

Mr Al Jasim did not provide details of du's bug bounty rewards scheme, but said the efforts of their participants have been well recognised.

Previously, about 10 to 15 years back, cyber security was a luxury item to have, but now it’s now a necessity
Jasim Al Awadi,
head of government and key accounts at du

“For the bounty programme, we are part of the community and we are engaging by rewarding them based on the agreement between us and Yogosha,” he said.

The bug bounty programme is part of the wider efforts of the UAE’s wider efforts to strengthen its cyber defences at a time of an increased threat, Mr Al Jasim said.

Du, he said, continues to invest “billions” on an annual basis on its telecom infrastructure, with security “having a good chunk of that".

“We are investing in engineers, people and processes to build all of these defence mechanisms to protect the nation and the people living in it,” he said.

“About 10 to 15 years back, cyber security was a luxury item to have, but now it’s now a necessity. Cyber security is [part of our] DNA – it is something that we need to live with on a daily basis.”

Jasim Al Awadi, head of government and key accounts at du. Photo: EITC
Jasim Al Awadi, head of government and key accounts at du. Photo: EITC
Dengue%20fever%20symptoms
%3Cp%3EHigh%20fever%20(40%C2%B0C%2F104%C2%B0F)%3Cbr%3ESevere%20headache%3Cbr%3EPain%20behind%20the%20eyes%3Cbr%3EMuscle%20and%20joint%20pains%3Cbr%3ENausea%3Cbr%3EVomiting%3Cbr%3ESwollen%20glands%3Cbr%3ERash%26nbsp%3B%3C%2Fp%3E%0A
Other workplace saving schemes
  • The UAE government announced a retirement savings plan for private and free zone sector employees in 2023.
  • Dubai’s savings retirement scheme for foreign employees working in the emirate’s government and public sector came into effect in 2022.
  • National Bonds unveiled a Golden Pension Scheme in 2022 to help private-sector foreign employees with their financial planning.
  • In April 2021, Hayah Insurance unveiled a workplace savings plan to help UAE employees save for their retirement.
  • Lunate, an Abu Dhabi-based investment manager, has launched a fund that will allow UAE private companies to offer employees investment returns on end-of-service benefits.
The specs

Engine: 3.8-litre twin-turbo flat-six

Power: 650hp at 6,750rpm

Torque: 800Nm from 2,500-4,000rpm

Transmission: 8-speed dual-clutch auto

Fuel consumption: 11.12L/100km

Price: From Dh796,600

On sale: now

The%20Secret%20Kingdom%20
%3Cp%3E%3Cstrong%3EDirector%3A%3C%2Fstrong%3E%20Matt%20Drummond%3C%2Fp%3E%0A%3Cp%3E%3Cstrong%3EStars%3A%20%3C%2Fstrong%3EAlyla%20Browne%2C%20Alice%20Parkinson%2C%20Sam%20Everingham%3C%2Fp%3E%0A%3Cp%3E%3Cstrong%3ERating%3A%3C%2Fstrong%3E%203%2F5%26nbsp%3B%3C%2Fp%3E%0A
THE SPECS

Engine: 6.75-litre twin-turbocharged V12 petrol engine 

Power: 420kW

Torque: 780Nm

Transmission: 8-speed automatic

Price: From Dh1,350,000

On sale: Available for preorder now

SPECS
%3Cp%3E%3Cstrong%3EEngine%3A%3C%2Fstrong%3E%20Dual%20electric%20motors%20with%20102kW%20battery%20pack%3C%2Fp%3E%0A%3Cp%3E%3Cstrong%3EPower%3A%20%3C%2Fstrong%3E570hp%3C%2Fp%3E%0A%3Cp%3E%3Cstrong%3ETorque%3A%3C%2Fstrong%3E%20890Nm%3C%2Fp%3E%0A%3Cp%3E%3Cstrong%3ERange%3A%3C%2Fstrong%3E%20Up%20to%20428km%3C%2Fp%3E%0A%3Cp%3E%3Cstrong%3EOn%20sale%3A%3C%2Fstrong%3E%20Now%3C%2Fp%3E%0A%3Cp%3E%3Cstrong%3EPrice%3A%20%3C%2Fstrong%3EFrom%20Dh1%2C700%2C000%3C%2Fp%3E%0A
Winners

Ballon d’Or (Men’s)
Ousmane Dembélé (Paris Saint-Germain / France)

Ballon d’Or Féminin (Women’s)
Aitana Bonmatí (Barcelona / Spain)

Kopa Trophy (Best player under 21 – Men’s)
Lamine Yamal (Barcelona / Spain)

Best Young Women’s Player
Vicky López (Barcelona / Spain)

Yashin Trophy (Best Goalkeeper – Men’s)
Gianluigi Donnarumma (Paris Saint-Germain and Manchester City / Italy)

Best Women’s Goalkeeper
Hannah Hampton (England / Aston Villa and Chelsea)

Men’s Coach of the Year
Luis Enrique (Paris Saint-Germain)

Women’s Coach of the Year
Sarina Wiegman (England)

The specs

Engine: 3.9-litre twin-turbo V8
Power: 620hp from 5,750-7,500rpm
Torque: 760Nm from 3,000-5,750rpm
Transmission: Eight-speed dual-clutch auto
On sale: Now
Price: From Dh1.05 million ($286,000)

Updated: May 29, 2023, 12:45 PM