<?xml version="1.0" encoding="utf-8"?>
<?xml-stylesheet type="text/xsl" href="../../assets/xml/rss.xsl" media="all"?><rss version="2.0" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:atom="http://www.w3.org/2005/Atom"><channel><title>Pentagrid AG (Posts about Swiss Cyber Storm)</title><link>https://www.pentagrid.ch/</link><description></description><atom:link href="https://www.pentagrid.ch/en/categories/swiss-cyber-storm.xml" rel="self" type="application/rss+xml"></atom:link><language>en</language><copyright>Contents © 2026 Pentagrid AG </copyright><lastBuildDate>Wed, 17 Jun 2026 19:14:55 GMT</lastBuildDate><generator>Nikola (getnikola.com)</generator><docs>http://blogs.law.harvard.edu/tech/rss</docs><item><title>Interview on the “SCS in a nutshell” channel about penetration testing versus bug bounty programs</title><link>https://www.pentagrid.ch/en/blog/interview-about-penetration-testing-vs-bug-bounty-programs/</link><dc:creator>Pentagrid AG</dc:creator><description>&lt;figure&gt;&lt;img src="https://www.pentagrid.ch/images/default_preview_image.jpeg"&gt;&lt;/figure&gt; &lt;p&gt;Swiss Cyber Storm and their host Christian Folini invited freelancing Bug Bounty
hunter Raphaël Arrouas and Pentagrid’s IT security analyst Tobias Ospelt to an
interview in the „SCS in a nutshell” format about the pro and cons of
penetration testing and bug bounty programs. While both approaches are valid
methods to find security vulnerabilities, they also differ in many aspects.&lt;/p&gt;
&lt;!-- TEASER_END --&gt;
&lt;p&gt;The interview began with a discussion about the trust in the maturity level of
the Bug Bounty program owner’s security and the necessary trust in people
knowing about an organisation’s vulnerabilities. The interview continues with
the flexibility on defining rules and scopes, the freedom of picking a scope
and about private bug bounty programs, a new format with increasing prominence.
The pros and cons of the different economic twists, where a company rewards
only identified vulnerabilities versus paying for work time are discussed as
well as the visibility and significance of pentest and bug bounty results and
their internal processing within a company.&lt;/p&gt;
&lt;p&gt;In the conversation, the security researchers’ risk to violate the hacker
paragraphs StGB 143 and 144 in Swiss law is also highlighted, because the law disregards
researchers and bug bounty hunters acting in good faith.&lt;/p&gt;
&lt;p&gt;The whole interview discussing additional topics runs for about 45 minutes and
is available via the &lt;a class="reference external" href="https://youtu.be/pTCljaQVlTU"&gt;Swiss Cyber Storm Youtube channel&lt;/a&gt;.&lt;/p&gt;</description><category>Bug Bounty</category><category>Pentesting</category><category>Swiss Cyber Storm</category><guid>https://www.pentagrid.ch/en/blog/interview-about-penetration-testing-vs-bug-bounty-programs/</guid><pubDate>Tue, 02 Mar 2021 06:00:00 GMT</pubDate></item></channel></rss>