Skip to content
← all posts
Security

Why Security Teams Gaslight Hackers: Disclosure Reality

The cybersecurity industry has a dirty secret: security teams are systematically dismissing legitimate vulnerability reports from ethical hackers. In a recent episode of Hackers on the Rocks, Bugcrowd founder Casey Ellis and security researcher Caleb Lerch exposed the uncomfortable reality of how organizational friction kills valid security findings before they ever reach engineering teams.

The "It's Fine" Problem

When researchers find actual security bypasses and report them through proper channels, they often face dismissive responses like "it's fine, don't worry about it" - with no technical discussion or deeper investigation. This organizational dismissal pattern persists even in 2026, showing how internal communication chains protect company reputation over actual security.

Caleb shared a firsthand account of discovering a security solution bypass and reporting it directly to the vendor through existing business relationships. Despite having connections to salespeople and customer support, the issue was "run up the internal chains" without him in the loop. The response? A dismissive "it's fine, don't worry about it" with no technical engagement.

Why Crowdsourced Security Revealed the Scale

Casey Ellis founded Bugcrowd by recognizing that talented researchers like Caleb are discovering vulnerabilities everywhere. The challenge isn't finding researchers - it's companies actually listening to them. Bug bounty economics reshaped disclosure but didn't solve organizational resistance to external security input.

"There's all of these different folk out there like Caleb that have the ability to discover vulnerabilities," Ellis explained. The crowdsourced security model he created revealed the massive pool of talent available, but also exposed how companies struggle to handle external security input at scale.

Watch on YouTube
Click to watch: Security Teams Are Gaslighting Hackers - Hackers On The Rocks Podcast

The Communication Chain Breakdown

Personal connections don't guarantee proper escalation. Issues get "run up internal chains" without researcher involvement, critical context gets lost between departments, and sales/support people become gatekeepers to actual security teams. Researchers are excluded from technical discussions about their own findings.

This breakdown happens because:

  • Security findings threaten established company narratives
  • Internal teams lack processes for handling external research
  • Middle management filters findings to protect executives from "problems"
  • Technical teams never receive the actual vulnerability details
  • Researchers lose agency in the disclosure process

Breaking the Gaslighting Cycle

The pattern is clear: companies accept the economic benefits of bug bounty programs while maintaining organizational structures that resist the findings. This creates a form of institutional gaslighting where researchers' valid concerns are systematically dismissed as "not real problems."

Effective vulnerability disclosure requires more than just publishing a security.txt file or launching a bug bounty program. It demands organizational commitment to:

  • Direct technical engagement with researchers
  • Transparent escalation processes
  • Regular feedback loops with the security community
  • Recognition that external researchers often understand attacks better than internal teams

The Cost of Dismissal

When security teams gaslight researchers, they don't just damage individual relationships - they undermine the entire ecosystem of responsible disclosure. Talented researchers like Caleb will find vulnerabilities regardless of whether companies want to hear about them. The question is whether those findings will be shared responsibly or disclosed publicly when organizations prove unwilling to engage.


This post is based on insights from the Hackers on the Rocks podcast episode "Security Teams Are Gaslighting Hackers (Vulnerability Disclosure)" featuring Casey Ellis, founder and CEO of Bugcrowd, and Caleb Lerch, application security specialist at Digital Boundary Group.

Casey Ellis
Casey Ellis
Hacker, founder, advisor, and pioneer of crowdsourced security. Founder of Bugcrowd, co-founder of disclose.io, principal of Tall Poppy Group. Board member at SRLDF.
bio →

Comments ·

members only