Customer Story

How a global equipment manufacturer reduced exploitable risk across a fast-growing digital footprint

A global equipment manufacturer running VDP and private bug bounty on the H1 Platform has resolved 2,500+ valid vulnerabilities, grown its researcher community from under 100 to hundreds, and cut phishing detection response time to under 20 minutes, while scaling security across mobile, web, and connected equipment.

Global leader in agricultural and construction equipment
Industry
Manufacturing
Use Cases
Exposure Management, Offensive Security, CTEM
Solutions
H1 Bounty, Hai, H1 Response, H1 Platform
Regions
North America
Smooth gradient background transitioning from deep navy blue on the left to bright cyan and magenta on the right
The Challenge

Trust at scale amid growing attack surfaces

The digital evolution of the company’s products and services introduced new cybersecurity challenges, from expanding attack surfaces to managing increasingly complex data environments. 

To scale their efforts, the security team needed a way to bring trusted external researchers into their process, reduce the time to identify and resolve vulnerabilities, and build a scalable culture of security across product teams.

External expertise at scale

Bring trusted researchers into the process to expand coverage across a fast-growing digital footprint.

Faster discovery to fix

Reduce time to identify and remediate vulnerabilities so risks are closed before they’re exploited.

Security culture, everywhere

Embed consistent, scalable security practices across product teams without slowing delivery.

 

The Goal

A mature VDP + bug bounty, accelerated by AI for faster risk reduction

Build a continuous, scalable layer of external security testing to keep pace with a rapidly expanding digital ecosystem. Engage trusted researchers to find and fix issues faster, strengthen product and data security, and reinforce customer trust.

The Solution

Their program on HackerOne

The company introduced its VDP in 2020 and expanded to a private bug bounty with HackerOne in 2022. Since launch, the VDP has resolved 225 reports, thanked 162 researchers, and added 1,720 assets to scope. Today, both programs operate in tandem to proactively identify and remediate vulnerabilities across their digital ecosystem.

Researchers are empowered to test across the company’s full product portfolio, including mobile apps, web assets, and connected equipment. In return, the team provides clear scopes, prompt feedback, and respectful collaboration.

“Their bug bounty program is world-class,” said Archangel, a top HackerOne researcher. “They value our input and care about security across their entire ecosystem.”

The company also uses the H1 Platform's agentic capabilities to streamline communication and speed up decision-making. The team uses it to summarize reports, write more professional messages to researchers, suggest severity levels, and justify bounty amounts based on real context rather than static scores. The H1 Platform's agentic layer helps the team respond faster and more confidently in day-to-day workflows.

A platform that grows with the program
The company runs both H1 Response (VDP) and H1 Bounty through the H1 Platform, giving the security team a unified view across disclosure and bug bounty workflows. The H1 Platform's agentic capabilities support triage and researcher communication across both programs, reducing the manual overhead of managing a high-volume, multi-program operation. As the company continues to expand scope and researcher access, the platform scales with it.

The Impact

From insight to outcomes

By integrating insights from HackerOne researchers into its Security by Design program, the company is also upskilling internal teams and shifting security left in the development lifecycle. They use benchmarks to track progress against industry peers, helping identify areas for improvement and reinforcing executive confidence in the program’s impact.

Across both programs, the H1 Platform operationalizes the full find-to-fix loop: researchers surface vulnerabilities, agentic capabilities accelerate triage and prioritization, and the team closes risk before it reaches production.

  • 2,500+ valid vulnerability submissions
  • Grown from fewer than 100 to hundreds of vetted security researchers
  • <20-minute response time for phishing detection with AI-powered tools
Looking Ahead

From strong to stronger: what’s next

The company is continuing to mature its VDP and is exploring the expansion of bounty offerings. They also remain focused on scaling secure development practices, supporting early-career talent, and leveraging automations and AI to accelerate threat detection and response.

The partnership with HackerOne