Customer Story

How Helvetia replaced point-in-time testing with continuous security across five countries

Cybersecurity has become a vital part of Helvetia’s strategy to protect both its operations and the trust of its customers.

Industry
Financial Services
Use Cases
Exposure Management, Offensive Security, CTEM
Solutions
H1 Bounty, Hai, H1 Bounty Challenge, H1 Platform
Regions
Europe
Smooth gradient background transitioning from deep navy blue on the left to bright cyan and magenta on the right
The Challenge

Limitations of a traditional model

Helvetia Group is one of Switzerland’s leading insurance companies, offering a broad range of insurance and pension solutions in Germany, Austria, Spain, Italy, and France. Cybersecurity has become a vital part of Helvetia’s strategy to protect both its operations and the trust of its customers.

As cyber threats become more sophisticated and the attack surface expands, Helvetia recognized the need for a proactive, scalable approach to vulnerability management. That’s when they turned to HackerOne.

Before HackerOne, Helvetia relied on traditional penetration testing and internal security processes to identify vulnerabilities. While these methods were useful, they had limitations:

Non-continuous testing

Testing occurred at fixed intervals, often leaving long gaps between assessments

Restricted scope

The scope was restricted, meaning some assets weren’t regularly tested

A growing ecosystem

Scaling security efforts across a growing digital ecosystem was increasingly difficult

Slow response

Manual workflows slowed down response times

The Goal

A proactive, scalable approach to vulnerability management

The Solution

Helvetia's program on HackerOne

Helvetia runs both H1 Bounty and time-bound challenge engagements through the H1 Platform, giving the security team continuous researcher coverage alongside focused, high-intensity testing during product launches and peak-risk periods. The H1 Platform's agentic validation capabilities handle report credibility scoring, severity assessment, and triage prioritization, reducing manual workload so Helvetia's in-house team stays focused on strategic decisions rather than first-pass processing. H1 Analytics & Intelligence gives the team the visibility to track severity trends, resolution timelines, and program health in dashboards built for security leadership. Across five European markets with distinct regulatory environments, the platform provides a consistent operational model without requiring separate program instances per jurisdiction.

Image
Ai Red Teaming Define scope
The Impact

Driving value

The program quickly proved its value. Security researchers uncovered logic flaws and complex chained vulnerabilities, issues that would have gone undetected through automated tools.

Continuous testing by a global community gave us insights that traditional methods simply couldn’t. It’s like having a 24/7 security lens on our systems. 

By incorporating time-bound bounty incentives during high-impact product launches, Helvetia saw faster vulnerability reporting and higher engagement. The team also leveraged H1 Analytics & Intelligence to streamline triage, allocate resources effectively, and prioritize remediation based on risk.

Image
Hai
The Impact

Agentic validation at scale

Helvetia also adopted H1 Platform's agentic validation capabilities to accelerate vulnerability validation and reduce manual workload. Hai analyzes each report by assigning a credibility score, comparing it against similar submissions, and suggesting CVSS severity and bounty amounts. By surfacing high-impact findings faster, it enables Helvetia’s team to focus on strategic decisions and faster resolution

Image
Digital automation connection
The Impact

Scaling security with HackerOne's researcher network

Our bug bounty program acts as a force multiplier rather than replacing internal efforts. Helvetia’s in-house security team can now focus on strategic initiatives while HackerOne’s community enhances day-to-day vigilance.

“The collaboration between internal experts and ethical security researchers has elevated our program. It’s no longer just about finding bugs – it’s about building a resilient security culture.”

Looking Ahead

The future of security at Helvetia

Helvetia sees HackerOne as a long-term partner in its cybersecurity strategy. As the organization continues to grow and evolve, the bug bounty program will remain a cornerstone of its efforts to stay proactive, agile, and resilient. With HackerOne’s scalable model, Helvetia can continuously adapt to new challenges and ensure emerging threats are addressed before they impact the business.

The return on investment is clear. By reducing risk, accelerating response times, and reinforcing customer trust, HackerOne has delivered measurable value. “Preventing even a single breach can justify the investment,” said Ulrich Winterer. “But more than that, the program has helped protect our reputation and strengthen our security culture.”

For organizations considering a bug bounty program, Helvetia recommends starting with clear objectives and choosing a trusted, experienced partner. Transparency around program scope and an openness to collaboration with security researchers are key. “A bug bounty program isn’t just a tactical initiative – it’s a long-term commitment to continuous improvement.”

Looking forward, Helvetia plans to expand the program's reach even further. One area of focus will be deeper integration into DevSecOps processes, embedding vulnerability discovery earlier in the software development lifecycle. As security continues to shift left, HackerOne will help Helvetia stay ahead of threats while enabling faster, safer innovation.

Helvetia's partnership with HackerOne