How Helvetia replaced point-in-time testing with continuous security across five countries
Cybersecurity has become a vital part of Helvetia’s strategy to protect both its operations and the trust of its customers.
Limitations of a traditional model
Helvetia Group is one of Switzerland’s leading insurance companies, offering a broad range of insurance and pension solutions in Germany, Austria, Spain, Italy, and France. Cybersecurity has become a vital part of Helvetia’s strategy to protect both its operations and the trust of its customers.
As cyber threats become more sophisticated and the attack surface expands, Helvetia recognized the need for a proactive, scalable approach to vulnerability management. That’s when they turned to HackerOne.
Before HackerOne, Helvetia relied on traditional penetration testing and internal security processes to identify vulnerabilities. While these methods were useful, they had limitations:
Non-continuous testing
Testing occurred at fixed intervals, often leaving long gaps between assessments
Testing occurred at fixed intervals, often leaving long gaps between assessments
Restricted scope
The scope was restricted, meaning some assets weren’t regularly tested
The scope was restricted, meaning some assets weren’t regularly tested
A growing ecosystem
Scaling security efforts across a growing digital ecosystem was increasingly difficult
Scaling security efforts across a growing digital ecosystem was increasingly difficult
Slow response
Manual workflows slowed down response times
Manual workflows slowed down response times
Helvetia's program on HackerOne
Helvetia runs both H1 Bounty and time-bound challenge engagements through the H1 Platform, giving the security team continuous researcher coverage alongside focused, high-intensity testing during product launches and peak-risk periods. The H1 Platform's agentic validation capabilities handle report credibility scoring, severity assessment, and triage prioritization, reducing manual workload so Helvetia's in-house team stays focused on strategic decisions rather than first-pass processing. H1 Analytics & Intelligence gives the team the visibility to track severity trends, resolution timelines, and program health in dashboards built for security leadership. Across five European markets with distinct regulatory environments, the platform provides a consistent operational model without requiring separate program instances per jurisdiction.
Driving value
The program quickly proved its value. Security researchers uncovered logic flaws and complex chained vulnerabilities, issues that would have gone undetected through automated tools.
Continuous testing by a global community gave us insights that traditional methods simply couldn’t. It’s like having a 24/7 security lens on our systems.
By incorporating time-bound bounty incentives during high-impact product launches, Helvetia saw faster vulnerability reporting and higher engagement. The team also leveraged H1 Analytics & Intelligence to streamline triage, allocate resources effectively, and prioritize remediation based on risk.
Agentic validation at scale
Helvetia also adopted H1 Platform's agentic validation capabilities to accelerate vulnerability validation and reduce manual workload. Hai analyzes each report by assigning a credibility score, comparing it against similar submissions, and suggesting CVSS severity and bounty amounts. By surfacing high-impact findings faster, it enables Helvetia’s team to focus on strategic decisions and faster resolution
Scaling security with HackerOne's researcher network
Our bug bounty program acts as a force multiplier rather than replacing internal efforts. Helvetia’s in-house security team can now focus on strategic initiatives while HackerOne’s community enhances day-to-day vigilance.
“The collaboration between internal experts and ethical security researchers has elevated our program. It’s no longer just about finding bugs – it’s about building a resilient security culture.”
The future of security at Helvetia
Helvetia sees HackerOne as a long-term partner in its cybersecurity strategy. As the organization continues to grow and evolve, the bug bounty program will remain a cornerstone of its efforts to stay proactive, agile, and resilient. With HackerOne’s scalable model, Helvetia can continuously adapt to new challenges and ensure emerging threats are addressed before they impact the business.
The return on investment is clear. By reducing risk, accelerating response times, and reinforcing customer trust, HackerOne has delivered measurable value. “Preventing even a single breach can justify the investment,” said Ulrich Winterer. “But more than that, the program has helped protect our reputation and strengthen our security culture.”
For organizations considering a bug bounty program, Helvetia recommends starting with clear objectives and choosing a trusted, experienced partner. Transparency around program scope and an openness to collaboration with security researchers are key. “A bug bounty program isn’t just a tactical initiative – it’s a long-term commitment to continuous improvement.”
Looking forward, Helvetia plans to expand the program's reach even further. One area of focus will be deeper integration into DevSecOps processes, embedding vulnerability discovery earlier in the software development lifecycle. As security continues to shift left, HackerOne will help Helvetia stay ahead of threats while enabling faster, safer innovation.