
The latest insights on global VDP adoption & IoT security trends
Source: YouTube · HackerOne · published Feb 28, 2025 · 46:20
The 2024 report on global vulnerability disclosure policy adoption, now in its seventh year, analyzes how IoT and consumer companies manage security risks by receiving reports from ethical hackers 0:22.
Key Takeaways:
• The report tracks the adoption of vulnerability disclosure policies among IoT and consumer product companies to improve their security posture 0:25.
• A vulnerability disclosure policy serves as a formal mechanism for organizations to receive and handle security findings from the external research community 0:36.
• This year's webinar highlights key findings from the ongoing seven-year study conducted on behalf of the IoT Security Foundation 0:20.
• The discussion features insights from David Rogers, a co-author of the report, alongside host Lorri Merer from HackerOne 0:08.
Understanding these policies is essential for fostering collaboration between manufacturers and the security community to mitigate risks in consumer technology.
Sources:
- 0:22 Introduction to the seventh annual report on vulnerability disclosure policy adoption.
- 0:25 Overview of the report's focus on IoT and consumer space companies.
- 0:36 Definition of a vulnerability disclosure policy and its role in security.
- 0:20 Context on the seven-year history of the report and its sponsors.
- 0:08 Introduction of the speakers, Lorri Merer and David Rogers.
Generate CPE Credits
Generate a professional CPE document from this video's transcript.
Estimated credit: 1 CPE hours
Estimate uses the video runtime (1 hour ≈ 1 CPE, rounded to the nearest 0.5, minimum 0.5, maximum 2.0). The final amount can be lower after review, never higher.
Topic: Cybersecurity. Commonly maps to: Security and Risk Management, Security Operations. Exact CISSP domains are assigned during generation.
Free account. One generation at a time, with a daily limit.
CPEBuddy is independent and not affiliated with or endorsed by ISC2, ISACA, or any certification body. Exports are formatted for common CPE submissions; acceptance is at your certification body's discretion.
Transcript Preview
First 800 characters of the transcript
um good afternoon uh everybody uh my name is lorri merer from hacka one and today we're going to be hosting a webinar and together with uh David Rogers um of copper horse on the 2024 report on global vulnerability disclosure policy adoption um just as a reminder this report has been running for seven years now um on behalf of the iot security foundation and and Dave is one of the authors of this report and it basically looks at all of the different companies out there in the iot consumer space who are running what we call a vulnerability disclosure policy um that is a way for an organization to receive vulnerabilities from the outside world from ethical hackers or security researchers uh in order to improve the security um of their of their products um today we're going to go over some of …