Hack, Learn, Improve: Inside Storebrand’s Bug Bounty Experience

Oleksandr Kazymyrov

Experience Report

Over the past years, Storebrand has actively engaged with ethical hackers through its bug bounty program, uncovering and mitigating vulnerabilities across a wide range of systems. In this talk, we’ll share what we’ve learned from real-world reports (from surprising edge cases to recurring patterns) and how these insights have strengthened both our technology and our culture.

We’ll highlight some of the most interesting findings, discuss how we improved our detection and response processes, and reflect on what it takes to build genuine collaboration between developers and security researchers. Whether you’re a developer, tester, or security professional, this session offers practical lessons on turning bugs into opportunities for better security.