# The CMS.gov OSPO One Year Later: Launching the Agency’s First Bug Bounty!

Source: https://www.youtube.com/watch?v=zER5YI5nRdg
Recap page: https://rapidrecap.app/video/zER5YI5nRdg
Generated: 2025-09-26T16:06:23.372+00:00

---
## Quick Overview

The CMS.gov OSPO launched its first bug bounty program, aiming to harness the power of the hacker community to improve security and identify vulnerabilities in federal systems.

**Key Points:**
- The Centers for Medicare & Medicaid Services (CMS) launched its first bug bounty program, "The OSPO One Year Later: Launching the Agency's First Bug Bounty!", at DEF CON 33.
- The program aims to leverage the hacker community to find vulnerabilities in federal systems, making them more secure.
- Bug bounty programs allow ethical hackers to report vulnerabilities without fear of legal repercussions, fostering a collaborative security environment.
- Casey Ellis, founder of Bugcrowd, highlighted the importance of such programs in making the internet safer and ensuring that governments can leverage the global security talent pool.
- The initiative aims to encourage participation from hackers by offering rewards and recognition for valid vulnerability reports.
- The program's success is measured not only by the number of bugs found but also by the improvement in the overall security posture of CMS systems.
- The talk emphasized the cultural shift required within government agencies to embrace bug bounty programs and proactive security measures.

![Screenshot at 00:00: The video begins with a title card displaying "AIxCC AI Cyber Challenge" and "AIxCC STAGE AT DEF CON 33", setting the context for a discussion about bug bounties at a cybersecurity conference.](https://ss.rapidrecap.app/screens/zER5YI5nRdg/00-00-00.png)

**Context:** This video discusses the launch of the first bug bounty program by the CMS.gov Open Source Program Office (OSPO) at DEF CON 33. The panel features key individuals involved in establishing and running the program, including Casey Ellis from Bugcrowd, who highlights the significance of bug bounties in enhancing cybersecurity and fostering collaboration between government agencies and the hacker community. The discussion emphasizes the importance of these programs for identifying and mitigating vulnerabilities in critical federal systems.

## Detailed Analysis

The CMS.gov OSPO launched its inaugural bug bounty program at DEF CON 33, a significant step in enhancing the security of federal systems. The program aims to leverage the collective expertise of the hacker community to proactively identify and report vulnerabilities. This initiative allows ethical hackers to engage with government systems in a secure and legal framework, fostering a collaborative approach to cybersecurity. Casey Ellis, founder of Bugcrowd, a prominent bug bounty platform, spoke about the program's importance, emphasizing how it allows governments to tap into a global talent pool for security research. The success of such programs is measured by the number of vulnerabilities discovered and the subsequent improvements in system security. The discussion also touched upon the cultural challenges and shifts needed within government to embrace such open and collaborative security models. The program's design aims to be attractive to hackers by offering rewards and recognition, thereby incentivizing participation and contributing to a safer digital environment for citizens. The initiative serves as a model for other government agencies looking to adopt similar proactive security measures.

### Program Launch

- CMS.gov OSPO launched its first bug bounty program at DEF CON 33.

### Program Goal

- To improve federal system security by leveraging the hacker community for vulnerability discovery.

### Bug Bounty Importance

- Fosters collaboration, allows ethical hackers to report vulnerabilities safely, and taps into global talent.

### Key Speaker

- Casey Ellis (Bugcrowd founder) discussed the significance of these programs.

### Success Metrics

- Measured by vulnerabilities found and improved security posture.

### Cultural Shift

- Highlights the need for government agencies to embrace proactive security through open collaboration.

### Participant Incentives

- Rewards and recognition encourage hacker participation.

![Screenshot at 00:00: The video begins with a title card displaying "AIxCC AI Cyber Challenge" and "AIxCC STAGE AT DEF CON 33", setting the context for a discussion about bug bounties at a cybersecurity conference.](https://ss.rapidrecap.app/screens/zER5YI5nRdg/00-00-00.png)
![Screenshot at 00:06: A title overlay reads "THE CMS.GOV OSPO ONE YEAR LATER: LAUNCHING THE AGENCY'S FIRST BUG BOUNTY!", introducing the main topic of the presentation.](https://ss.rapidrecap.app/screens/zER5YI5nRdg/00-00-06.png)
![Screenshot at 00:17: A wide shot of the stage shows the five panelists seated, with a large screen behind them displaying the AIxCC logo and background graphics, indicating a presentation or panel discussion.](https://ss.rapidrecap.app/screens/zER5YI5nRdg/00-00-17.png)
![Screenshot at 00:41: The speaker introduces the OSPO and the bug bounty program, setting the stage for the discussion about its development and impact.](https://ss.rapidrecap.app/screens/zER5YI5nRdg/00-00-41.png)
![Screenshot at 01:14: The speaker introduces Casey Ellis, founder of Bugcrowd, as the first panelist, highlighting her role in the bug bounty ecosystem.](https://ss.rapidrecap.app/screens/zER5YI5nRdg/00-01-14.png)
![Screenshot at 01:53: Details about Casey Ellis's background are presented, including her extensive experience in bug bounty programs and her role at Bugcrowd.](https://ss.rapidrecap.app/screens/zER5YI5nRdg/00-01-53.png)
![Screenshot at 02:22: The speaker introduces Keith Busby, Acting CISO at CMS, as the second panelist, emphasizing his role in the agency's cybersecurity efforts.](https://ss.rapidrecap.app/screens/zER5YI5nRdg/00-02-22.png)
![Screenshot at 02:47: Leah Siskind is introduced as the bug bounty program manager at CMS, highlighting her role in the initiative.](https://ss.rapidrecap.app/screens/zER5YI5nRdg/00-02-47.png)
![Screenshot at 03:15: The speaker introduces the third panelist, Zwink, a hacker, emphasizing the hacker community's perspective.](https://ss.rapidrecap.app/screens/zER5YI5nRdg/00-03-15.png)
![Screenshot at 03:50: Leah Siskind begins discussing the scale of CMS operations, noting that over 50% of Americans are insured through Medicare or Medicaid services.](https://ss.rapidrecap.app/screens/zER5YI5nRdg/00-03-50.png)
