Bug Bounty has become a vital testing layer for a growing number of EU financial services firms, with AI threats and the Digital Operational Resilience Act (DORA) both increasing the need for agile, continuous security testing.
In our latest interview with a customer in this sector, a pair of senior security professionals from Crédit Agricole Personal Finance & Mobility (CAPFM) explain how they’ve handled scoping and calibrated testing coverage so far, the various benefits of crowdsourced security testing, the key role played by YesWeHack’s triage team, and CAPFM’s plans for testing AI-powered scopes.
Sandy Dussottier is an expert leader in new technologies and AI, while Claire Saulnier is information security officer and expert leader in risk management.
CAPFM is a European leader in consumer finance and mobility solutions. Operating in 22 countries, it provides consumer credit, leasing, insurance, instalment payments, vehicle financing and related services to more than 17 million customers.
Sandy on the reasons for launching a Bug Bounty Program…
My question is: why not? With the hunters, we have a community of different mindsets, different tools, different skills.
It’s very precious because with one auditor for one week, two weeks, you don’t have all the mindsets [necessary] to discover all [vulnerabilities].
Claire on CAPFM’s Bug Bounty configuration so far…
So we firstly did the most known assets with [authenticated user] access. And more progressively, we then added the less well-known assets.
We firstly had not a lot of results, so we had time to understand the platform, the hunters. And more progressively, we had more and more findings that were really interesting for us, because some findings were applicable to other perimeters.
A few months after the beginning of the black-box program, we [introduced] a grey-box program. We needed to give accounts to the hunters, so we needed to have the trust also of the people working in the business, to give this access to the hunters.
And the [ultimate] objective is to have all the exposed attack surface [of CAPFM] in the program.
Sandy on the most notable benefits of Bug Bounty…
Many points. The first is having the opportunity to have a [useful] tool and humans, because we have humans in the loop to deep dive on our exposed applications.
In addition, we have the opportunity to have every day, every hour, all across the year, our security improved by the hunters.
Sandy on the triage team’s contribution…
The expertise of the YesWeHack guys on the triage team is very important because it’s the first layer, the first phase to help us understand the hunters’ [reports] and to verify the Proof of Concept and finding. [As a result, we don’t have to] spend much time engaging in discussions with the hunters to understand what they are saying.
Claire on their testing coverage…
So firstly, we tested all the exposed surface with black-box testing, then grey-box testing for the most critical [assets] with [authenticated user] access.
And for now, what we wish to test is all the blind spots of our [information systems]. This means maybe the API or some other exposed assets that are maybe not tested annually.
Sandy on any AI-related scopes in the pipeline…
We launched a new AI for clients or partners and it’s very important for our company to secure that.
For me, it’s normal to take another step with YesWeHack to launch the same [testing regime] for the AI system exposed on the internet, to secure its usage for our clients and partners.
WANT TO LAUNCH A BUG BOUNTY PROGRAM?
Is your security team managing a Bug Bounty Program yet? Schedule a Bug Bounty consultation to find out more about the benefits of crowdsourced security testing and how this model can be adapted to the specific needs of your organisation.



