Companies are often contacted by individuals claiming to be "white hat" hackers who purport to have identified a security vulnerability and are willing to share it with the company for a price. These requests are often perceived as extortion or blackmail when they are unsolicited, but having such cybersecurity information may ultimately benefit the companies, so they are increasingly deciding to create formal “bounty” programs to encourage such hackers, and the public at large, to come forward. This program addresses the legal implications of creating (or not creating) a "bounty" program and provides practical advice for in-house counsel on how to structure and draft such a program.