Belgian Federal Government invites Ethical Hackers for First-Ever 'Hack the Government' Event
CVE/FIRST VulnCon 2025 · Main Stage
Overview
This talk details the ambitious journey of the Belgian Federal Government to transition from a stance of prosecuting ethical hackers to actively inviting them to secure national digital assets. Presented by Susan Bush, Project Manager for the inaugural "Hack the Government" event, the session provides a candid look at the societal, legal, and operational challenges overcome to make this pioneering initiative a reality. While her colleague Johan Callaway, a renowned cybersecurity expert and the technical lead for the event, was unable to attend, Bush effectively conveys the depth of expertise and strategic planning involved.

Key moments
- 0:00 The paradox: criminalized hackers now invited by government
- 1:00 Speaker's journey: organizing 'Hack the Government' event
- 2:00 Introducing the expert team and technical lead
- 3:40 Why Belgium? Understanding the unique national context
- 6:00 Belgium: first to institutionalize and promote ethical hacking
- 7:00 CCB's creation: transforming cyber outlaws into guardians
- 8:00 Key motivations and players behind the government hack
Belgian Federal Government invites Ethical Hackers for First-Ever 'Hack the Government' Event
Speakers: Susan Bush (Project Manager, CERT Network, Center for Cyber Security Belgium), Johan Callaway (Cybersecurity Expert, CERT Network, Center for Cyber Security Belgium)
Conference: VulnCon
YouTube: https://www.youtube.com/watch?v=f9zlUbvqa1E
Overview
This talk details the ambitious journey of the Belgian Federal Government to transition from a stance of prosecuting ethical hackers to actively inviting them to secure national digital assets. Presented by Susan Bush, Project Manager for the inaugural "Hack the Government" event, the session provides a candid look at the societal, legal, and operational challenges overcome to make this pioneering initiative a reality. While her colleague Johan Callaway, a renowned cybersecurity expert and the technical lead for the event, was unable to attend, Bush effectively conveys the depth of expertise and strategic planning involved.
The core of the presentation revolves around the establishment of a safe harbor law for ethical hackers in Belgium and the subsequent organization of a large-scale live hacking event targeting federal government services. This endeavor is significant because it represents a profound shift in government-hacker relations, moving from suspicion and criminalization to collaboration and mutual trust. It underscores a growing global recognition that ethical hackers are not adversaries but invaluable partners in enhancing national cyber resilience.
The "Hack the Government" event, held in late 2024, was not merely a technical exercise but a strategic move to build an ethical hacking community, foster national talent, and proactively identify vulnerabilities in critical government infrastructure. By sharing their story, the Belgian CCB offers a blueprint for other nations seeking to leverage the collective intelligence of the hacking community to strengthen their cybersecurity posture, demonstrating that substantial security gains can be achieved even without large monetary incentives, provided there's a robust legal framework and genuine appreciation for the hackers' contributions.
Background
▶ Watch: The paradox: criminalized hackers now invited by government (0:00)
Belgium, a relatively young constitutional monarchy with a legal system based on Napoleonic code, faced a significant challenge in adapting its laws to the rapidly evolving cybersecurity landscape. Historically, the act of hacking, even with benevolent intent, was a criminal offense. Susan Bush recounted a poignant true story from 2014 where an ethical hacker was criminally charged and received a permanent record for responsibly disclosing vulnerabilities in government systems. This incident starkly highlighted the legal vacuum and the deterrent effect such laws had on the cybersecurity community.
The turning point began in 2014 with the creation of the Center for Cyber Security Belgium (CCB), reporting directly to the Prime Minister's office. The CCB’s general director, Miguel Dereer, set ambitious goals: to make Belgium one of the least vulnerable countries in Europe, build a strong cybersecurity workforce, develop future talent, enhance crisis preparedness, and strengthen national cyber resilience. This vision necessitated a fundamental shift in how ethical hacking was perceived and regulated.
Prior to 2023, the rise of bug bounty platforms and the implementation of the EU's General Data Protection Regulation (GDPR) in 2018 made data protection an unavoidable priority. High-profile data breaches in Belgium forced companies to consider engaging independent hackers for security assessments. However, without a clear legal framework, these interactions remained legally ambiguous, with hacking still technically a criminal act. The need for legal protection for ethical hackers became paramount. This societal shift, from vilifying hackers to tolerating and eventually encouraging them, was the first crucial step. The opportunity arose with the EU’s directive mandating the transposition of whistleblower laws into national legislation. Belgium seized this moment, leveraging the directive to introduce a groundbreaking legal framework that would redefine ethical hacking within its borders.
Key Findings
▶ Watch: Introducing the expert team and technical lead (2:00)
The "Hack the Government" initiative yielded several critical findings, demonstrating the profound impact of a well-structured government-led ethical hacking program.
Firstly, the legal framework established by the new whistleblower law, passed on February 15, 2023, proved to be a cornerstone. This law legalized ethical hacking, even in cases where the hacked entity had not explicitly consented, provided strict conditions were met. This legislative courage, driven by the CCB, removed a significant barrier for ethical hackers and laid the foundation for trust. The law's implementation, including clear reporting procedures (24-hour simplified notification, 72-hour complete notification), was crucial for providing genuine protection.
Secondly, the talk emphasized the indispensable role of community building. The CCB actively worked to shift the perception of hackers from "villains" to "valued members of society." This involved acknowledging their talent, appreciating their efforts through non-monetary incentives like personalized letters from the CCB director-general and custom t-shirts, and sponsoring high-profile hacker conferences like BruCON. These efforts fostered an ecosystem where ethical hackers felt "seen" and valued, leading to high engagement rates in the "Hack the Government" event. The use of a Discord server for communication, coaching, and collaboration among hackers further solidified this community aspect.
Thirdly, the "Hack the Government" event itself served as a powerful proof of concept for live hacking as an ultimate security testing method. Over 15 days, 50 invited Belgian ethical hackers targeted assets from four federal public services, including the CCB's own systems. The event generated 154 reports, of which 85 were validated vulnerabilities, ranging from low to crucial severity. This demonstrated the immense value of crowd-sourced security assessments, far exceeding the scope and depth typically achieved by traditional penetration testing. A significant outcome was the discovery of a CVE (8.8 severity) in the Arctic Hub URL mapper security product, directly attributed to a researcher (Bob Vandermission) participating in the event, highlighting the real-world impact.
Finally, the initiative achieved unexpected and widespread societal impact. The event garnered extensive national and international media coverage, including prime-time news and recognition from the UN. The personal attendance of the Belgian Prime Minister at the award ceremony, where he personally distributed challenge coins and congratulated participants, provided the highest level of appreciation and legitimacy. This high-profile endorsement not only validated the program but also encouraged educational institutions, initially hesitant, to celebrate their students' participation, further strengthening the cybersecurity talent pipeline. The success proved that even without large budgets or cash prizes, engaging the ethical hacking community through legal protection, genuine appreciation, and impactful challenges can yield substantial rewards for national cybersecurity.
Technical Deep Dive
▶ Watch: Why Belgium? Understanding the unique national context (3:40)
The "Hack the Government" initiative was underpinned by a meticulously designed legal and operational framework, ensuring both the protection of ethical hackers and the security of targeted federal assets. The core of this framework is the whistleblower law, enacted on February 15, 2023, which established four primary conditions for ethical hackers to receive legal protection:
- No Intent to Harm or Illegitimate Benefit: Hackers must prove their activities were not intended to cause harm or obtain illicit gains. Extortion, for instance, remains illegal.
- Prompt Reporting: Any discovered cybersecurity vulnerability must be reported as soon as possible to both the CCB and the affected organization.
- Proportionality and Necessity: Hackers are not allowed to go further than "absolutely necessary and proportionate." This has been a nuanced point in the law, as determining the precise boundaries can be challenging. Crucially, ethical hackers are not protected from civil action if they cause damage.
- Information Disclosure Control: No information regarding vulnerabilities can be disclosed publicly without prior authorization from the CCB. This allows the CCB to manage coordinated disclosure and prevent premature public exposure that could be exploited.
Furthermore, the law explicitly applies only within Belgium, though amendments are proposed to extend protection to EU nationals hacking Belgian-based assets. All activities must strictly respect GDPR and other data privacy laws.
To operationalize these legal protections, the CCB established a clear reporting procedure:
- Within 24 hours of discovering a potential vulnerability, a simplified notification must be submitted to the CCB. If the target organization lacks a Coordinated Vulnerability Disclosure (CVD) policy, a general notification must also be sent to them.
- A complete, detailed notification, adhering to the specifications on the CCB website, must follow within 72 hours. Failure to meet these deadlines means the CCB cannot protect the hacker from criminal action.
The CCB’s internal CERT (Cyber Emergency Response Team), led by Jean-Luc Peters, was central to this operationalization. A dedicated technical research team within CERT, headed by Johan Callaway, was responsible for triaging all submitted vulnerability reports. This team acted as a crucial liaison between hackers and target organizations, even tempering potential backlash from organizations that had been hacked. This direct engagement, especially with Johan Callaway being an ethical hacker himself, built significant trust and credibility within the hacking community.
For the "Hack the Government" event, the CCB partnered with Integrity, a Belgian bug bounty platform company, which provided the technical platform and invaluable guidance on event management. Key insights from Integrity included the importance of constant communication (using Discord as the primary channel), the psychology of scope releases (staggering targets to maintain engagement), and the criticality of early bug findings to boost hacker morale.
The event targeted digital assets from four federal public services: BOSA (policy and government support), an organization responsible for medicines and health products, a group managing annual vacation entitlements for independent workers, and the CCB's own assets, notably safeonweb.be. To incentivize participation and demonstrate commitment, the CCB uniquely increased the severity rating of any vulnerability found against its own systems (e.g., a low-rated bug was bumped to medium, a medium to high), impacting the hacker's reputation points on the Integrity platform. This move, while initially causing internal apprehension, provided crucial insights into managing similar concerns from other federal agencies.
Hacker engagement was meticulously managed. The Discord server became a vibrant hub for discussions, team formation, coaching, and sharing tips. Participants were encouraged to use their personal identity credentials (Belgian ID cards) for testing, particularly for systems requiring authentication, which differed from typical anonymous testing environments. VPN use was also offered and encouraged to help targets monitor and throttle traffic if needed. The event's success was highlighted by findings like a CVE (8.8 severity) in the Arctic Hub URL mapper, credited to researcher Bob Vandermission and the "Hack the Government" initiative itself. This specific find underscores the practical, high-impact technical outcomes of the program.
Demo / Proof of Concept
▶ Watch: CCB's creation: transforming cyber outlaws into guardians (7:00)
While the talk itself did not feature a live technical demonstration, the entire "Hack the Government" event served as a large-scale, real-world proof of concept for the viability and effectiveness of government-sponsored ethical hacking programs. The event, held over 15 days and culminating in an in-person award ceremony, was meticulously designed to demonstrate that a legal framework combined with a community-focused approach could yield significant security benefits.
The "demo" of the CCB's innovative approach began even before the main event. At the BruCON conference, where the "Hack the Government" event was announced, the CCB team provided a tangible example of the hacking prowess they sought to harness. Their custom-made conference badges, typically secure, were hacked within minutes by the CCB team themselves, transforming the display into a "Matrix" like sequence that occasionally glitched to show "CERT." This playful yet potent demonstration immediately resonated with the hacker community, signaling the CCB's deep understanding and appreciation for their skills.
For hacker registration for "Hack the Government," the CCB implemented an ingenious, air-gapped system: a manual typewriter. This unconventional method not only respected the hackers' desire for privacy (by avoiding digital Personally Identifiable Information leaks) but also served as an unexpected "challenge." Susan Bush noted that hackers "can't resist trying," even attempting a failed SQL injection on the typewriter, highlighting their intrinsic curiosity and persistence. This quirky approach underscored the CCB's commitment to understanding and engaging with the unique culture of ethical hackers.
The ultimate proof of concept was, of course, the event's results: 154 reports submitted, leading to 85 validated vulnerabilities across critical federal government systems. This outcome directly demonstrated that inviting ethical hackers, even without monetary rewards, could uncover significant security flaws that might otherwise remain undiscovered until exploited by malicious actors. The discovery of a CVE with an 8.8 severity rating in a commercially available security product (Arctic Hub URL mapper) during the event provided concrete evidence of its high-impact contributions to national and even broader cybersecurity. The "Hack the Government" event, therefore, wasn't just a program; it was a living, breathing demonstration of a new paradigm in government cybersecurity.
Defensive Implications
▶ Watch: Key motivations and players behind the government hack (8:00)
The "Hack the Government" initiative offers profound defensive implications for governments and organizations worldwide seeking to bolster their cybersecurity posture. The central message is clear: embrace ethical hackers as indispensable cyber guardians, not as adversaries.
- Establish Legal Safe Harbors: The Belgian experience unequivocally demonstrates that a robust legal framework, such as a safe harbor law, is the foundational instrument for facilitating ethical hacking. Governments must prioritize transposing whistleblower protections and explicitly legalizing benevolent hacking to remove the fear of criminal prosecution. This encourages responsible disclosure and unlocks a vast pool of talent for national defense.
- Prioritize Proactive Security Testing: Live hacking events and structured bug bounty programs are shown to be superior to traditional, often superficial, penetration testing. They provide a "closest to a real incident without harm" scenario, allowing organizations to test their systems and incident response procedures under realistic pressure. Unlike ring-fence checks, ethical hackers often "pull on a loose thread," conducting deep, focused investigations that uncover subtle, critical vulnerabilities. Organizations should integrate these methods into their security assessment cycles.
- Invest in Community Building and Engagement: Defenders must actively foster a strong, trust-based relationship with the ethical hacking community. This involves genuine acknowledgment of their talent, appreciation for their efforts (even non-monetary, like public recognition, personalized letters, and unique swag), and creating platforms for interaction (e.g., Discord servers for collaboration and coaching). Making hackers "feel seen" and useful to society is a powerful motivator, far outweighing monetary incentives for many.
- Develop Robust Internal Triage and Communication: Hosting such events requires a highly skilled and dedicated internal triage team (like CCB's CERT team led by Johan Callaway). This team is critical for assessing reports, liaising between hackers and target organizations, and managing potential organizational backlash. Clear, consistent communication channels with hackers are essential for managing scope, providing updates, and ensuring respectful engagement.
- Cultivate Organizational Courage and Transparency: Federal agencies and other organizations must overcome internal fears regarding reputation damage, increased workload, and potential downtime. The CCB's approach of addressing these concerns head-on, offering no empty promises but highlighting the benefits (confidential results, proactive patching, free high-quality assessment), is crucial. Organizations must understand that vulnerabilities exist regardless; it is far better for ethical hackers to find them first. Leading by example, as the CCB did by putting its own assets in scope and increasing vulnerability ratings against itself, can inspire others.
- Leverage External Expertise and Platforms: Partnering with experienced bug bounty platform providers like Integrity can be invaluable. Their expertise in platform management, hacker psychology (e.g., scope releases), and communication strategies can significantly streamline the process and prevent common pitfalls.
In essence, the "Hack the Government" initiative demonstrates that a paradigm shift towards collaboration with the ethical hacking community, supported by appropriate legal and operational frameworks, is not just beneficial but essential for robust national cybersecurity. It empowers defenders to harness external ingenuity to stay ahead of evolving threats.
Key Takeaways
- Legal Frameworks are Foundational: Establishing a clear safe harbor law that protects ethical hackers from criminal prosecution is the single most important step for fostering a vibrant and effective ethical hacking ecosystem.
- Community Building Drives Engagement: Genuine acknowledgment, appreciation, and consistent engagement with the ethical hacking community (through events, awards, and communication platforms like Discord) are critical for motivating participation and building trust, even without large monetary rewards.
- Live Hacking is a Superior Security Test: Government-sponsored live hacking events provide a highly effective, deep, and realistic assessment of digital assets, often uncovering critical vulnerabilities (like the CVE 8.8 in Arctic Hub URL mapper) that traditional testing might miss.
- Government Endorsement is Powerful: High-level recognition, such as the Belgian Prime Minister's personal involvement, significantly legitimizes ethical hacking efforts, boosts hacker morale, and encourages broader societal and institutional support.
- Meticulous Planning and Communication are Essential: Successful execution requires careful planning of scope releases, robust internal triage, clear communication protocols with both hackers and target organizations, and the flexibility to adapt to unexpected challenges.
- Intrinsic Motivation is Key: Ethical hackers are often driven by a sense of purpose, patriotism, the challenge, learning opportunities, and the desire to "feel useful to society," rather than solely by financial incentives.
About the Speaker(s)
Susan Bush served as the Project Manager for the Belgian Federal Government's inaugural "Hack the Government" event in 2024. As part of the CERT network within Belgium, she was tasked with organizing this pioneering initiative to encourage ethical hackers to find vulnerabilities in federal government digital assets. Despite not being a programmer, hacker, or possessing deep technical expertise herself, Susan leveraged the skills of her talented team and focused on listening to their needs to successfully deliver the complex project.
Johan Callaway is a highly regarded Cybersecurity Expert and a key member of the CCB's C team and the CERT network. He is a guest professor at a prestigious Belgian university and an experienced bug bounty and ethical hacker, making him a "celebrity" within the Belgian ethical hacking market. In his day job, he works with the CCB's tech research group and served as the technical lead for the "Hack the Government" event, meticulously scoping the project and heading the triage team. Johan's expertise, particularly in API hacking, and his dedication were instrumental in the event's success, including his efforts in testing scopes and mentoring participants.
Reviews
Dr. Zero (Offensive Security Researcher) — SOLID
A competent case study / war story talk about Belgium's 'Hack the Government' initiative — the right lane for this content, and judged accordingly. Susan Bush delivers an honest, detailed account of building a national ethical hacking program from scratch: the safe harbor legislation, the community mechanics, the operational scaffolding, and the results. It's not a technical research talk and shouldn't be graded as one. Within its lane, it earns its slot. The legal framework details are genuinely useful for any government or large org trying to stand up a vulnerability disclosure program, the candor about internal resistance is refreshing, and the 85-validated-out-of-154-reports data point…
Heather Calloway (CISO) — SOLID
A credible and candid account of Belgium's legal and operational journey to stand up a government-sponsored live hacking program. The story is genuine, the outcomes are concrete, and the legislative innovation deserves attention from any government or security leader thinking about vulnerability disclosure policy. But the talk stays in program management territory — it documents what was done more than it analyzes why it works, what failed, or what the limits of this model are. For a CISO audience, it's instructive without being transformative.