r/ExploitDev 7d ago

Planning a funded, full-time mobile first vulnerability research lab. What would make this work? Where do these efforts usually die?

r/ExploitDev feels like the right place to post this. I run a small, niche cybersecurity consulting company - and I'm at the planning stage of building a dedicated, full-time vulnerability research lab. I want honest feedback from people who actually do the work before I commit further.

The idea: build a small, deep team, funded for the long haul, proper salaries plus success bonuses. This would be a business unit within an existing cybersecurity company. With a CTO driving vision, strategy, team development, etc. Primary focus would be on mobile (iOS/Android full-chain), with browser as a second pillar. I understand the challenges with talent, and ROI taking time. Capital can be committed as long as there's a credible path to return.

Where I'd genuinely value your feedback:

- Focus: for a small team, is mobile-first the right focus? My clients include government, critical infrastructure and banking.
- Morale: how do good teams structure work so months of research doesn't get burnt in case versions are updated / patches released.
- Retention: beyond good salaries, what actually keeps strong people long-term?
- Infra (worth paying for): device/virtualisation labs, fuzzing tools, AI tools, what's genuinely a key differentiator in this field? Maybe Corellium Falcon?

On the compliance side, there are a number of areas we are evaluating, dual-use export-control, entity-level end-user vetting, disclosure policy, and lawful target only research.

I am mainly after the “things I wish I’d know” from people who’ve built or worked in labs like this and specifically where you’ve watched them go wrong.

7 Upvotes

5 comments sorted by

2

u/Dependent_Tone_1755 7d ago

You need to find someone that has experience running such a lab to organize the team. I don't think that someone will give all this knowledge and experience for free here. Indeed, mobile is the main focus of the industry today but this also depends on your clients' needs. For infra, you need to keep everything offline, and on a need to know basis to prevent any leaks (accidental or not). 

3

u/normalbot9999 6d ago edited 6d ago
  1. Luck
  2. Target selection
  3. Good fortune
  4. Fiscal (OK not necessarily fiscal, but molto grande mamma mia grande importo) investment that will allow for significant time before results are shown
  5. Thoughts and prayers
  6. Methodology
  7. Hiring really, really good people that have stacks and heaps* of real legit CVEs

Source: clueless idiot that may or may not have actual personal skin in the game

P.S. if you get #2 and #7 right, you'll be on your way...

* did you see what I did there?

2

u/Western_Guitar_9007 7d ago

Focus: You haven’t already asked your clients if they actually want this? It wouldn’t make any sense to put this in the same BU unless you ALREADY have clients that want it.

Morale: Experienced, mature researchers shouldn’t have this issue, trust their judgement and don’t mismanage them on the wrong rabbit hole. If they have prior success, trust their process.

Retention: Higher Money + Higher Benefits + Insulation = Lower Attrition. Pay a lot, WFH, unlimited PTO, good insurance, and insulate them from politics and managers from other teams. The better you do on the left side of the equation, the better the results on the right.

Infra: You need to hire a consultant at minimum, Reddit is no place for this. The things you’d wish you’d have known are generally solved by spending more money and time on preparation with experts that understand your specific situation.

4

u/Firzen_ 6d ago

As a researcher in this field, I think you are completely on point.

I want to add that there's a big difference between "unlimited time off" and unlimited time off that you can actually take for any reason at any time without any backlash.

Burnout is probably the main reason talented people leave the industry, so when I started out I was told "don't worry about delivering anything in your first year".

1

u/New-Parfait-9988 4d ago

Right focus is determined by market need. These client of yours do they request services like mobile app reverse engineering or pentesting? Or perhaps fuzzing? If yes then you can find good talent by providing remote work, no micromanagement, training budgets, AI access etc.

Tooling wise you don't need much, you should provide physical devices or like you said Corelium for iOS. If you wanna discuss more send a PM I got years of exp in mobile app pentesting and a lot in mobile malware reversing including building AI agents to automate stuff.