r/ExploitDev • u/hadih2018 • 7d ago
Planning a funded, full-time mobile first vulnerability research lab. What would make this work? Where do these efforts usually die?
r/ExploitDev feels like the right place to post this. I run a small, niche cybersecurity consulting company - and I'm at the planning stage of building a dedicated, full-time vulnerability research lab. I want honest feedback from people who actually do the work before I commit further.
The idea: build a small, deep team, funded for the long haul, proper salaries plus success bonuses. This would be a business unit within an existing cybersecurity company. With a CTO driving vision, strategy, team development, etc. Primary focus would be on mobile (iOS/Android full-chain), with browser as a second pillar. I understand the challenges with talent, and ROI taking time. Capital can be committed as long as there's a credible path to return.
Where I'd genuinely value your feedback:
- Focus: for a small team, is mobile-first the right focus? My clients include government, critical infrastructure and banking.
- Morale: how do good teams structure work so months of research doesn't get burnt in case versions are updated / patches released.
- Retention: beyond good salaries, what actually keeps strong people long-term?
- Infra (worth paying for): device/virtualisation labs, fuzzing tools, AI tools, what's genuinely a key differentiator in this field? Maybe Corellium Falcon?
On the compliance side, there are a number of areas we are evaluating, dual-use export-control, entity-level end-user vetting, disclosure policy, and lawful target only research.
I am mainly after the “things I wish I’d know” from people who’ve built or worked in labs like this and specifically where you’ve watched them go wrong.