I’ve recently heard about the Bug bounty idea – a program for rewarding IT geeks (with just recognition or even money) for finding bugs in company systems.
The idea is similar to honeypot mechanizm, but one step before – which is more civilized and less ridicule for corporation.
Even though I think it’s a good idea, for me behind the scenes it’s the way of paying the hacker for keeping his mouth shot 😉
At the end of the day it’s always cheaper than PR harm, which in some cases cannot be restored to it’s original form.
You can find some info at wikipedia: Bug bounty program and a list of companies with bug bounty programs