A British cybersecurity expert granted permanent residency through Australia’s National Innovation visa has launched a Sydney-based cybersecurity company within six months of receiving it.
Jacob Riggs recently founded Bugtri, an Australian cybersecurity platform built to automatically assess vulnerability reports submitted to organisations and help security teams separate genuine threats from spam, duplicates and increasingly convincing reports produced with generative AI.
The launch also provides an early test of what Australia’s National Innovation visa is intended to achieve, with Riggs moving from the United Kingdom to Sydney and establishing a cybersecurity company within months of receiving permanent residency.
Bugtri founder and CEO Jacob Riggs told Tech Business News he hacked the Australian government and they later awarded him an ultra-rare visa.
“Australia welcomed me through the National Innovation Visa program, and I’ve tried to contribute back by creating an innovative Australian company that now aims to solve a global cybersecurity problem,” said Riggs
Bugtri opened early-access applications three weeks ago and has since received 27 applications, with 11 organisations now actively using the platform.
The early uptake comes as security teams and open-source maintainers face increasing pressure from vulnerability submissions that can appear technically credible but still require considerable time and expertise to investigate.
Riggs believes vulnerability disclosure is entering an “AI arms race”, with generative AI making it possible to produce reports at a scale that traditional human triage processes were never designed to handle.
The issue has already drawn the attention of the Open Source Security Foundation, whose Vulnerability Disclosures Working Group has been examining the impact of low-quality and AI-generated vulnerability reports on open-source projects and the wider security community.
One case examined through that work involved the curl project, where only about 5% of bug bounty submissions were reported to be genuine vulnerabilities by the middle of 2025, while around 20% appeared to be low-quality reports generated with AI.
The shift is creating a significant workload problem for security teams.
Generative AI can produce detailed vulnerability reports quickly and in large numbers, but each submission can still require an analyst to determine whether the issue is genuine, whether it has already been reported and whether remediation or escalation is required.
Bugtri is designed to assess those reports before they consume substantial analyst time. The platform connects to an organisation’s shared security mailbox, analyses incoming vulnerability submissions and returns a structured decision, risk score and summary directly to the inbox.
Sensitive information, including URLs and IP addresses, is sanitised before being sent to an AI provider. Reports can be categorised, duplicates identified and uncertain assessments referred for human review rather than being automatically rejected.
The company says it’s new system is intended to reduce the amount of time security teams spend processing low-value reports while preserving human oversight where there is uncertainty.
For organisations operating vulnerability disclosure or bug bounty programs, that distinction is becoming increasingly important.
A poorly researched report can still require an analyst to reproduce the alleged flaw, inspect affected systems, check for previous submissions and determine whether further investigation is warranted.
When those reports arrive at scale, the workload can divert security personnel away from legitimate vulnerabilities and active incidents.
Bugtri is effectively using AI to counter a problem that AI itself is helping accelerate, positioning the platform as an automated triage layer between incoming vulnerability reports and the analysts responsible for making final security decisions.
The company was entirely bootstrapped and self-funded by Riggs, who moved from the United Kingdom to Sydney after securing Australia’s National Innovation visa, subclass 858.
Australia’s Most Selective Migration Pathways
The visa is one of Australia’s most selective permanent migration pathways and is reserved for people with an internationally recognised record of exceptional and outstanding achievement.
Applicants must first be invited by the Australian Government before they can lodge a visa application.
The program is intended to attract internationally recognised talent capable of contributing to Australia’s economy, productivity and strategically important industries.
Riggs’ move into the Australian cybersecurity sector provides an early example of that policy translating into local company formation rather than remaining an abstract migration objective.
Within six months of receiving permanent residency, he has established an Australian cybersecurity company, secured its first users and begun developing technology aimed at a problem already attracting international attention.
During the visa application period, Riggs also responsibly disclosed a vulnerability in a live Australian Government system, which was subsequently acknowledged by the Department of Foreign Affairs and Trade.
His experience in vulnerability disclosure extends back more than a decade and includes responsibly reporting security weaknesses to thousands of organisations around the world.
That work exposed him to recurring problems in how vulnerability reports are received, assessed and prioritised, particularly when organisations are dealing with large volumes of submissions.
“After responsibly disclosing vulnerabilities to thousands of organisations over the past decade and observing the friction in their processes, I’m simply reconnecting with those teams and offering the automated triage solution they now need,” said Riggs
Riggs’ case gives Australia’s National Innovation visa program a tangible cybersecurity outcome only months after permanent residency was granted.
The visa has already resulted in the establishment of an Australian company working in a strategically important technology sector at a time when governments and businesses are confronting growing cybersecurity threats and an increasingly AI-driven security environment.
Bugtri has also been accepted into the Australian Signals Directorate Partner Program.
Riggs says he intends to make the platform’s capabilities available on a not-for-profit basis where they can support Australia’s cybersecurity interests.
The company remains in early access and its performance at greater scale is yet to be established, but the problem it is targeting is becoming increasingly difficult for the cybersecurity industry to ignore.
The surge in AI-generated vulnerability reports is now creating a practical security risk of its own, with genuine flaws increasingly competing for attention inside already crowded disclosure channels.
For security teams, the danger is that the next serious vulnerability may not be missed because nobody reported it, but because it was buried among hundreds of reports that looked convincing and led nowhere..

