A fintech board wants a bug bounty live before a funding round in 30 days. No vulnerability disclosure policy exists and internet-facing assets were never inventoried. What should the security manager do FIRST?
A. Launch a private bounty limited to the main web application
B. Run an authenticated vulnerability scan of all production systems
C. Define the disclosure policy and scope the assets in play
D. Hire an external firm to penetration test before launch
(Explain your answer for more points in the comments!)