Responsible Disclosure
Introduction
At VIB, we believe that cybersecurity is a shared responsibility. We value the efforts of ethical hackers and researchers who help us strengthen our digital environment. This Responsible Disclosure Policy provides a clear, transparent, and safe framework for reporting vulnerabilities in our systems.
Glossary
To help readers understand this document, here are short definitions of commonly used terms:
- Responsible Disclosure: The process by which security researchers report vulnerabilities to an organization in a safe, structured, and ethical manner, allowing the organization to address the issue before public disclosure.
- Vulnerability: A weakness or flaw in a system, application, or process that could be exploited to compromise security or functionality.
- Ethical Hacker / Security Researcher: An individual who lawfully investigates and reports security vulnerabilities to help organizations improve their security posture.
- PGP Key (Pretty Good Privacy key): A cryptographic key used to encrypt and decrypt messages or files, ensuring secure and confidential communication.
- DDoS (Distributed Denial of Service): An attack that attempts to make a service unavailable by overwhelming it with traffic from multiple sources.
- Social Engineering: Manipulating individuals into divulging confidential information or performing actions that compromise security.
- Brute Force Attack: A method of gaining access by systematically trying all possible combinations of passwords or keys.
- Malware: Malicious software designed to damage, disrupt, or gain unauthorized access to systems.
- Hall of Fame: A recognition system for researchers who responsibly report vulnerabilities, ranking them based on the number and severity of their findings.
- Encryption: The process of converting information into a code to prevent unauthorized access, commonly used for secure communication (e.g., using a PGP key).
- Confidentiality: Ensuring that information is accessible only to those authorized to have access.
Scope
This policy applies to:
- All web applications, platforms, and digital services managed by VIB.
- All interactions with these services, such as logging in or submitting forms.
Out of Scope
This policy does not apply to:
- Systems or services of third parties.
- Internal test or development environments.
- Anything explicitly excluded in this policy.
Objectives
- To encourage open dialogue with the security community.
- To ensure vulnerabilities are reported and resolved responsibly, without risk to those acting in good faith.
How to Report a Vulnerability
Send your report confidentially to security@vib.be, encrypted with our PGP key.
- Start the subject line with [reported vulnerability] and add a short, clear title.
- Attach a report (PDF or DOCX, max. 25 MB) including:
- Description of the vulnerability (type, impact, scope).
- Step-by-step reproduction instructions (including relevant URLs, parameters, screenshots).
- Your contact details (name/pseudonym, email address, optional phone number).
- Reports are preferably submitted in English, but Dutch and French are also welcome.
Code of Conduct for Researchers
- Demonstrate vulnerabilities minimally, without further exploitation.
- Do not open, modify, or delete data belonging to others.
- Do not disrupt our services (no DDoS, spam, brute force, etc.).
- Do not share details publicly without our written consent.
- Do not attempt to gain additional access rights.
- Collect only strictly necessary information.
What We Do Not Expect
- Social engineering, phishing, or attacks on staff/users.
- Testing of third-party services.
- Ransom demands or active exploitation.
- Installation of malware or deletion of data.
- Findings such as weak mail configurations or outdated TLS versions without direct risk.
Our Commitment to You
We will handle every report carefully and promptly.
- No legal action will be taken if you act within this policy.
- Recognition via a LinkedIn recommendation and/or mention in our Hall of Fame.
- Ranking based on the number and severity of reported vulnerabilities (no financial
reward).
Legal Framework
Always act proportionally and within the boundaries of the law. Unauthorized access, dissemination of obtained data, or development of hacking tools is punishable by law. Your actions must be strictly limited to what is necessary and proportionate to discover and report a vulnerability.
The following may be considered illegal:
- Unauthorized access or attempts to access an information system.
- Exceeding authorized access rights.
- Copying or taking over data.
- Developing or possessing hacking tools.
- Retaining, disclosing, using, or distributing information obtained through unauthorized access.
- Entering or modifying data in an information system.
- Intercepting communications or attempting to do so.
- Breaching professional or contractual confidentiality.
Source: Legal procedure for reporting vulnerabilities to the CCB | CCB Safeonweb