
Before the Netherlands introduced a formal framework, vulnerability reporting depended far too much on judgement, luck, and how an organisation happened to react.
As a researcher, you had to work a lot of things out for yourself. How far should you go to prove the vulnerability is real? Who do you contact? How much information do you provide? Will the organisation thank you, ignore you, or threaten you?
From the organisation's side, there was uncertainty too. Is this person genuinely trying to help? Have they accessed data? How serious is the vulnerability? Do legal, communications, IT, management, or the police need to get involved?
Without a process, both sides were left guessing. And when a report did arrive, the first reaction could easily be defensive. That reaction is understandable. But it can also make things worse. Someone reporting a vulnerability is not necessarily attacking you. They may simply be giving you the chance to close a door before somebody decides to walk through it.
And that was the problem the Netherlands needed to solve.
In January 2013, the Dutch government published the Guideline for Responsible Disclosure through the National Cyber Security Centre, the NCSC.
It gave organisations a practical framework for receiving vulnerability reports and encouraged them to be clear about what researchers could and could not do.
That was important.
Researchers finally had more certainty about how to report a problem, while organisations had a better way to distinguish between someone acting in good faith and someone trying to cause harm.
The basic principle was straightforward: sometimes you need to demonstrate that a vulnerability exists, but you should not go further than necessary. That means avoiding unnecessary damage, accessing more information than required, maintaining access to systems, using techniques such as social engineering without good reason, or publishing the vulnerability before the organisation has had a reasonable opportunity to fix it.
The Dutch Public Prosecution Service also introduced guidance around Responsible Disclosure.
Public interest, proportionality and subsidiarity became important concepts. Was the researcher acting in the wider interest of security? Did they go further than necessary? And did they choose the least harmful way to investigate and report the issue?
This did not create a perfect legal safe harbour. Unauthorised access did not suddenly become legal because somebody called themselves an ethical hacker.
But it changed the relationship.
For the first time, researchers and organisations had a shared framework for the conversation. And organisations could confidently say: if you follow these rules and report the vulnerability in good faith, we will treat you as someone trying to improve our security rather than as someone attacking us.
That was a major step forward.
After 2013, the practice matured quickly.
More organisations published disclosure policies. The NCSC handled growing numbers of reports. And organisations started to understand that having a public reporting channel did not invite chaos.
It was simply part of taking vulnerability management seriously.
In 2018, the terminology changed from Responsible Disclosure to Coordinated Vulnerability Disclosure, or CVD.
I was part of the group of hackers working with government on this shift. When the CVD guideline was updated in 2018, they even put my face in it - propeller hat and all.
The change in wording matters.
"Responsible Disclosure" can suggest that the responsibility sits mainly with the researcher.
"Coordinated Vulnerability Disclosure" makes it clear that both sides have work to do.
And in reality, there can be many more parties involved: the person who found the issue, the organisation responsible for the system, software vendors, hosting providers, CSIRTs, regulators and sometimes the public.
CVD is therefore not simply about asking hackers to behave responsibly. It is an operational process. How do you receive a report? Who checks whether it is valid? Who owns the fix? How do you keep the researcher informed? When should disclosure happen? And what do you learn from the process afterwards?
That is what a good CVD looks like.


