Zerocopter Blogs

It started with responsible disclosure

From distrust to collaboration - and why it still matters.

By Edwin van Andel

The Netherlands did not become one of the frontrunners in Coordinated Vulnerability Disclosure by accident. It happened because hackers, companies, government, police, prosecutors and the security community gradually learned how to solve a very practical problem together: what should happen when someone finds a serious vulnerability and wants to report it before criminals get the chance to abuse it?

Before there was a recognised process, reporting a vulnerability could be personally risky. The person trying to help could quickly become the problem.

The Dutch Responsible Disclosure guideline of 2013 changed that conversation. Organisations got a framework for receiving vulnerability reports, while researchers got a somewhat safer route for doing the right thing.

In 2018, the terminology changed from Responsible Disclosure to Coordinated Vulnerability Disclosure, or CVD. That might sound like a small detail. It isn't. The focus shifted away from judging whether the hacker had behaved "responsibly" and towards something much more useful: solving the problem together.

Today, with NIS2 implemented in the Netherlands through the Cybersecurity Act, vulnerability disclosure is no longer a progressive nice-to-have. It has become part of the wider expectation that organisations understand their digital risks, respond to them and work with the people who can help uncover weaknesses before criminals do.

That is why CVD matters. It turns curiosity into an early warning system, conflict into communication and individual vulnerabilities into resilience.


Zerocopter Blogs

It started with responsible disclosure

From distrust to collaboration - and why it still matters.

By Edwin van Andel

The Netherlands did not become one of the frontrunners in Coordinated Vulnerability Disclosure by accident. It happened because hackers, companies, government, police, prosecutors and the security community gradually learned how to solve a very practical problem together: what should happen when someone finds a serious vulnerability and wants to report it before criminals get the chance to abuse it?

Before there was a recognised process, reporting a vulnerability could be personally risky. The person trying to help could quickly become the problem.

The Dutch Responsible Disclosure guideline of 2013 changed that conversation. Organisations got a framework for receiving vulnerability reports, while researchers got a somewhat safer route for doing the right thing.

In 2018, the terminology changed from Responsible Disclosure to Coordinated Vulnerability Disclosure, or CVD. That might sound like a small detail. It isn't. The focus shifted away from judging whether the hacker had behaved "responsibly" and towards something much more useful: solving the problem together.

Today, with NIS2 implemented in the Netherlands through the Cybersecurity Act, vulnerability disclosure is no longer a progressive nice-to-have. It has become part of the wider expectation that organisations understand their digital risks, respond to them and work with the people who can help uncover weaknesses before criminals do.

That is why CVD matters. It turns curiosity into an early warning system, conflict into communication and individual vulnerabilities into resilience.


Zerocopter Blogs

It started with responsible disclosure

From distrust to collaboration - and why it still matters.

By Edwin van Andel

The Netherlands did not become one of the frontrunners in Coordinated Vulnerability Disclosure by accident. It happened because hackers, companies, government, police, prosecutors and the security community gradually learned how to solve a very practical problem together: what should happen when someone finds a serious vulnerability and wants to report it before criminals get the chance to abuse it?

Before there was a recognised process, reporting a vulnerability could be personally risky. The person trying to help could quickly become the problem.

The Dutch Responsible Disclosure guideline of 2013 changed that conversation. Organisations got a framework for receiving vulnerability reports, while researchers got a somewhat safer route for doing the right thing.

In 2018, the terminology changed from Responsible Disclosure to Coordinated Vulnerability Disclosure, or CVD. That might sound like a small detail. It isn't. The focus shifted away from judging whether the hacker had behaved "responsibly" and towards something much more useful: solving the problem together.

Today, with NIS2 implemented in the Netherlands through the Cybersecurity Act, vulnerability disclosure is no longer a progressive nice-to-have. It has become part of the wider expectation that organisations understand their digital risks, respond to them and work with the people who can help uncover weaknesses before criminals do.

That is why CVD matters. It turns curiosity into an early warning system, conflict into communication and individual vulnerabilities into resilience.


Zerocopter Blogs

It started with responsible disclosure

From distrust to collaboration - and why it still matters.

By Edwin van Andel

The Netherlands did not become one of the frontrunners in Coordinated Vulnerability Disclosure by accident. It happened because hackers, companies, government, police, prosecutors and the security community gradually learned how to solve a very practical problem together: what should happen when someone finds a serious vulnerability and wants to report it before criminals get the chance to abuse it?

Before there was a recognised process, reporting a vulnerability could be personally risky. The person trying to help could quickly become the problem.

The Dutch Responsible Disclosure guideline of 2013 changed that conversation. Organisations got a framework for receiving vulnerability reports, while researchers got a somewhat safer route for doing the right thing.

In 2018, the terminology changed from Responsible Disclosure to Coordinated Vulnerability Disclosure, or CVD. That might sound like a small detail. It isn't. The focus shifted away from judging whether the hacker had behaved "responsibly" and towards something much more useful: solving the problem together.

Today, with NIS2 implemented in the Netherlands through the Cybersecurity Act, vulnerability disclosure is no longer a progressive nice-to-have. It has become part of the wider expectation that organisations understand their digital risks, respond to them and work with the people who can help uncover weaknesses before criminals do.

That is why CVD matters. It turns curiosity into an early warning system, conflict into communication and individual vulnerabilities into resilience.


Why I still have to explain CVD to people who see hackers as the enemy

Why I still have to explain CVD to people who see hackers as the enemy

Before CVD, reporting was the risky part

Before CVD, reporting was the risky part

Before the Netherlands introduced a formal framework, vulnerability reporting depended far too much on judgement, luck, and how an organisation happened to react.

As a researcher, you had to work a lot of things out for yourself. How far should you go to prove the vulnerability is real? Who do you contact? How much information do you provide? Will the organisation thank you, ignore you, or threaten you?

From the organisation's side, there was uncertainty too. Is this person genuinely trying to help? Have they accessed data? How serious is the vulnerability? Do legal, communications, IT, management, or the police need to get involved?

Without a process, both sides were left guessing. And when a report did arrive, the first reaction could easily be defensive. That reaction is understandable. But it can also make things worse. Someone reporting a vulnerability is not necessarily attacking you. They may simply be giving you the chance to close a door before somebody decides to walk through it.

And that was the problem the Netherlands needed to solve.

2013: Responsible Disclosure gets a framework

2013: Responsible Disclosure gets a framework

In January 2013, the Dutch government published the Guideline for Responsible Disclosure through the National Cyber Security Centre, the NCSC.

It gave organisations a practical framework for receiving vulnerability reports and encouraged them to be clear about what researchers could and could not do.

That was important.

Researchers finally had more certainty about how to report a problem, while organisations had a better way to distinguish between someone acting in good faith and someone trying to cause harm.

The basic principle was straightforward: sometimes you need to demonstrate that a vulnerability exists, but you should not go further than necessary. That means avoiding unnecessary damage, accessing more information than required, maintaining access to systems, using techniques such as social engineering without good reason, or publishing the vulnerability before the organisation has had a reasonable opportunity to fix it.

The Dutch Public Prosecution Service also introduced guidance around Responsible Disclosure.

Public interest, proportionality and subsidiarity became important concepts. Was the researcher acting in the wider interest of security? Did they go further than necessary? And did they choose the least harmful way to investigate and report the issue?

This did not create a perfect legal safe harbour. Unauthorised access did not suddenly become legal because somebody called themselves an ethical hacker.

But it changed the relationship.

For the first time, researchers and organisations had a shared framework for the conversation. And organisations could confidently say: if you follow these rules and report the vulnerability in good faith, we will treat you as someone trying to improve our security rather than as someone attacking us.

That was a major step forward.

2016 to 2018: From Responsible Disclosure to Coordinated Vulnerability Disclosure

2016 to 2018: From Responsible Disclosure to Coordinated Vulnerability Disclosure

After 2013, the practice matured quickly.

More organisations published disclosure policies. The NCSC handled growing numbers of reports. And organisations started to understand that having a public reporting channel did not invite chaos.

It was simply part of taking vulnerability management seriously.

In 2018, the terminology changed from Responsible Disclosure to Coordinated Vulnerability Disclosure, or CVD.
I was part of the group of hackers working with government on this shift. When the CVD guideline was updated in 2018, they even put my face in it - propeller hat and all.

The change in wording matters.

"Responsible Disclosure" can suggest that the responsibility sits mainly with the researcher.

"Coordinated Vulnerability Disclosure" makes it clear that both sides have work to do.

And in reality, there can be many more parties involved: the person who found the issue, the organisation responsible for the system, software vendors, hosting providers, CSIRTs, regulators and sometimes the public.

CVD is therefore not simply about asking hackers to behave responsibly. It is an operational process. How do you receive a report? Who checks whether it is valid? Who owns the fix? How do you keep the researcher informed? When should disclosure happen? And what do you learn from the process afterwards?

That is what a good CVD looks like.