NCSC CVD Policy
At the National Cyber Security Centre, the security of our systems and the privacy of our users are of paramount importance. We value the work of the security research community and believe that a collaborative relationship with researchers is vital to maintaining a resilient digital environment.
If you discover a security vulnerability in one of the National Cyber Security Centre systems, you can report the identified vulnerability to us below. This kind of report is known as a Coordinated Vulnerability Disclosure or CVD. In your report, please describe as clearly as possible how the problem can be reproduced as this will help to accelerate the resolution process.
Safe Harbour
The National Cyber Security Centre will not initiate legal action against any individual or entity that conducts security research and discloses vulnerabilities to us in accordance with this policy. We consider any activity conducted in good faith and within the defined scope of this policy to be activity carried out with our authority and therefore to be "lawful authority" under the Criminal Justice (Offences Relating to Information Systems) Act 2017. That said, ultimately it is a matter for any individual or entity to obtain its own independent legal advice to satisfy itself as to the lawfulness of its intended activities to ensure that no criminal offence under the Criminal Justice (Offences Relating to Information Systems) Act 2017 would be committed.
We waive any claims against researchers for accidental, good-faith violations of this policy, provided that the researcher ceases activity immediately upon discovering the violation and contacts us.
Scope
This policy applies to the following systems and services:
- *.ncsc.gov.ie (All subdomains)
Prohibited activities
To ensure system stability and user privacy, any testing that impacts system Confidentiality, Integrity, and Availability is strictly prohibited. This includes, but is not limited to:
- Denial of Service (DoS/DDoS).
- Social Engineering: Phishing or physical security attacks against staff, vendors, or customers.
- Data Destruction: Deleting, altering, or corrupting data not owned by the researcher.
- Privacy Violations: Accessing or retaining Personal Identifiable Information (PII) beyond what is strictly necessary to prove a flaw.
Standard Technical Exclusions
The following report types are not eligible for credit:
- Reports of missing security headers (e.g. CSP, HSTS, X-Frame-Options) without a working exploit.
- SSL/TLS best practices (e.g. weak ciphers, expired certificates).
- Reports from automated scanners that have not been manually verified.
- "Banner grabbing" or version disclosure without a functional Proof of Concept (PoC).
Researcher Obligations
We ask that researchers:
- Report Promptly: Notify us as soon as a potential vulnerability is discovered.
- Provide Detail: Use our Vulnerability Report Template to provide clear, technical reproduction steps.
- Maintain Confidentiality: Do not disclose any information regarding the vulnerability to third parties or the public until a fix has been deployed and we have provided explicit authorisation.
- The "Stop Rule": If you encounter sensitive data (PII, financial data), you must stop testing immediately, report the find, and securely delete any local copies.
Our commitment (Remediation Cycle)
When you report a vulnerability to the National Cyber Security Centre, we commit to:
- Acknowledgment: Confirming receipt of your report within 3 business days.
- Verification: Updating you once the flaw has been verified and triaged.
- Remediation: Working to resolve the issue based on a risk-based priority (Critical, High, Medium, Low).
- Recognition: Crediting you on our wall of fame, should you wish to be named.
How to report
Please submit your findings below:
You can also submit your findings via encrypted email
Encrypted Email: cvdreport@ncsc.gov.ie
PGP Key: PGP KEY
PGP Fingerprint: 82E6 671F FE48 9AB9 94B5 F0C9 B242 BF19 B60D B8C8