NCSC CVD Policy

At the National Cyber Security Centre, the security of our systems and the privacy of our users are of paramount importance. We value the work of the security research community and believe that a collaborative relationship with researchers is vital to maintaining a resilient digital environment.

If you discover a security vulnerability in one of the National Cyber Security Centre systems, you can report the identified vulnerability to us below. This kind of report is known as a Coordinated Vulnerability Disclosure or CVD. In your report, please describe as clearly as possible how the problem can be reproduced as this will help to accelerate the resolution process.

Safe Harbour

The National Cyber Security Centre will not initiate legal action against any individual or entity that conducts security research and discloses vulnerabilities to us in accordance with this policy. We consider any activity conducted in good faith and within the defined scope of this policy to be activity carried out with our authority and therefore to be "lawful authority" under the Criminal Justice (Offences Relating to Information Systems) Act 2017. That said, ultimately it is a matter for any individual or entity to obtain its own independent legal advice to satisfy itself as to the lawfulness of its intended activities to ensure that no criminal offence under the Criminal Justice (Offences Relating to Information Systems) Act 2017 would be committed.

We waive any claims against researchers for accidental, good-faith violations of this policy, provided that the researcher ceases activity immediately upon discovering the violation and contacts us. 

Scope

This policy applies to the following systems and services:

Prohibited activities

To ensure system stability and user privacy, any testing that impacts system Confidentiality, Integrity, and Availability is strictly prohibited. This includes, but is not limited to:

Standard Technical Exclusions

The following report types are not eligible for credit:

Researcher Obligations

We ask that researchers:

Our commitment (Remediation Cycle)

When you report a vulnerability to the National Cyber Security Centre, we commit to:

How to report

Please submit your findings below:

You can also submit your findings via encrypted email

Encrypted Email: cvdreport@ncsc.gov.ie

PGP Key: PGP KEY

PGP Fingerprint: 82E6 671F FE48 9AB9 94B5 F0C9 B242 BF19 B60D B8C8