Skip to main content
defend Iceland
A policy for responsible reporting of security vulnerabilities

Vulnerability Disclosure Policy (VDP)

A key step towards NIS2 in minutes

Vulnerability Disclosure Policy (VDP)

A Vulnerability Disclosure Policy (VDP) is a policy that gives companies and organisations a formal way to create a simple channel for reporting vulnerabilities. Through such a channel, external parties can send companies and organisations potential security vulnerabilities in their systems. For the many companies that will be classified as critical infrastructure under the NIS2 legislation, Defend Iceland now offers a simple way to establish such a policy as an important part of their vulnerability-management practices.

A VDP defines, among other things:

  • How vulnerabilities can be reported
  • Which systems are within scope
  • How the company responds to reports
  • Clear “safe harbor” rules for reporters acting in good faith
  • A legally clear framework for responsible reporting
  • Rules for the public disclosure of vulnerabilities (Disclosure Policy)

This creates trust, clarity and predictability for both companies and those who discover vulnerabilities.

Vulnerability management is about finding, receiving, assessing, prioritising, fixing and following up on vulnerabilities in information systems. A VDP is a formal way to strengthen an organisation's vulnerability management by enabling a channel through which vulnerabilities can be surfaced, thereby meeting NIS2's requirements for active and continuous vulnerability management.

Set up a VDP in minutes - a key step towards NIS2

Free basic setup - no obligation

  1. 01

    Registration and responsibility

    Register basic information about the company, the responsible party and security contacts. Once registered, we confirm ownership and contacts before the VDP goes live.

  2. 02

    We analyse your digital footprint

    An automatic analysis where you can add, remove and define what is in and out of scope.

  3. 03

    Rules and process

    You can tailor the VDP policy, which is based on international standards (including disclose.io (opnast í nýjum glugga)), that define how vulnerabilities are reported and handled.

  4. 04

    An open reporting channel

    Security.txt, DNS records and a working VDP form ready for use on your website.

Why does a VDP matter?

Every company and organisation has vulnerabilities. The question is not whether they exist - but how you get to know about them. For too many, it is waking up to find the company's data has been taken hostage. Good vulnerability management no longer requires only the use of vulnerability-scanning tools or the occasional security audit; it is equally important to give external parties a defined way to find and report potential security threats.

A VDP simplifies the journey of creating a standardised way to report vulnerabilities, thereby engaging ethical hackers and security experts. For security experts and hackers, this is a defined way to search for security vulnerabilities without fearing sanctions or retaliation from the companies and organisations in question.

With Defend Iceland's VDP solution:

  • Vulnerability reports reach you directly
  • In a secure, organised and legally clear way
  • Hackers have defined and standardised working rules

All companies and organisations that will fall under NIS2 need to have an established process for handling vulnerabilities and disclosing vulnerability information as part of the security of acquiring, developing and maintaining their systems, and a VDP is an important link in that. Likewise, it is important to ensure protection for hackers, and a policy for responsible reporting of security vulnerabilities provides exactly that. This is a simple way to open up disclosure that helps you start small, build trust and strengthen security from day one. A VDP does not permit unrestricted security testing and does not include the payment of rewards for vulnerabilities; it defines only a responsible reporting channel for external parties.

VDP and NIS2

The NIS2 directive emphasises the organised handling of vulnerabilities, clear processes for security incidents, and responsible disclosure in cooperation with external parties.

The directive stipulates that member states and those under the EEA set up a policy for Coordinated Vulnerability Disclosure (CVD), which means that companies falling under NIS2 must be able to receive, analyse and respond to vulnerability reports in an efficient and traceable manner.

A well-defined VDP policy is a simple and effective way to support this requirement, by ensuring a continuous process for the receipt and remediation of vulnerabilities, reducing the likelihood of serious security incidents, and demonstrating proactive risk management in line with NIS2.

NIS2 requires that the relevant parties:

  • Have processes to identify and handle vulnerabilities from external parties
  • Need not fear lawsuits as long as they follow the terms of the VDP policy and act in good faith
  • Can respond to security incidents in a timely manner
  • Demonstrate an organised methodology

A VDP is therefore a strong tool to help companies meet NIS2's requirement for vulnerability management.

There is a distinction between what falls under the obligations of the state/authorities in these matters and what is considered an obligation on entities (critical and important infrastructure).

The role of the authorities

Under NIS2, states are responsible for shaping a comprehensive policy for vulnerability management and for promoting coordinated disclosure of vulnerability information at the national level. National CERT teams play a key role there in monitoring, analysing and sharing information about cyber threats and vulnerabilities, as well as communicating with European institutions such as ENISA.

Obligations of entities (critical and important infrastructure)

Entities that fall under NIS2 (both essential and important entities) must meet the requirements of Article 21 of the directive on cybersecurity management systems. It specifically stipulates that security measures must cover:

  • the handling of vulnerabilities
  • and the disclosure of vulnerability information

This management must be active, documented and part of a regular methodology.

Frequently asked questions

A Vulnerability Disclosure Policy (VDP) is a policy that gives companies and organisations a formal way to create a simple channel for reporting vulnerabilities. Through such a channel, external parties can send companies and organisations potential security vulnerabilities in their systems.

Setting up a VDP, where you can create your policy and publish it in a standardised way, is free.

A VDP is an open reporting, communication and process framework that allows anyone to report vulnerabilities in a secure and responsible way.

A bug bounty platform goes a step further, where registered ethical hackers are continuously searching for vulnerabilities in the systems of companies that have such a platform. The ethical hackers are paid reward money for approved vulnerabilities according to severity level.

The purpose is to create strong incentives to find such vulnerabilities, whereas a VDP is just a way to report such vulnerabilities.

With a VDP, parties can send you vulnerabilities in a defined way, but a bug bounty platform is about actively searching for them and having them assessed by an independent party.

Yes. Internal and external security testing is important, but it is a point-in-time measurement. A VDP is a continuous, open policy. Vulnerabilities can arise between tests. External parties can see things that tests miss. A VDP ensures that if someone becomes aware of a vulnerability between tests, there is a clear, secure and responsible way to report it.

No, a bug bounty platform goes a step further than a VDP and includes everything a VDP does, and more. A bug bounty platform is built on the same foundations as a VDP: clear rules, a defined scope, the secure receipt of vulnerabilities and processes for handling them.

When a vulnerability arrives through the bug bounty platform, a vulnerability committee reviews and assesses it. The committee writes a report and provides information on remediation. The work is therefore not extensive for the customer.

All reports, whether they arrive through a bug bounty platform or a VDP, must always go into the same internal vulnerability-management process. A bug bounty platform is thus an addition to, but not a substitute for, the internal processes that NIS2 requires.

A key factor in meeting NIS2 compliance with regard to a VDP is having clear vulnerability management. It is therefore important to have a defined process that takes over after a vulnerability report arrives. Without vulnerability management, the compliance is not valid.

When a vulnerability arrives through the VDP, it should go into a defined vulnerability-management process:

1. Receipt and confirmationThe vulnerability is received securely and it is assessed whether it is valid and relevant.

2. Risk assessment and prioritisationIt is assessed how serious the vulnerability is, which systems it affects and what impact it can have.

3. RemediationThe relevant team fixes the vulnerability or takes mitigating measures according to internal methodology.

4. Follow-up and closureIt is confirmed that the vulnerability is genuinely fixed and the case is closed with a record for traceability.

5. Communication (optional)Where applicable, the reporter is given confirmation or thanks for the report.

A VDP ensures that vulnerabilities arrive through the right channel, but vulnerability management ensures that they are responded to correctly, and it is important that all parties can absorb vulnerabilities reported through a VDP into their vulnerability-management process.

If any questions arise, please contact us here

On the contrary, a VDP reduces legal risk by setting clear rules for vulnerability reporting and responsible responses. A VDP reduces the likelihood of unauthorised actions, misunderstandings or disputes between the company and the person reporting a vulnerability.

Oversight of vulnerability reports should be in the hands of a defined responsible party; in most organisations, oversight lies with the security teams.

1. You apply for a VDP policy

2. Defend Iceland reviews and confirms the registration

3. The onboarding process is completed and the VDP is set up

4. You then receive all the relevant information to publish on your website

Apply today

A Vulnerability Disclosure Policy (VDP) is a simple step that delivers a lot.

Meet NIS2's requirements, improve security and build trust.

Do you have questions? Please get in touch here

Report a vulnerability