At ICT Group, we believe it is essential that our systems, networks, and products are secure and meet the highest security requirements. Despite all the measures we take, it is still possible that there is a weak spot in one of these systems.

Report a vulnerability

If you find a weak spot in one of these systems or products, ICT Group would like to hear from you as soon as possible. This enables us to act swifty and take additional measures to improve security as stated in our Coordinated Vulnerability Disclosure policy. Complete the form below to submit a CVD report.

Report vulnerability (CVD)

What does your report relate to? *
In which environment was the vulnerability found?

The vulnerability

One file only. 10 MB limit. Allowed types: txt, pdf, docx, xlsx

Impact and urgency

Your assessment of the severity
As far as you know, is the vulnerability being actively exploited? *
Has the vulnerability already been shared elsewhere or made public?

Your details

You are reporting as

Coordination and closure

For a scheduled date: mention this in the description so we can coordinate the timing with you.
We will handle your data confidentially. Read our privacy statement.

1. Purpose of this policy

ICT Group attaches great importance to the security of its systems, websites, networks and products. Despite the precautions we take, vulnerabilities may still occur.

If you discover a vulnerability, we appreciate you reporting it to us so that we can take appropriate action.

This Coordinated Vulnerability Disclosure Policy describes the conditions under which you may conduct research and report a vulnerability. Its purpose is to enable vulnerabilities to be reported responsibly, without creating unnecessary risks for ICT Group, its customers, employees, users, or other stakeholders.

2. Who is this policy intended for?

This policy is intended for anyone wishing to report a potential vulnerability, including independent security researchers, ethical hackers, customers, users, suppliers, CERT/CSIRT organisations, supervisory authorities and other stakeholders.

The policy applies to reports concerning ICT Group systems, websites, networks and products, insofar as they are publicly accessible or can reasonably be considered within the scope of the report.

3. Safe harbour for security researchers

Under this policy, ICT Group grants limited permission to conduct research that is reasonably necessary to identify and demonstrate a vulnerability.

If you act in good faith and comply with the conditions of this policy, ICT Group will not take legal action against you for researching or reporting the vulnerability.

This safe harbour applies only to actions necessary to demonstrate the existence of the vulnerability. If it is found that you went beyond what was necessary, ICT Group reserves the right to take appropriate measures.

4. What we ask of you

To enable us to assess a report carefully, we ask you to:

  • Report the vulnerability as soon as possible using the reporting form.
  • Provide sufficient information for us to reproduce, analyse and assess the vulnerability.
  • Include at least a description of the vulnerability, the relevant URL, application, system, product or IP address, and a description of the actions performed.
  • Provide your contact details so that we can ask follow-up questions if necessary.
  • Keep information about the vulnerability confidential until it has been remediated or other arrangements have been agreed.
  • Do not view, copy, modify, delete or retain information belonging to customers, employees, users or other stakeholders unless this is necessary to demonstrate the vulnerability.
  • Stop immediately if you unintentionally gain access to data, functionality or systems beyond what is necessary for the research.

5. What is not permitted

To prevent damage, disruption and risks to ICT Group and its customers, the following activities are not permitted:

  • Conducting denial-of-service attacks or other activities that may affect the availability of systems or services.
  • Using social engineering, phishing or attempts to gain physical access.
  • Modifying, deleting or copying data.
  • Adding, modifying or deleting accounts, configurations or system settings.
  • Installing malware, backdoors or other software.
  • Conducting brute-force attacks or using automated means to collect large amounts of data.
  • Exploiting a discovered vulnerability beyond what is necessary to demonstrate its existence.
  • Sharing or disclosing information about the vulnerability before arrangements have been agreed with ICT Group.

6. What you can expect from ICT Group

If you submit a report that complies with this policy, you can expect the following from ICT Group:

  • We will acknowledge receipt of your report within three working days.
  • We will assess the report and contact you if additional information is required.
  • We will treat your report and personal data confidentially.
  • We will not share your data with third parties without your consent, unless required to do so by law.
  • We will inform you if the vulnerability has already been reported.
  • Where possible, we will keep you informed of progress, insofar as this is compatible with the investigation and any legal or contractual obligations.
  • If your report is found to be valid, ICT Group may, at its sole discretion, offer an appropriate form of appreciation or recognition. No rights may be derived from this.

The technical assessment of a report is performed by ICT Group. The outcome of this assessment is binding.

7. Reports concerning ICT Group products

Some reports concern software, platforms, devices or other products developed or supplied by ICT Group. If your report concerns an ICT Group product or software solution, we ask you to provide additional information where possible.

Information

Examples

Product nameName of the ICT Group product or software solution.
Version, build or firmware informationFor example, 4.2.1 or 20260115
EnvironmentProduction environment, test or acceptance environment, own laboratory or research environment, or other.
ReproducibilitySteps that demonstrate the vulnerability, including a proof of concept where this can be done safely.
ReferencesAny CVE, advisory or other relevant references.
Impact and urgencyYour assessment of the severity and any indications of active exploitation.
Supporting informationRelevant documentation, screenshots, log entries or attachments.

This information helps ICT Group investigate the report more efficiently and, where applicable, comply with legal obligations relating to digital products.

8. Impact, urgency and active exploitation

In the reporting form, you can indicate how severe you consider the vulnerability to be and whether there are indications that it is being actively exploited.

Your assessment helps us prioritise the report. ICT Group will always conduct its own assessment of the severity, impact and required follow-up.

9. Responsible disclosure

We understand that security researchers may sometimes wish to publish their findings. We ask you not to publish or share information about a vulnerability with others until:

  • ICT Group has had the opportunity to investigate the vulnerability and take appropriate measures; and
  • The timing and content of any disclosure have been coordinated.

If you intend to publish your research, please indicate this when submitting your report so that we can coordinate the disclosure with you.

10. Privacy and confidentiality

ICT Group will treat your report and personal data confidentially. Your data will be used to assess the report, communicate with you and take appropriate follow-up action regarding the vulnerability.

We will not share your personal data with third parties without your consent, unless required to do so by law. More information about the processing of personal data is available in ICT Group’s privacy statement.

11. Submitting a report

You can report a vulnerability using the CVD reporting form on the ICT Group website. Use the form to indicate whether your report concerns:

  • ICT Group systems or websites; or
  • An ICT Group product or software solution.

Where possible, include relevant technical details, reproduction steps and any attachments. This will help us assess the report more quickly and carefully.