Responsible Disclosure

Kantoorpand KWF

Klik hier om naar de Nederlandse versie te gaan

Report vulnerabilities in our IT systems

At KWF Dutch Cancer Society, we take the security of our systems very seriously. Despite the care we take to protect our IT environment, vulnerabilities may still exist.

If you have discovered a vulnerability in one of our systems, we would appreciate hearing from you so that we can take appropriate measures as quickly as possible. We would like to work together to better protect our donors, partners, employees and IT systems.

What can you report?

You can report any type of security vulnerability affecting our IT systems. Please contact us as soon as possible after discovering the issue.

How can you report a vulnerability?

Please send your findings to [email protected]. To help ensure that sensitive information does not fall into the wrong hands, please encrypt your report using the PGP key provided at the bottom of this page.
Once we receive your report, our security specialists will review and validate your findings to determine whether a genuine vulnerability exists.

What happens after you submit a report?

Our security team will investigate your report and contact you within 3 workdays. We may ask for additional information about the vulnerability, how it was discovered, and any steps required to reproduce the issue. We will also keep you informed about the progress of our investigation.

What we ask of you

When reporting a vulnerability, we ask that you:

  • do not exploit the vulnerability beyond what is strictly necessary to demonstrate its existence. For example, do not access, download, modify, or delete data that doesn't belong to you
  • do not disclose the vulnerability to others until it has been resolved, and permanently delete any confidential information obtained through the vulnerability once it has been fixed
  • do not use techniques involving physical attacks, social engineering, distributed denial-of-service (DDoS) attacks, spam, or attacks against third-party applications or services
  • provide sufficient information to enable us to reproduce the vulnerability so that we can resolve it as quickly as possible. In most cases, the affected URL or IP address together with a description of the vulnerability will be sufficient. More complex vulnerabilities may require additional information

What we promise

If you comply with the guidelines described above, we will:

  • not take legal action against you in relation to your report
  • treat your report confidentially and will not share your personal information with third parties without your permission, unless required by law. You may also submit your report under a pseudonym
  • keep you informed of the progress of our investigation and remediation efforts
  • acknowledge you as the discoverer of the vulnerability in any public communication about the issue, if you would like us to do so

We make every effort to resolve reported vulnerabilities as quickly as possible. We would appreciate being involved in any public disclosure of the vulnerability after it has been resolved.

Legal considerations

During your research, you may unintentionally perform actions that could be considered unlawful. If you act in accordance with the guidelines set out in this Responsible Disclosure Policy, KWF will not file a criminal complaint or seek compensation for any damage arising from your report.

Please note, however, that the final decision whether to prosecute rests solely with the Public Prosecution Service. KWF cannot make that decision and therefore cannot guarantee that you will never be prosecuted if your research involves actions that are considered criminal offences.

This Responsible Disclosure Policy is based on the guideline published by the National Cyber Security Centre of the Dutch Ministry of Justice and Security

PGP

 

-----BEGIN PGP PUBLIC KEY BLOCK-----

 

xsFNBFYU7XcBEACyVobaq7zJx8jN+Cou0o+pVaLipv+4oJh/cHuOIF/sdwox
I+v9tan5uR2zfE47mbbDxlV0aY2v0XYs8g/RCYGtOhtLEJhwl7bMV8k5cONp
KosN6vaUZFqQsjzRCEAvhiJe3ap5FbLygTWu/G7CmHinLiyovOrgkegNm0Kv
k0e8AABLHjfdHOa4nmwRJoDtL5aYGT+4X3suAiWNqNb1sBrt44glbnz1O9W4
qVn1APYE7TIh97ubA9XJBb7iwdkdLoPUu0wcZ3ZGV6Wh1P/NacZwkCAGWaJI
Bb8dnqkgPa6aGFm6CETpuuvLCbzLtpX2T7T2k7YOEvvjQJBbydybBEQVW21m
J+DTeaSkwkNL6GWG2H619km6w4LbwWWMp20bnDgNsl77/N3MUZtVyYiVrMEC
VGnhJP1+bWT9mlOWQ4Af4SVLUkUqWawrZRzQf9NUd/7LEhPW/ryK1PX3k7Ub
xLzcKl/DIMnrXljwEZFBNNvTRHiJoYOm72yWFhIdvkT+Wg0K4noqsZB4CzPS
tWjUTHW+EZT+B+SX34w1UdctKVCVILnsvtZNB8tgh0QEgmnd/51pi0c70mGB
G7QWEc2l81H2jpPRwQmfzsDdtCxGJu+6S5r20kg8tLzxkgiFAL/2fKqQNIvo
lvU8+b6ycA+TfTzgiUYuhgvMc2BNdDTsYMsAXwARAQABzSMic2VjdXJpdHlA
a3dmLm5sIiA8c2VjdXJpdHlAa3dmLm5sPsLBdQQQAQgAKQUCVhTtfgYLCQgH
AwIJEFQAJylSkmVvBBUIAgoDFgIBAhkBAhsDAh4BAADjsA/+OoaPJ2zOI9ui
TxnI5c8jSX+KlsYFBan+XNY1J1JdaNObDdbxJDXUjqo0EGDAwq1Z0jQpk1mT
ZL4VD2F0Qak9Fa4NpyX1hFi4XJF7YKxxxfnM5WOK9x5Totgk8DLBJeUmXWjH
YFLlhtEbPegZxbhE1F/EnK/eLyVq3162ylD1V8Pu2RsXCZzMvAR7vmcJ6AOx
4tTbp1hPxLsaxMS3jDQ7sthn2aScq83v5gMq0OY4dtO8vWY36GsTZS5pzQUX
hrWulKcelCeaBWuy4U38IWrMEDs5iE3EIhV6c/9w5ZtZZrN/wVhSSON3oVmA
h/AlNKY0n/xssePdAwRRLJpudHX10j8NJ7kmwvfxxFGJ23IIzJ9KzuFAMZkh
qELEvaZ+jG4YmhMz4a/4TxqzLHIWn0NRFc0XhncRSb/Ktg5GC8ffjIwwBQ3b
Z8ExTUSkHeb5my7cS3qrBFTn12UK1CfAfthO29lt/DhtOOAk6IghBoLGlX03
iaUuy4foLutSNZOcV0OF9tkdL7SYqze0Ks29JrOnzYwe98+6xZWU8Tit/9DP
uND1Fp6n9qkSLbNm8nhbBKz0rNdDUt4+ZiBUlSzgRe6kexowceuZr8okBlsz
ZseltQGYILAfshQMl9DXM5VsvDp76E8IceTdchOI8WPKSm8WPf1k6cIqTw+p
ONqLTXFtfHzOwU0EVhTtdwEQAJehfuQEclmP8tIxgAxQauMtCCRIhG66y8QG
p8QsHKxqerXkxBHzS2ia0Edyen3p26/LklqdlEBGZwaICALXySx8HXbt7jbz
BK9Q+jST6vnHU1OzJmscs+mhUDHQQtQpjvzAYWIPs9/33wbHEp7MK8tF0oGI
DHG3AzBH9y2sHlUlIYcM+dyAyiF9n+ZSF7IxPDRUiyWgXAdXKueTIXCExUwV
WKobJLTFtbOdFgwqT9fizilsu4GCP+WZ2mpueR/tdPYmlsjEwzCKi4E2pAiG
xN5jySU49PJLdO9Qy6JOhCbzoK8616kHY5f9WQNRkinhP7ykT96KHJcMfi1h
yb3JFMkvSjWpVRTUyQ5pvJifLQEX52EpUZCGe23IpOSGsw2yzR/JkK2UWDQx
9K7VLZHlBbNJwlzeXjvd83W1/SjlmyNdRg2UumFcDSgsba5ydkxRb+zehswQ
ZSGbVl8M1WiTQxPrg1Kw8vqhI96uAh9vjaKntl8WR+iKiEJmTF1vV2DpzHGZ
ug/x0yOLUFh/S1A1uG9Aexp8Z18818ovsl9Pd8SrJ9bxMIM1oebQfRKg6H6/
8+dbh7/NvRa5XsZFOEuYHyLut9H1xfOlL2aUyUnUQSqd+dl5tL97Bd6WcnQW
c5zGQSOeWh5vRZUjMds96RrrWvX2T+4e6x7fghAAdG9l6em/ABEBAAHCwV8E
GAEIABMFAlYU7YAJEFQAJylSkmVvAhsMAADftRAAk9HRvSbha5cA39XKDYFw
fzOCgjwOB1dDF4aNZs08VdXz5mVswsZTYkbegR7ojPphDuyqdj/HKZZ57Mjc
K2md9vUu3wOe7bsMxTC2o6dPkRAq6ANMzU7Mw8/+zXDuzqO2XUW3Pe9Y+VCF
O4mql2kR2a4GnASaUbcVXk53pcx2ZpEN6tOnNEItdkF+4lzydhhcuvg2J56K
H1T5hrx7wyt9LaBKYS1J8PYu57uS/FBlmJODDV7yGbmQTl2tG55LNm59qj5h
dDcGEtABZAOdyCDCm0ijbJZLGBJSLCDorjz/0S5qFo49MA2AGFs98V4Asxiu
UD8odjN+oi9l3tLuKeuT6L2f4+OLdrGQrPv8jlIu6P03wYzyjF3EpH1FJU3C
7UNVSJU6QspR+MVIV5AAQFJFTv43PPVJYFoSLED2lfjppqnq6iZP1f7Cn17U
eLJO7EbwNdML6aK2R/mD92CC8ja+Vro8DA88mbeVUdiqbEv/A70vwCCs8LgE
0Fn8oLZScaMiwg1vS880F2ndbUEcHvPLdOrAAVnAo2CPBwMKfSKHopH5wKPg
Ninf6HdMO6JBzi4w8CD6TuEMv2LQ6Kg2rKgj4JeiO1vyW5GBmzWn4XG5U2xi
xlqtCdBJz3nKnxvi+DTbXETg3yNm/8msa6DqsZbbUAodl6bj38/Cem2FXVg+
MiE=
=n1ls
-----END PGP PUBLIC KEY BLOCK-----