Responsible disclosure for companies: a guide for handling your first report
By Kike Gandia · Co-Founder & CEO, OSCP
If a security researcher has just sent you a vulnerability report and you don't know what to do, you're reading the right article. Responsible disclosure is the process by which researchers notify companies of vulnerabilities before publishing them. How you respond in the next few hours can determine whether that vulnerability gets handled well or turns into a public incident.
What to do in the first 24 hours
When you receive an unexpected vulnerability report:
1. Don't ignore the message. Ignoring a security report is the worst possible response. The researcher either has a real vulnerability or doesn't — but the only way to find out is by responding.
2. Acknowledge receipt immediately. An email confirming you've received the report and are reviewing it. You don't need a technical answer yet — just confirmation that the channel works and someone is looking at it.
3. Don't threaten the researcher legally. The vast majority of people who report vulnerabilities do so in good faith. A legal threat destroys your reputation in the security community and can create an incentive for them to publish immediately.
4. Assess whether the vulnerability is real. Have someone technical review the report. If you have no one internal, consider urgent external support.
How to communicate with the researcher
Communication with the researcher should be:
- Professional and respectful: the researcher is doing you a favor, regardless of how they got in touch.
- Clear: no ambiguity about the report's status and next steps.
- Timely: late responses create uncertainty and the temptation to publish.
Recommended acknowledgment message:
"Thank you for reaching out and for the time you spent investigating this. We've received your report and are reviewing it. We'll get back to you on technical validation within [X business days]. If you need any additional information, we'll stay in touch."
What to communicate once you validate the vulnerability
If the report is valid:
- Confirm you've verified the vulnerability.
- Share an estimated resolution timeline (without committing to impossible dates).
- If the researcher wants to publish the finding, propose a coordinated disclosure process: agree on a publication date for once the patch is deployed.
- Consider public recognition: a Hall of Fame entry or a mention in the advisory is highly valued in the community.
If the report isn't valid:
• Explain technically why it isn't a vulnerability.
• Avoid generic responses: "this is expected behavior" without a technical explanation convinces no one.
After the incident: build the process before the next report
After handling the first report, you have all the context you need to build a formal process:
- Define an official intake channel (security@ email, web form, platform).
- Draft a responsible disclosure policy and publish it.
- Set internal response SLAs.
- Assign an owner for the process.
- Consider outsourcing triage if you don't have internal capacity.
The goal is for the next report to come through an expected channel, follow a defined process, and reach someone who knows what to do with it.
FAQ
Am I legally required to respond to a vulnerability report?
It depends on your sector and applicable regulations. NIS2 and the Cyber Resilience Act establish vulnerability management obligations. GDPR may require notifying authorities if the reported vulnerability led to a data breach. In any case, not responding is never the right answer.
What do I do if the vulnerability has already been exploited?
If there are signs the reported vulnerability has already been exploited, activate your incident response process. Prioritize containment and forensic analysis. Communication with the researcher can wait a few hours while you assess the scope of the incident.
Do I have to pay the researcher who reported the vulnerability?
If you don't have a bug bounty program with a published reward table, you have no obligation to pay. Non-monetary recognition (a public mention, a Hall of Fame entry) is perfectly valid. If you want to incentivize future reports, you can make a voluntary payment or formally announce a bug bounty program.
Related service
vulnerability report triage and management service