UK PSTI? You’ll need a Vulnerability Disclosure Program!
ID: 4f42fce9-794c-5f37-9e96-f4357250fe82
STIX ID: report--4f42fce9-794c-5f37-9e96-f4357250fe82
Feed Name: Pen Test Partners Blog
This guide explains how organizations selling smart devices in the UK can establish an effective Vulnerability Disclosure Program (VDP) to comply with the Product Security and Telecommunications Act, advising on publishing a security.txt (RFC 9116), drafting a tailored disclosure policy, assigning accountable roles, empowering and training teams, and stress-testing the process. It warns against common pitfalls such as using NDAs, issuing legal threats, and overreliance on bug bounty platforms, emphasizing clear, transparent communication and regular updates to researchers.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
