https://portswigger.net/daily-swig/belgium-launches-nationwide-safe-harbor-for-ethical-hackers The Daily Swig [ ] ( ) ( ) ( ) ( ) ( ) ( ) Latest threats Bug bounty For devs Deep dives More About Web security vulnerabilities Network security vulnerabilities Cloud security Zero-day news Supply chain attacks View all web security news Prototype pollution Prototype pollution project yields another Parse Server RCE Prototype-pollution Bug bounty news VDPs Bug Bounty Radar View all bug bounty news Bug Bounty Radar The latest programs for February 2023 Bug bounties DevSecOps Security best practices Dev stack tech View all dev related news All Day DevOps AppSec engineer keynote says Log4j revealed lessons were not learned from the Equifax breach DevOps Deep dives Interviews View all of the latest features Infosec beginner? A rough guide to launching a career in cybersecurity cyber-career Industry news Enterprise security news Web hacking tools Events View all infosec industry news Cybersecurity conferences A schedule of events in 2022 and beyond More topics Belgium launches nationwide safe harbor for ethical hackers Adam Bannister 15 February 2023 at 16:49 UTC Updated: 16 February 2023 at 11:11 UTC Legal Policy and Legislation VDP Twitter WhatsApp Facebook Reddit LinkedIn Email New legal protections for security researchers could be the strongest of any EU country Belgium launches nationwide safe harbor for ethical hackers UPDATED Belgium has become the first European country to adopt a national, comprehensive safe harbor framework for ethical hackers, according to the country's cybersecurity agency. The Centre for Cyber Security Belgium (CCB) has announced a mechanism that protects individuals or organizations from prosecution - contingent on certain "strict" conditions being met - when they report security vulnerabilities affecting any systems, networks, or applications located in Belgium. The framework applies regardless of whether vulnerable technologies are owned by private or public sector organizations. Terms and conditions According to the procedure set out in a national coordinated vulnerability disclosure policy (CVDP) on its website, the CCB - Belgium's computer emergency response team (CSIRT) - can now receive reports on IT vulnerabilities that give security researchers legal protection providing the following conditions are met: * Notify the owner of the vulnerable technology as soon as possible and at least at the same time as the CCB * Submit a written vulnerability report to the CCB as soon as possible in the prescribed format * Act without fraudulent intent or intention to harm * Act strictly in a necessary and proportionate manner to demonstrate the existence of a vulnerability * Do not publicly disclose information about the vulnerability and vulnerable systems without the CCB's consent CCB also has guidelines, adopted in 2020, that encourage organizations in Belgium to adopt their own CVDP or bug bounty program. RELATED HackerOne encourages customers to adopt standard policy to protect hackers from legal problems Hackers need not notify the CCB where an organization already has a VDP, but may choose to do so if the vulnerability affects other organizations without VDPs, or "if difficulties arise" with disclosure and remediation. In common with most VDPs and bug bounty programs, offensive techniques such as phishing, social engineering, and brute force attacks "may be considered as disproportionate and/or unnecessary actions". Elsewhere in the EU A 2022 EU Agency for Cybersecurity (ENISA) report on national coordinated vulnerability disclosure (CVD) policies within the bloc revealed that France, Lithuania, and the Netherlands were also "undertaking CVD policy work and have implemented policy requirements". However, according to Valery Vander Geeten, legal officer at the CCB, Belgium's policy is the most comprehensive yet. He told The Daily Swig that the Netherlands indicates "that the Public prosecutor Office will not prosecute ethical hackers", France and Slovakia fall short of "full legal protection", and that Lithuania's legal safe harbor is "limited to critical infrastructure". He also emphasized that it protects vulnerability reporters regardless of whether they work for the organization whose technology is affected. Numerous other EU member states are developing, or planning to develop, similar nationwide protections for hackers. Far from the norm While Telenet, Brussels Airlines, and Port of Antwerp are among Belgian companies with VDPs, it is far from the norm to have one. Even among the Fortune 500, less than 20% of blue chips apparently had VDPs as of 2021 (albeit this had risen from 9% in 2019). "I do hope that legislation like this will have the 'GDPR'-effect that will effectively force companies to adopt this," Inti De Ceukelaire, head of hackers at Belgium-based bug bounty platform Intigriti, told The Daily Swig. "Paradoxically, most security researchers are now delivering value and improvements to companies that want to listen and are already on board with the latest security trends, such as a VDP. "Applying that to companies that are completely new to this will have interesting results, I believe. In the Netherlands, where they have similar legislation, a hacker that goes by the name Victor Gevers (0xDUDE) on Twitter has already reported 5,000 vulnerabilities under this." This article was updated on February 16 to clarify certain terms and terminology of the CVDP DON'T MISS IoT vendors faulted for slow progress in setting up vulnerability disclosure programs Legal Policy and Legislation VDP Pen Testing Hacking News Vulnerabilities Hacking culture Industry News Enterprise Organizations Bug Bounty Compliance Core Adam Bannister Adam Bannister @Ad_Nauseum74 Twitter WhatsApp Facebook Reddit LinkedIn Email This page requires JavaScript for an enhanced user experience. Latest Posts We're going teetotal - It's goodbye to The Daily Swig 02 March 2023 We're going teetotal - It's goodbye to The Daily Swig PortSwigger today announces that The Daily Swig is closing down Bug Bounty Radar The latest bug bounty programs for March 2023 28 February 2023 Bug Bounty Radar The latest bug bounty programs for March 2023 Indian gov flaws allowed creation of counterfeit driving licenses 28 February 2023 Indian gov flaws allowed creation of counterfeit driving licenses Armed with personal data fragments, a researcher could also access 185 million citizens' PII Related stories This page requires JavaScript for an enhanced user experience. Bug Bounty Radar The latest bug bounty programs for March 2023 28 February 2023 Bug Bounty Radar The latest bug bounty programs for March 2023 Indian gov flaws allowed creation of counterfeit driving licenses 28 February 2023 Indian gov flaws allowed creation of counterfeit driving licenses Armed with personal data fragments, a researcher could also access 185 million citizens' PII Password managers part II A rough guide to enterprise secret platforms 27 February 2023 Password managers part II A rough guide to enterprise secret platforms Chromium bug allowed SameSite cookie bypass on Android devices 27 February 2023 Chromium bug allowed SameSite cookie bypass on Android devices Protections against cross-site request forgery could be bypassed Burp Suite Web vulnerability scanner Burp Suite Editions Release Notes Vulnerabilities Cross-site scripting (XSS) SQL injection Cross-site request forgery XML external entity injection Directory traversal Server-side request forgery Customers Organizations Testers Developers Company About PortSwigger News Careers Contact Legal Privacy Notice Insights Web Security Academy Blog Research The Daily Swig PortSwigger Logo Follow us (c) 2023 PortSwigger Ltd.