Dutch government introduces disclosure guidelines for white hat hackers

Macbook keyboard macro

The Netherlands last week released official guidelines on "hacktivism," as part of an attempt to encourage white hat hackers to responsibly disclose security flaws. The framework, published Thursday, establishes a formal procedure for ethical hackers to follow when reporting IT vulnerabilities, standing in stark contrast to the more fragmented means by which security holes are typically publicized.

"Persons who report an IT vulnerability have an important social responsibility," the Netherlands' National Cyber Security Center (NCSC) said in a release. The NCSC added that some hackers may be reluctant to directly notify an organization after discovering a security flaw, choosing instead to anonymously go public online or via other media forums. Such an approach, according to the Netherlands, would only exacerbate the issue, as it threatens to more widely expose a flaw before it is fixed.

Trust and transparency

The NCSC's guidelines won't have any affect on current legislation, though they do call for companies and organizations to implement more formal channels of communication. One recommendation, for instance, calls for organizations to establish online forms that hackers could use to submit exposed security flaws to the affected company.

The government is also urging companies to agree to not prosecute any hackers who discover IT vulnerabilities, on the premise that doing so would foster trust and facilitate direct communication between the hacker community and the organizations they impact. Likewise, the guidelines would impose strict protocol for white hat hackers to follow, in order to ensure that their actions are truly in the best interest of a company.

It remains unclear whether the Netherlands' proposals will be widely adopted, though they'll likely have an immediate impact on the public sector. In a letter to Parliament, Minister of Security and Justice Ivo Opstelten said he would encourage government offices to adopt and embrace the measures on a wide basis.

The Verge
Log In Sign Up

Log In Sign Up

Please choose a new Verge username and password

As part of the new Verge launch, prior users will need to choose a permanent username, along with a new password.

Your username will be used to login to Verge going forward.

I already have a Vox Media account!

Verify Vox Media account

Please login to your Vox Media account. This account will be linked to your previously existing Eater account.

Please choose a new Verge username and password

As part of the new Verge launch, prior MT authors will need to choose a new username and password.

Your username will be used to login to Verge going forward.

Forgot password?

We'll email you a reset link.

If you signed up using a 3rd party account like Facebook or Twitter, please login with it instead.

Forgot password?

Try another email?

Almost done,

By becoming a registered user, you are also agreeing to our Terms and confirming that you have read our Privacy Policy.



Choose an available username to complete sign up.

In order to provide our users with a better overall experience, we ask for more information from Facebook when using it to login so that we can learn more about our audience and provide you with the best possible experience. We do not store specific user data and the sharing of it is not required to login with Facebook.