Responsible disclosure

Vulnerabilities in PGGM's ICT Systems


PGGM considers the security of its systems to be important. Despite all the attention paid to the security of our systems, it is possible that a vulnerability may be overlooked. If you have found a vulnerability in a PGGM system, PGGM would like to hear from you so that the necessary measures can be taken as quickly as possible. With this in mind, PGGM applies the policy below for handling reports of identified vulnerabilities in PGGM’s ICT systems. You may hold PGGM to this policy if you discover a vulnerability in one of its systems and report it. We would like to work with you to better protect the data in our systems.

PGGM expects you to do the following:

  • Send your report as soon as possible after discovering the vulnerability to https://app.zerocopter.com/en/rd/19ff4179-5fef-4bbb-a617-c729168ed0ee.
  • The report must contain information that enables PGGM to reproduce the issue. In most cases, the IP address or URL of the affected system and a description of the vulnerability will be sufficient, but more information may be required for more complex vulnerabilities.
  • Please provide at least an email address or telephone number so that we can work together towards a secure outcome.
  • Do not share information about the vulnerability with others until it has been resolved.
    Handle your knowledge of the security issue responsibly by refraining from any actions that go beyond what is necessary to demonstrate the security issue.

In any event do NOT:

  • Distribute malware; 
  • Copy, modify or delete data in the system. As an alternative, you may create a directory listing of a system;
  • Make changes to the system;
  • Repeatedly gain access to the system or share access with others;
  • Use so-called brute forcing to gain access to systems;
  • Use (distributed) denial-of-service attacks or social engineering.

 

What to expect from PGGM:

  • If, when reporting a vulnerability you have identified in a PGGM ICT system, you comply with the conditions set out above, PGGM will not take legal action against you.
  • PGGM will treat your report confidentially and will not share personal data with third parties without your consent, unless required to do so by law or by a court ruling.
  • PGGM’s supplier will send you an acknowledgement of receipt within one working day.
  • PGGM will respond to a report within three working days with its assessment of the report and an expected date for a solution, if known at that time.

PGGM will keep you informed of the problem solving progress.