Live · Tue, Jul 21, 2026 · 15:11 UTC Block 843,917 Fees 14 sat/vB Fear & Greed 72 · Greed
Newsletter Pro Terminal Sign in
ITop Field News.
Subscribe →
Live · 15:11 UTC Block 843,917 F&G 72
Cybersecurity Cybersecurity desk

Vulnerability disclosure in Australia: how responsible disclosure actually works

Vulnerability disclosure in Australia sits at the intersection of ethics, law, and operational urgency. Here is a clear breakdown of how responsible disclosure works and what IT teams need to get right.

Close-up of hands typing on a laptop displaying cybersecurity graphics, illuminated by purple light.

Photo by AI25.Studio Studio on Pexels

Vulnerability disclosure in Australia has never been more consequential. Researchers and IT teams regularly uncover flaws in software, infrastructure, and third-party systems, and the decisions made in the hours after discovery can determine whether a vulnerability gets quietly patched or becomes front-page news. Yet despite its importance, responsible disclosure is widely misunderstood, with many organisations lacking any formal policy at all.

What responsible disclosure actually means

Responsible disclosure (sometimes called coordinated vulnerability disclosure, or CVD) is the practice of privately reporting a discovered vulnerability to the affected vendor or organisation before making it public. The idea is straightforward: give the vendor enough time to produce and release a fix, then disclose the details so the broader community can protect itself. In practice, it involves a chain of trust, deadlines, and negotiation that frequently breaks down.

The two most widely cited models are responsible disclosure and full disclosure. Responsible disclosure keeps the details private during remediation. Full disclosure publishes everything immediately, on the theory that public pressure is the only reliable way to force vendors to act. Most Australian security practitioners sit firmly in the responsible disclosure camp, aligning with guidance from the Australian Signals Directorate and international norms established by bodies such as CISA and the UK's NCSC.

The legal grey zone in Australia

Australian law creates genuine complexity for security researchers. The Criminal Code Act 1995 (Cth) contains offences related to unauthorised access to computer systems, and the line between legitimate security research and criminal conduct is not always clear. A researcher who discovers a vulnerability by probing a system without explicit permission may have technically violated the law, even if their intent was entirely benign.

Unlike the United States, Australia does not yet have a formal "safe harbour" framework that explicitly protects good-faith security researchers from prosecution. This means that even well-intentioned disclosure can carry legal risk. Several prominent Australian researchers have spoken publicly about the chilling effect this creates, and there have been calls for legislative reform to introduce clearer protections.

In the meantime, Australian organisations are encouraged to publish their own vulnerability disclosure policies (VDPs), which set out the scope of authorised testing and the process for reporting findings. A well-written VDP offers a degree of implied consent and significantly reduces the legal ambiguity for researchers who follow it. The ACSC's advisory framework provides context for how government-aligned organisations are expected to handle incoming vulnerability reports.

How the disclosure timeline works

Once a vulnerability is discovered and a vendor is notified, the clock starts. The most widely accepted disclosure deadline is 90 days, popularised by Google Project Zero. Under this model, if a vendor has not released a patch within 90 days of private notification, the researcher publishes the details regardless. Some researchers apply a shorter 45-day window for actively exploited vulnerabilities.

In practice, the timeline negotiation can be fraught. Vendors sometimes request extensions, dispute the severity of the finding, or go silent altogether. Researchers face the uncomfortable choice of granting more time (and potentially leaving users exposed longer) or holding firm and publishing details that attackers might weaponise before a patch is available.

A few principles help navigate this:

  • Document every communication with the vendor from the first contact, including dates and response times.
  • Set a clear initial deadline in the first notification, not after an impasse develops.
  • Consider engaging a coordinating body such as the ACSC, CERT Australia (now part of ASD), or a specialist vulnerability coordination service if a vendor is unresponsive.
  • Where a vendor is a government agency, the Protective Security Policy Framework (PSPF) and the Essential Eight obligations create additional pressure to remediate promptly.

What organisations should have in place

For organisations on the receiving end of a disclosure, a formal VDP is non-negotiable at any meaningful scale. A credible policy should clearly describe the scope of authorised research, provide a dedicated and monitored contact channel (a security@ email address at minimum), commit to acknowledgement within a set timeframe (48 to 72 hours is standard), and outline how and when the organisation will communicate its remediation progress.

Bug bounty programmes extend this further by offering financial rewards for valid findings. Platforms such as HackerOne and Bugcrowd have Australian clients and provide the infrastructure for triaging reports, communicating with researchers, and tracking remediation. For organisations that are not ready to run a public bug bounty, a private programme (invitation-only, with a small group of trusted researchers) offers many of the same benefits with less operational overhead.

Internal patch management matters here too. There is little point inviting responsible disclosure if the organisation cannot act on what it receives. Teams that already struggle with patch management backlogs will find that incoming vulnerability reports compound rather than reduce their exposure.

The ACSC's role in coordinating disclosures

The Australian Cyber Security Centre plays an active coordination role when disclosures involve critical infrastructure, government systems, or vulnerabilities with national significance. Researchers who discover something of this nature can contact the ACSC directly; it has the authority and relationships to facilitate remediation across multiple affected parties where a vulnerability affects shared infrastructure or widely-deployed Australian software.

The ACSC also publishes advisories when a CVE is actively exploited in the wild, which effectively forces the hand of any organisation that has not yet patched. For IT teams, monitoring ACSC advisories is one of the most practical early-warning mechanisms available, particularly for vulnerabilities in common enterprise platforms.

Where things go wrong

Disclosure failures tend to cluster around a few predictable patterns. Vendors that lack a dedicated security response team often route disclosures to general support inboxes, where they sit unread. Researchers who skip documentation of their discovery process leave themselves legally exposed. Organisations without a VDP sometimes threaten legal action against researchers who report in good faith, a response that almost invariably backfires reputationally.

The DevSecOps shift in software development has improved the picture somewhat, as teams that integrate security into their delivery pipelines are generally faster at assessing and deploying patches once a CVE is confirmed. The core premise of DevSecOps is that security is a continuous practice rather than a release-gate activity, which maps well onto the demands of a time-sensitive disclosure.

Australia's cybersecurity maturity is improving, but responsible disclosure norms have not kept pace with the threat landscape. Organisations that take the time to build a proper VDP, train their security response team, and engage constructively with the research community will be better positioned both to remediate quickly and to avoid the reputational damage that comes from disclosure gone wrong.

→ The Confirmations · Daily newsletter

One email at 06:00 UTC. Six minutes. The only digest written for desks, not for retail.