Vulnerability Disclosure Guidelines
If you find a security issue with any MTCyber systems, please inform us so that we
can address and resolve it promptly.
Our Goal
Our primary aim is to protect the privacy of our customers and staff. We appreciate and encourage responsible reporting of vulnerabilities, allowing us to work collaboratively with individuals to ensure any identified issues are swiftly addressed.
We are committed to working with anyone who reports vulnerabilities in our systems.
MTCyber utilizes a range of services from various providers. If the identified
vulnerability relates to a third-party product or service, we may need to relay the
information to them. Your personal information, including contact details, will not be
disclosed without your explicit permission.
How to Report a Vulnerability
Please contact the MTCyber security team immediately if you have identified a
vulnerability:
- Email us at info@mtcyber.co.nz. Our emails are monitored Monday to Friday, 08:30 – 17:30 (NZT). We will respond to your inquiry within one working day.
- We do not support PGP-encrypted emails. For particularly sensitive information, we may respond with an appropriate mechanism for secure transmission.
Information to Include
When reporting a vulnerability, please provide as much relevant information as
possible without further exploring or exploiting the issue. This may include:
- Type of vulnerability
- Whether the vulnerability has been published or shared with others
- Affected systems, products, and versions
- Affected configurations
- Step-by-step instructions, screenshots, or proof-of-concept code to replicate the issue
- Whether any personal information was exposed
- What actions have been taken (if any) regarding exposed personal information
What We Will Do
- We will acknowledge receipt of your email as soon as possible and provide an update on the progress of our investigation within five working days.
- Our team will review the reported vulnerability and collaborate with any relevant service providers to validate your findings.
- We will inform you of the results of our investigation and our intended actions.
- We aim to address all identified vulnerabilities as quickly as possible. Please note that resolution may depend on third-party suppliers and contractual obligations.
-
What You Should Not Do
To ensure a responsible approach to vulnerability research, please refrain from:
- Conducting Denial of Service (DoS/DDoS) attacks
- Accessing or retrieving data or information that does not belong to you. If you have confirmed a vulnerability that exposes information, avoid seeking further information—one example is sufficient
- Destroying or corrupting data or information that does not belong to you
- Sharing or publishing any personal information that you have obtained
Protecting Privacy
We ask that you do not share any identified vulnerabilities with others until we have
had the opportunity to resolve the issue. Preventing exploitation of vulnerabilities is a
priority.
Do not share any personal information obtained from MTCyber, as this could
potentially harm individuals. Publishing or sharing personal information may also be
considered a breach of the New Zealand Privacy Act and could lead to legal
consequences.
Our Commitment
If you act in good faith and adhere to these guidelines, MTCyber makes the following
commitments to you:
- Any information you share with us as part of this process will be kept confidential within MTCyber and our directly contracted suppliers.
- Your personal information, including contact details, will not be shared with third parties without your permission.
- We will not initiate legal action against individuals attempting to identify vulnerabilities within our systems, provided they act in good faith and comply with these guidelines.