COMMENTARY: Last month, a security researcher and a major software company became the latest protagonists in a story the cybersecurity industry keeps retelling.
The researcher found serious vulnerabilities in widely used tools. The company's reporting channel allegedly broke down. The researcher published the flaws publicly, with working exploit code and no advance warning. Real-world attackers moved quickly. The company invoked its legal enforcement unit before backing down. Recriminations flew across social media, with veteran researchers warning of a chilling effect on exactly the kind of work that keeps software secure.
[
SC Media Perspectives columns are written by a trusted community of SC Media cybersecurity subject matter experts. Read more Perspectives here.]
While this episode attracted unusual attention, the underlying challenge is becoming more common.
Advances in artificial intelligence are dramatically increasing the speed and scale of vulnerability discovery. AI systems are enabling researchers to identify classes of software flaws that previously required significant manual effort, while simultaneously lowering the barriers to entry for both defenders and malicious actors.
Related reading:
As the volume of discoveries grows, organizations will need reporting and coordination mechanisms that can process far more findings, far more quickly, than today's largely manual systems were designed to handle.
Against that backdrop, both sides of this dispute have a point. Coordinated disclosure, the practice of reporting vulnerabilities privately so companies can fix them before details become public, is a best practice that protects users. Companies that invest in security programs deserve a fair opportunity to remediate. At the same time, a researcher who cannot get through the front door of a reporting channel cannot be expected to wait indefinitely.
The episode points to a structural failure rather than bad faith on either side: the absence of a reliable, transparent, well-maintained channel for security researchers to report what they find. That structural failure is entirely preventable. As AI continues to accelerate vulnerability discovery, preventing it is increasingly a board-level responsibility.
The gap is getting more expensive
The debate over how security vulnerabilities should be disclosed is older than the commercial internet. What has changed is the speed and scale at which the problem compounds.
AI-assisted tools are accelerating both discovery and exploitation, letting researchers and attackers weaponize software weaknesses faster than ever. The window between when a flaw exists and when it is exploited is closing. Organizations that lack a structured way to receive external vulnerability reports have a meaningful blind spot, at exactly the moment when blind spots are most dangerous.
No internal security team, however capable, finds everything. The attack surface of a modern enterprise spans cloud infrastructure, third-party dependencies, AI systems, and legacy code, growing faster than a single team can audit. Independent security researchers collectively represent one of the largest and most motivated sources of vulnerability intelligence available. Alienating them is not a neutral act.
Essential elements of a vulnerability disclosure program
A
vulnerability disclosure program (VDP) is, at its core, a promise: if you find something in our systems and report it to us in good faith, here is exactly how to reach us, here is what to expect in return, and here is the legal protection that applies to you. A well-designed VDP removes the ambiguity that can prevent good-faith researchers from reporting.
The components matter. A VDP should clearly define the scope of what can be tested, establish concrete timelines for acknowledgment and remediation, and include explicit safe harbor language protecting researchers who follow the process from legal action. That last element is not a formality. Without it, many researchers will not report at all, not because they don’t want to, but because the risk calculus doesn’t justify it.
When the channel exists and works, vulnerabilities reach security teams quickly and confidentially, get triaged and prioritized, and are fixed before they can be exploited. When it does not exist, or breaks down, researchers face a choice between indefinite silence and public disclosure. Neither outcome serves users.
Bug
bounty programs, which layer a financial reward for valid reports on top of VDPs, have become standard practice for mature security programs. Rewards can run into six figures for critical vulnerabilities, but that cost is small when compared to the size of a breach. And even organizations not ready for a bounty program have no excuse for lacking a basic disclosure channel.
Regulators have taken notice
Policymakers on both sides of the Atlantic have reached the same conclusion. In the United States, a June 2026 executive order directed federal contractors to operate VDPs, building on a 2020 directive that required all federal agencies to operate VDPs. The action sent a clear message: if you do business with the federal government, you are part of the federal attack surface and must be part of its defense.
The
EU's Cyber Resilience Act (CRA), which begins imposing mandatory reporting obligations on Sept. 11, 2026, requires manufacturers of products with digital elements to maintain an accessible intake channel for vulnerability reports, a published coordinated vulnerability disclosure program, and the ability to meet 24- and 72-hour reporting timelines when actively exploited vulnerabilities are identified. Mandatory notification goes to EU authorities through ENISA's (European Union Agency for Cybersecurity) Single Reporting Platform. For companies selling software or hardware into the EU market, a VDP is no longer optional.
These rules point to the same conclusion. Vulnerability disclosure is no longer just a technical issue. It touches corporate governance, supply chain security, and public trust.
What boards and executives should do
The practical response is not complicated. Every organization that operates software, which is to say, every organization, should be able to answer three questions: Where do external security researchers go to report a vulnerability? What happens when they get there? How quickly do valid reports reach the people who can act on them?
If you do not have clear answers to those questions, the most useful thing you can do now is stand up a VDP. A VDP that is easy to find, honest about its scope and timelines, and backed by genuine safe harbor language signals to the research community that you are a responsible partner. That reputation is increasingly table-stakes. Researchers bring their best findings to organizations they trust.
The alternative is to wait until a researcher cannot reach you, loses patience, and publishes. At that point, whatever is said about responsible disclosure is beside the point. The vulnerability is public, the patch is not ready, and the damage is real.
Building a front door is not a concession to outside pressure. It is one of the most cost-effective investments in resilience an organization can make.