IT Pro is supported by its audience. When you purchase through links on our site, we may earn an affiliate commission. Learn more

MoD launches bug bounty programme

Researchers are encouraged to report any flaws they find on MoD systems, but they must not engage in social engineering or phishing attacks

The Ministry of Defence (MoD) has introduced its own bug bounty programme through which white hat hackers can disclose vulnerabilities to the UK government department without fear of prosecution.

Partnering up with HackerOne, the MoD has published a submission form that security researchers can use to report any bugs or flaws with systems or platforms managed by the UK’s defence authorities. Unlike bug bounty programmes commonly run by private companies, however, there is no monetary reward available for disclosure.

Researchers who find a security vulnerability relating to an MoD system must include details of the website IP or page where the vulnerability can be observed, a brief description of its nature, and steps to reproduce. These should be a benign and non-destructive proof-of-concept and works to ensure the report can be triaged quickly and with accuracy.

“If you believe you have found a vulnerability on any MOD system, you can report using the Hacker One: submit a vulnerability report,” the MoD said. “We recommend reading this disclosure policy fully before you report any vulnerabilities. This helps ensure that you understand the policy, and act in compliance with it.

“This policy is designed to be compatible with common vulnerability disclosure good practice. It does not give you permission to act in any manner that is inconsistent with the law, or which might cause the MOD or partner organisations to be in breach of any legal obligations.”

After you submit a report, the MoD will respond within five working days and will aim to triage the report within ten working days. A representative will keep you informed on its progress throughout the process via HackerOne if you’ve registered for an account.

After the ten-day process has elapsed, the priority for remediation will be assessed based on the impact, severity and exploit complexity. Some flaws may take time to address if they are not deemed a priority, and researchers are welcome to enquire on the status of their reports. However, the MoD stressed they should only check in once every fortnight at a maximum.

The MoD will then report back when the vulnerability is fixed, with researchers invited to confirm the solution fixes the problem adequate. Future public disclosure arrangements will then be subject to co-ordination between researchers and the MoD.

Researchers seeking to report a vulnerability must abide by a set of strict protocols, however. They must not, for example, break any law, access unnecessary of significant amounts of data, modify data in MoD systems, disrupt any systems, use high-intensity invasive of destructive scanning tool, or attempt any form of denial of service

Also out of bounds is social engineering or phishing exercises, demanding financial compensation to disclose vulnerabilities, submitting reports detailing non-exploitable flaws, or submitting reports detailing TLS configuration weaknesses. 

The MoD claims its policy is compatible with common industry-wide vulnerability disclosure practices, and that it does not give white hat hackers or security researchers permission to act in any way that’s inconsistent with the law.

The government department will not, however, seek prosecution of any researcher who reports vulnerabilities on MoD services or systems where they’ve acted in good faith and in accordance with the disclosure policy.

Featured Resources

The Total Economic Impact™ Of Turbonomic Application Resource Management for IBM Cloud® Paks

Business benefits and cost savings enabled by IBM Turbonomic Application Resource Management

Free Download

The Total Economic Impact™ of IBM Watson Assistant

Cost savings and business benefits enabled by Watson Assistant

Free Download

The field guide to application modernisation

Moving forward with your enterprise application portfolio

Free Download

AI for customer service

Discover the industry-leading AI platform that customers and employees want to use

Free Download

Recommended

Cyber resiliency and end-user performance
Whitepaper

Cyber resiliency and end-user performance

17 Aug 2022
Can't choose between public and private cloud? You don't have to with IaaS
Whitepaper

Can't choose between public and private cloud? You don't have to with IaaS

12 Aug 2022
What is zero trust?
network security

What is zero trust?

14 Jul 2022
Retbleed hardware-level flaw brings overhead woe to Intel and AMD
Hardware

Retbleed hardware-level flaw brings overhead woe to Intel and AMD

13 Jul 2022

Most Popular

Why convenience is the biggest threat to your security
Sponsored

Why convenience is the biggest threat to your security

8 Aug 2022
How to boot Windows 11 in Safe Mode
Microsoft Windows

How to boot Windows 11 in Safe Mode

29 Jul 2022
UK water supplier confirms hack by Cl0p ransomware gang
ransomware

UK water supplier confirms hack by Cl0p ransomware gang

16 Aug 2022