As asked
Your company has no vulnerability disclosure programme. A researcher emails you about a critical bug. What do you do, and how would you build the programme?
Sample answer outline
Immediate: acknowledge the researcher fast (under 24 hours), validate the bug, assess severity (CVSS), get a fix path with engineering on a known timeline. Communicate clearly with the researcher on the timeline; respect their disclosure window. Build the programme: a public security.txt with a contact and PGP key, a clear scope document, a safe harbour statement, a triage rota, an internal severity-to-timeline policy (critical: hours, high: days, medium: weeks). Decide on bounty vs no-bounty. Track every report and close the loop with the researcher when it ships.
Expect these follow-ups
- How do you handle a researcher who threatens public disclosure on day 3?
- What is in a good safe harbour clause?
- When is a bug bounty programme premature?