Thanking the vulnerability research community with NCSC Challenge Coins
Reflecting on the positive impact of the Vulnerability Reporting Service – and introducing something new for selected contributors.
Our advice & guidance covers a broad range of topics
Resources for individuals and organisations in the UK who have experienced an online scam or cyber attack.
Find a range of products & services from NCSC and certified 3rd party suppliers
Working with industry, government and academia to support the next generation of researchers, students and cyber security professionals
All the latest information to help you keep track of what's happening
Reflecting on the positive impact of the Vulnerability Reporting Service – and introducing something new for selected contributors.

In 2018 the NCSC launched the Vulnerability Reporting Service (VRS), for security researchers to disclose vulnerabilities they had found in UK government services. We set it up because we wanted to offer a way to disclose responsibly. At its heart is the core principle of responsible vulnerability disclosure: that disclosure itself is not an incident, but has the potential to become one if a vulnerability is disclosed in an irresponsible way, like posting it on social media.
The VRS has been a real success because it has allowed us to make use of talented researchers worldwide through the HackerOne platform, with help from NCC Group.
In 2022, there were four times the number of reports than when the service first started. It’s been heartening to see that where there is a route to report vulnerabilities and even with minimal incentive, the researcher community is in most cases committed to disclosing vulnerabilities responsibly and seeing them remediated.
The service has also helped in other ways – indirectly, by helping us shape the Vulnerability Disclosure Toolkit, where we’ve taken what we’ve learned from the VRS and made it available to everyone. And more directly, we’ve seen the VRS evolve and work alongside a wider ‘Disclosure for Government’ scheme that empowers government departments to manage their own vulnerability disclosure process, while making use of the shared platform and triage service the VRS offers.
We have awarded HackerOne reputation points to show our appreciation to researchers who submit valid vulnerability reports and as we come to the five-year mark, we’ll now also be awarding NCSC Challenge Coins to selected researchers. Regrettably we can’t give coins to everyone who contributes a report, so we're awarding them to those who have shown themselves to be exemplars of the vulnerability disclosure community. If you’ve been selected, you’ll be contacted through the HackerOne platform.
We’d like to take this opportunity to thank everyone who has reported a vulnerability and helped to make government systems more secure and resilient.
There are four versions of the challenge coins. Each depicts a person or element important in the history of British computing (top down, left to right).
Ada Lovelace was a mathematician and writer during the 1800s. She is considered the world's first programmer, for her work writing an algorithm (set of operating instructions) for the early analytical engine that was built and conceived by Charles Babbage. She is also the namesake of the Ada programming language created a century after her death.
Alan Turing was a leading cryptanalyst at the Government Code and Cypher School (GC&CS) working at Bletchley Park during World War 2. He is also considered the founding father of theoretical computer science and artificial intelligence. He is the creator and namesake of the Turing Test (he originally called it the imitation game): a test of a machine's ability to exhibit intelligent behaviour equivalent to human intelligence.
Charles Babbage was also a mathematician during the 1800s, but took an additional interest in philosophy and mechanical engineering. He is considered the father of the computer, after creating the concept of a digital programmable computer. He built the prototype for the first difference engine, and conceived the analytical machine, receiving assistance from Ada Lovelace who developed an algorithm to help it process data.
The Bombe is an electromechanical device used by British cryptologists to help decipher German secret messages during World War 2 encrypted by the Enigma machine. The initial design of the British bombe was produced in 1939 at the UK Government Code and Cypher School (GC&CS) at Bletchley Park by Alan Turing, with an important refinement devised in 1940 by Gordon Welchman.
As the UK national technical authority for cyber security, our work to help manage vulnerabilities continues, as we consider how to take what we’ve learnt in the government space into other areas to help make the UK the safest place to live and work online.
And look out soon for our updated vulnerability management guidance, which includes advice about how to establish a vulnerability disclosure process.


