Skip to main content

Thanking the vulnerability research community with NCSC Challenge Coins

Reflecting on the positive impact of the Vulnerability Reporting Service – and introducing something new for selected contributors.

Image of Challenge Coins. Clockwise from top left - Ada Lovelace, Charles Babbage, The Bombe, Alan Turing
Clockwise from top left - Ada Lovelace, Charles Babbage, the Bombe, Alan Turing

In 2018 the NCSC launched the Vulnerability Reporting Service (VRS), for security researchers to disclose vulnerabilities they had found in UK government services. We set it up because we wanted to offer a way to disclose responsibly. At its heart is the core principle of responsible vulnerability disclosure: that disclosure itself is not an incident, but has the potential to become one if a vulnerability is disclosed in an irresponsible way, like posting it on social media.

Positive impact

The VRS has been a real success because it has allowed us to make use of talented researchers worldwide through the HackerOne platform, with help from NCC Group.

In 2022, there were four times the number of reports than when the service first started. It’s been heartening to see that where there is a route to report vulnerabilities and even with minimal incentive, the researcher community is in most cases committed to disclosing vulnerabilities responsibly and seeing them remediated.

The service has also helped in other ways – indirectly, by helping us shape the  Vulnerability Disclosure Toolkit, where we’ve taken what we’ve learned from the VRS and made it available to everyone. And more directly, we’ve seen the VRS evolve and work alongside a wider ‘Disclosure for Government’ scheme that empowers government departments to manage their own vulnerability disclosure process, while making use of the shared platform and triage service the VRS offers.




Written by

Ollie N Head of Vulnerability Management Team, NCSC

Published