Skip to main content

Security bulletin policy

Security advisories and incident notices for the CyberOptix CTEM Platform are published to Security bulletins, which carries its own RSS feed - separate from Release notes, so subscribing to advisories does not subscribe you to the changelog.

What gets a bulletin​

TypePublished
AdvisoryA vulnerability in the platform, whether we found it or you did
IncidentA security incident affecting the service, after resolution

A vulnerability fixed before any release shipped it does not get a bulletin - there was nothing for you to be exposed to. One that reached a release does, whether or not we believe it was exploited.

Severity​

Bulletins use the same five-level scale as findings in the product, derived from CVSS v3 ranges:

SeverityScoreMeaning
Critical9.0 - 10.0Exploitable remotely with severe impact, little or no precondition
High7.0 - 8.9Serious impact, or severe impact with meaningful preconditions
Medium4.0 - 6.9Limited impact, or significant preconditions
Low0.1 - 3.9Minor impact

Timing​

SeverityTarget
CriticalWithin 72 hours of a fix being available
HighWithin 7 days
Medium and LowWith the release that fixes them

Publication is timed to a fix being available, not to it being deployed everywhere, because you may need to act on hosted components yourself. Where a mitigation exists before a fix, we publish the mitigation rather than waiting.

What a bulletin contains​

  • What the issue is, in terms of what an attacker could do
  • Affected versions and components
  • Severity and score
  • Whether we have evidence of exploitation
  • What you need to do, and whether anything is required of you at all
  • CVE identifier where one has been assigned

We do not publish exploit details or proof-of-concept code.

Silence​

An empty period means no advisories were published in it. It does not mean none were found - it means none reached a release, or none were of a severity that requires one under this policy.

We state that explicitly because a quiet advisory feed is easy to read as an absence of diligence, and because a policy that only describes what happens when something is found tells you nothing about the other case.

Reporting something to us​

If you believe you have found a vulnerability in the platform, contact [email protected].

Please give us a reasonable period to investigate and fix before disclosing publicly. We will keep you informed of progress, and we will credit you in the bulletin unless you would rather we did not.

Compliance evidence​

If you need evidence of our vulnerability communication process for your own audit, this page plus the bulletin feed is it. Both are public and neither requires a request.