Responsible Disclosure
Help us keep our digital environment secure
The security and resilience of our digital systems are essential for the safe and reliable operation of NGT. We therefore take appropriate measures to protect our IT and operational systems.
However, you may discover a vulnerability. Have you found a potential security issue in one of NGT’s digital systems? Please report it to us. This will allow us to investigate it and, where necessary, take appropriate measures.
This process is called Coordinated Vulnerability Disclosure (CVD), also known as Responsible Disclosure.
Reporting a Vulnerability
Send your report to security@noordgastransport.nl.
If you are unable to send an email for security or technical reasons, please contact us by phone at +31 85 208 75 01.
Describe the potential vulnerability as thoroughly as possible. Please include, preferably:
- a clear description of the vulnerability;
- the affected system, URL, or IP address;
- the steps required to reproduce the vulnerability;
- relevant technical information, such as logs or screenshots;
- the potential impact of the vulnerability;
- your contact information, so we can reach you for additional details.
Do not send any sensitive data unless it is necessary to demonstrate the vulnerability.
Guidelines for Responsible Research
When investigating a potential vulnerability in our systems, we ask that you act with care and discretion.
Please do the following:
- limit your research to what is strictly necessary to identify the vulnerability;
- avoid disrupting our systems, services, and business operations;
- do not exploit the vulnerability for any other purpose;
- do not modify, delete, or copy any data unless it is strictly necessary to demonstrate the vulnerability;
- delete any data obtained as soon as it is no longer necessary;
- do not share information about the vulnerability with third parties and do not publish it without prior written consent from NGT;
- give us sufficient time to investigate the vulnerability and remedy it where necessary.
Critical and Operational Infrastructure
NGT manages critical energy infrastructure. The safety and continuity of this infrastructure are always our top priority.
Therefore, it is not permitted to actively conduct security research on operational technology (OT), Industrial Control Systems (ICS), SCADA systems, process automation, safety or security systems, or other systems that are directly or indirectly connected to our operational infrastructure.
Also, do not perform any actions that could affect the availability, integrity, or safe operation of our infrastructure.
Do you think you’ve discovered a vulnerability in such a system? If so, stop further investigation and report your finding immediately to NGT.
What can you report?
We welcome reports of verifiable technical vulnerabilities that could affect the confidentiality, integrity, or availability of our systems or data.
Examples include:
- unauthorized access to systems or data;
- Remote Code Execution (RCE);
- SQL injection;
- Cross-Site Scripting (XSS);
- Cross-Site Request Forgery (CSRF) with demonstrable security impact;
- vulnerabilities in authentication or authorization;
- cryptographic vulnerabilities with demonstrable impact;
- unintentional disclosure of confidential information;
- relevant security misconfigurations.
Out of Scope
The following activities and findings are, in principle, outside the scope of our Responsible Disclosure policy:
- social engineering, phishing, and similar techniques;
- attempts to gain physical access to locations, buildings, facilities, or equipment;
- Denial of Service (DoS) and Distributed Denial of Service (DDoS);
- automated tests that generate large amounts of traffic;
- vulnerabilities in third-party systems not managed by NGT;
- non-reproducible findings;
- automated scanner results without validation or demonstrable impact;
- information about version numbers, open ports, or services without a specific exploitation scenario;
- missing security headers or cookie flags without a demonstrable security impact;
- TLS/SSL configuration findings without demonstrable impact;
- clickjacking, content spoofing, redirects, or host header findings without a demonstrable security risk;
- missing or incorrect SPF, DKIM, DMARC, or CAA configurations without demonstrable impact;
- outdated software without a known or demonstrably exploitable vulnerability;
- vulnerabilities that can only be exploited through outdated or unsupported client-side software;
- general hardening or best-practice recommendations without a specific vulnerability;
- vulnerabilities for which a security update has very recently become available;
- duplicates of previously received reports.
This list is not exhaustive. NGT ultimately determines whether a report falls within the scope of this policy.
What can you expect from us?
When you report a vulnerability in accordance with this policy:
- we will handle your report carefully and confidentially;
- we will assess the report and its potential impact;
- we may contact you if additional information is needed;
- we will inform you, where reasonably possible, about how the report is being handled.
NGT does not offer a financial reward (bug bounty) for reports, unless otherwise expressly agreed upon in advance.
If you act in good faith and comply with this Responsible Disclosure Policy, NGT will, in principle, not take legal action against you in connection with the investigation to which your report relates.
This protection does not apply if you act outside the scope of this policy, cause damage, misuse data, disrupt our business operations, or otherwise act unlawfully.
Known Vulnerabilities
It is possible that a reported vulnerability is already known to us or that mitigating measures or corrective actions have already been planned for it.
In that case, we may indicate that the report is already known, and it may not be treated as a new report.
For security reasons, we do not publish a list of known vulnerabilities or accepted security risks.
Security.txt
NGT supports the standard for publishing contact information for reporting security issues as described in RFC 9116.
Our security.txt file is available at:
www.ngt.nl/.well-known/security.txt
Terms and Conditions
By reporting a vulnerability to NGT, you acknowledge that you have read this Responsible Disclosure Policy and that you have conducted your investigation in accordance with these terms and conditions.
A report does not grant permission to conduct further investigation beyond what is permitted under this policy and does not grant access to NGT’s systems, data, locations, or infrastructure.
Use of NGT’s name, trade name, logo, or other trademarks in connection with a report or investigation is not permitted without prior written consent.
Publication or other external use of information regarding a reported vulnerability is permitted only after prior written consultation with NGT.
If you are unsure whether an action is permitted under this policy, do not proceed with it; instead, contact us first at or security@noordgastransport.nl.