Cybersecurity Vulnerability Disclosure (VDP) at WEPA
At WEPA, cyber security, information security and data protection are our top priorities. We are committed to protecting our digital systems, data, employees, customers and business partners. Furthermore, we recognise the important role that stakeholders play in identifying and responsibly reporting suspected security incidents, vulnerabilities or concerns regarding personal data. If you believe you have discovered a vulnerability affecting WEPA’s own media content, please report it immediately using the procedure described below.
We investigate all legitimate reports in good faith and endeavour to rectify confirmed vulnerabilities as promptly as possible. The investigation and handling of a report does not give rise to any entitlement to compensation, reimbursement, a reward, a contractual relationship or any other benefits. WEPA does not operate a bug bounty programme.
Incidents to be reported
Please report any suspected vulnerabilities or concerns relating to our systems, including:
- Suspected cyber security incidents or attacks
- Unauthorised access to systems, networks or data
- Information security vulnerabilities
- Attempts at phishing, fraud or identity theft affecting our company
- Potential breaches of personal data protection or the right to privacy
- Risks posed by third parties that could affect our systems, services or customers
Please use the contact details provided below to submit your report.
What should your report include?
To help us categorise and prioritise reports, please include the following information with your report:
- A detailed description of the incident, the problem or the vulnerability, including the steps required to reproduce it
- Date and time of discovery
- Affected systems, URLs, applications or services
- Any relevant screenshots, logs or evidence Your contact details (optional, but recommended in case of follow-up enquiries)
If you agree to provide us with your contact details, we will liaise with you as promptly and transparently as possible.
To whom should the notification be sent?
Please send reports to:
Information Security / Cyber Security: itsecurity@wepa.eu
Data Protection: datenschutz@wepa.eu
WEPA will acknowledge receipt of any valid report. If you have provided personal data in your report, please refer to WEPA’s information on data protection: Data Protection | WEPA
Responsible Disclosure
WEPA supports responsible security research conducted in good faith. For the purposes of this section on responsible disclosure, ‘in good faith’ refers only to activities aimed at identifying and reporting vulnerabilities. Activities involving the deliberate access, acquisition, use, storage, disclosure or exfiltration of data, confidential information, trade secrets, intellectual property, or breaches of applicable law do not constitute acting in good faith. When reporting a vulnerability, we ask that you avoid data breaches and treat the vulnerability as confidential until the measures to rectify it have been completed or both parties have agreed to its disclosure. Should you come across personal data or other sensitive information, you must notify WEPA immediately and delete any information obtained inadvertently without delay, unless its retention is required by law. We will not take legal action against researchers who act in good faith, comply with this policy, respect privacy and avoid operational disruption.
Confidentiality
Personal data provided as part of a report will be processed solely for the purpose of investigating and dealing with the matter reported, in accordance with applicable data protection laws and our privacy policy.
Thank you for helping us to ensure the security and integrity of our systems, data and services.