KIT | KIT-Bibliothek | Impressum | Datenschutz

Do (Not) Tell Me About My Insecurities: Assessing the Status Quo of Coordinated Vulnerability Disclosure in Germany Amid New EU Cybersecurity Regulations

Neef, Sebastian 1; Schlunke, Cenk 1; Hennig, Anne ORCID iD icon 2
1 Technische Universität Berlin (TU Berlin)
2 Institut für Angewandte Informatik und Formale Beschreibungsverfahren (AIFB), Karlsruher Institut für Technologie (KIT)

Abstract:

In our increasingly interconnected world, good IT security practices are necessary to prevent vulnerabilities and data breaches. Providing security contacts, e.g., via Coordinated Vulnerability Disclosure (CVD) programs or security.txt files, is an important practice for businesses to facilitate vulnerability reporting by external parties. As part of a longitudinal study, we analyzed the adoption of, as well as the challenges and experiences with, CVD programs among the 40 companies listed on Germany’s DAX (the country’s primary stock market index). In addition to monitoring publicly available information about their CVD programs, we sent out questionnaires via email and postal mail in 2023 and 2025, and received answers from 20% of the companies. The adoption rates show a significant increase from 50% (2023) to over 90% (2025), with ten new CVD programs and 25 new security.txt files now available. The survey answers reveal that, for example, legal obligations (e.g., NIS2 and CRA) drive the adoption of CVD practices, but a lack of (human) resources and varying report quality are considered drawbacks. As the first study to survey 40 German stock market index (DAX) companies on their CVD practices, our results can help foster the adoption and understanding of security programs among SMEs and other companies, and provide policymakers with insights into practical challenges and industry experiences.


Postprint §
DOI: 10.5445/IR/1000184817/post
Veröffentlicht am 20.02.2026
Preprint §
DOI: 10.5445/IR/1000184817
Veröffentlicht am 12.09.2025
Originalveröffentlichung
DOI: 10.1109/EuroUSEC69254.2025.00020
Cover der Publikation
Zugehörige Institution(en) am KIT Institut für Angewandte Informatik und Formale Beschreibungsverfahren (AIFB)
Kompetenzzentrum für angewandte Sicherheitstechnologie (KASTEL)
Publikationstyp Proceedingsbeitrag
Publikationsjahr 2025
Sprache Englisch
Identifikator ISBN: 979-8-3315-5924-3
KITopen-ID: 1000184817
HGF-Programm 46.23.01 (POF IV, LK 01) Methods for Engineering Secure Systems
Erschienen in Proceedings of the 2025 European Symposium on Usable Security (EuroUSEC '25); Manchester, Vereinigtes Königreich, 10.-11.09.2025
Veranstaltung European Workshop on Usable Security (EuroUSEC 2025), Manchester, Vereinigtes Königreich, 10.09.2025 – 11.09.2025
Verlag Institute of Electrical and Electronics Engineers (IEEE)
Seiten 100-113
Vorab online veröffentlicht am 29.12.2025
Schlagwörter Security Awareness, Usable Security, Coordinated Vulnerability Disclosure, Responsible Disclosure, Bug Bounty Programs, security.txt, NIS2, CRA, Germany
KIT – Die Universität in der Helmholtz-Gemeinschaft
KITopen Landing Page