CERT in Iberia
Ethical, coordinated disclosure with secure reporting and CVE assignment via Thales CERT in Iberia.
Thales’ mission is to safeguard organiSations by managing cyber risk. Thales CERT in Iberia supports ethical vulnerability disclosure, secure reporting, CVE assignment and coordinated publication with vendors and authorities.
Why disclose vulnerabilities with Thales CERT in Iberia
Ethical disclosure, secure reporting, vendor coordination, CVE assignment, and publication support.
-
Ethical disclosure
Thales is fully committed to ethical and timely disclosure of vulnerability information to safeguard people, assets and business transformation.
-
Secure reporting
Researchers submit details via secure email to cve-coordination@s21sec.com. Encrypted exchanges are supported using a public PGP key.
-
Coordinated timeline
Initial contact is by email (or a secure vendor mechanism). A disclosure timeframe is agreed with the affected supplier depending on their situation.
-
Vendor collaboration
When appropriate, Thales CERT in Iberia shares a draft notice before publication and participates jointly and in a coordinated manner throughout the process.
-
CVE assignment (CNA)
Thales CERT in Iberia operates as a CNA (under a CNA-Root scope) and can authorize CVE identifier assignment for vulnerabilities found by its research teams.
-
Publication support
After vendor confirmation, CVE IDs are reserved and shared. Once public, MITRE and, when appropriate, national CERTs are informed.
Responsible disclosure process
Thales CERT in Iberia provides a structured vulnerability disclosure process including secure intake, vendor coordination, vulnerability analysis, CVE assignment and public advisory publication aligned with ethical timelines.
© 123RF
To support responsible and secure vulnerability disclosure, Thales CERT in Iberia enables encrypted communications for researchers and partners. Vulnerability reports must be sent to cve.coordination.iberia@thalesgroup.com using secure email. For encrypted exchanges, please use the official public PGP key below.