Skip to main content Skip to navigation

Vulnerability disclosure policy

The department is committed to ensuring the security of the Western Australian public by protecting their information.

About this policy

This policy is intended to give security researchers clear guidelines for conducting vulnerability discovery activities and to convey our preference in how to submit any discovered vulnerabilities found within our systems.

If you make a good faith effort to comply with this policy during your security research, we will not take any legal action against you.

The following activities are not permitted against any system: 

  • denial of service (DoS/DDos) and spam 
  • social engineering (e.g. phishing) against our Department staff 
  • physical access attacks (e.g. attempting to access buildings) 
  • uploading malware, backdoors, webshells, or other ‘weaponised’ exploits that could degrade system security of affect other users 
  • attempt to access or manipulate accounts that do not belong to you (e.g. resetting passwords for other users) 
  • any attempt to modify or destroy data. 

How to report a vulnerability 

To report a vulnerability, please submit all reports to VulnerabilityDisclosure@dpird.wa.gov.au

To help address the issue as quickly as possible, your reports should: 

  • describe where the vulnerability was discovered and the potential impact of exploitation 
  • include enough detail so we can reproduce your steps. Screenshots and proof of concept code are helpful.

What happens next 

  • We will confirm we received vulnerability reports within 5 business days.
  • We do not offer payment or public credit to security researchers for reporting potential or confirmed vulnerabilities.