GMC_EventMarketing_LandingpageHeader_1600x500px-2

 Roland Berger 

       Responsible Disclosure

Vulnerability Disclosure Program @ Roland Berger

Roland Berger is committed to maintaining the security of its digital services. We welcome responsible security research and encourage the responsible disclosure of vulnerabilities found in our internet‑facing systems.
This page describes what systems are in scope, how to report vulnerabilities, and the rules that apply when conducting security research.


Scope

In Scope

    • Public‑facing Roland Berger websites and web applications
    • Internet‑accessible systems and services owned and operated by Roland Berger
    • Domains and subdomains under rolandberger.com

Out of Scope

    • Physical security assessments
    • Social engineering activities (e.g. phishing, vishing, pretexting)
    • Denial‑of‑Service (DoS/DDoS) testing
    • Third‑party systems or services not owned or operated by Roland Berger
    • Testing that results in service disruption, data loss, or excessive traffic

Rules of Engagement

Researchers are expected to act in good faith and comply with the applicable laws as well as the following rules.

Researchers are expected to act in good faith and comply with the following rules.

Permitted Activities

    • Non‑destructive testing only
    • Limited proof‑of‑concept testing to demonstrate impact
    • Avoidance of unnecessary access to data

Prohibited Activities

    • Accessing, modifying, deleting, or exfiltrating data
    • Accessing personal, confidential, or business‑critical information
    • Privilege escalation beyond what is strictly required to demonstrate the issue
    • Any activity that disrupts systems, services, or users
    • Social engineering or impersonation attempts

Safe Harbor

If you make a good‑faith effort to comply with this page, Roland Berger will consider your research to be authorized and does intend to pursue legal action for activities conducted in accordance with this page. Activities outside this page or conducted in bad faith may violate applicable laws (including §§202a–202c StGB). Roland Berger reserves all rights to pursue unauthorized activity and the damages incurred.

We ask that you:

    • Do not exploit vulnerabilities beyond what is necessary for a proof‑of‑concept
    • Do not publicly disclose vulnerabilities without prior written agreement

Reporting a Vulnerability

Please report vulnerabilities by email to:
informationsecurityofficer@rolandberger.com

Your report should include:

    • A detailed description of the vulnerability
    • Steps to reproduce
    • Affected systems or URLs
    • Supporting technical details or screenshots

Disclosure Process & Timeline

Our process is as follows:

Acknowledgment
We aim to acknowledge reports within 5 business days.

Validation
Our IT Security team will assess and validate the reported issue.

Internal Coordination
Confirmed vulnerabilities are coordinated internally with relevant teams, including Communications where applicable.

Resolution
Once remediation is completed, we will inform the reporter.


Public Disclosure & Publication

Any public disclosure, publication, or presentation of a reported vulnerability must be explicitly agreed upon in advance with Roland Berger.
Unauthorized public disclosure may result in exclusion from safe harbor protections.


Compensation

Roland Berger does not currently operate a bug bounty program.
No financial compensation is offered for reported vulnerabilities unless explicitly stated otherwise.


Researcher Recognition

Researchers will generally receive personal acknowledgment
Public recognition is not guaranteed and is assessed on a case‑by‑case basis
Any public publications of findings as bug reports requires mutual agreement


Email & Phishing Notice

The only official Roland Berger email domain is @rolandberger.com.
Emails claiming to represent Roland Berger from other domains should be treated as suspicious.