Vulnerability Disclosure Program @ Roland Berger
Roland Berger is committed to maintaining the security of its digital services. We welcome responsible security research and encourage the responsible disclosure of vulnerabilities found in our internet‑facing systems.
This page describes what systems are in scope, how to report vulnerabilities, and the rules that apply when conducting security research.
Scope
In Scope
Out of Scope
Rules of Engagement
Researchers are expected to act in good faith and comply with the applicable laws as well as the following rules.
Researchers are expected to act in good faith and comply with the following rules.
Permitted Activities
Prohibited Activities
Safe Harbor
If you make a good‑faith effort to comply with this page, Roland Berger will consider your research to be authorized and does intend to pursue legal action for activities conducted in accordance with this page. Activities outside this page or conducted in bad faith may violate applicable laws (including §§202a–202c StGB). Roland Berger reserves all rights to pursue unauthorized activity and the damages incurred.
We ask that you:
Reporting a Vulnerability
Please report vulnerabilities by email to:
informationsecurityofficer@rolandberger.com
Your report should include:
Disclosure Process & Timeline
Our process is as follows:
Acknowledgment
We aim to acknowledge reports within 5 business days.
Validation
Our IT Security team will assess and validate the reported issue.
Internal Coordination
Confirmed vulnerabilities are coordinated internally with relevant teams, including Communications where applicable.
Resolution
Once remediation is completed, we will inform the reporter.
Public Disclosure & Publication
Any public disclosure, publication, or presentation of a reported vulnerability must be explicitly agreed upon in advance with Roland Berger.
Unauthorized public disclosure may result in exclusion from safe harbor protections.
Compensation
Roland Berger does not currently operate a bug bounty program.
No financial compensation is offered for reported vulnerabilities unless explicitly stated otherwise.
Researcher Recognition
Researchers will generally receive personal acknowledgment
Public recognition is not guaranteed and is assessed on a case‑by‑case basis
Any public publications of findings as bug reports requires mutual agreement
Email & Phishing Notice
The only official Roland Berger email domain is @rolandberger.com.
Emails claiming to represent Roland Berger from other domains should be treated as suspicious.
Illustration: Getty Images