Vulnerability Disclosure Programs

A Multiple Case Study on the Factors Influencing Vendors’ Decision on Adopting Coordinated Vulnerability Disclosure Programs

Master Thesis (2025)
Author(s)

A.M. Tjin Tjoen Jin (TU Delft - Technology, Policy and Management)

Contributor(s)

C. Hernandez Ganan – Graduation committee member (TU Delft - Technology, Policy and Management)

A.C. Smit – Graduation committee member (TU Delft - Technology, Policy and Management)

Faculty
Technology, Policy and Management
More Info
expand_more
Publication Year
2025
Language
English
Graduation Date
25-08-2025
Awarding Institution
Delft University of Technology
Programme
Management of Technology (MoT)
Faculty
Technology, Policy and Management
Downloads counter
112
Reuse Rights

Other than for strictly personal use, it is not permitted to download, forward or distribute the text or part of it, without the consent of the author(s) and/or copyright holder(s), unless the work is under an open content license such as Creative Commons.

Abstract

As cybersecurity threats continue to evolve, organizations face increasing pressure to proactively identify and manage vulnerabilities. Coordinated Vulnerability Disclosure (CVD) programs offer a structured approach to receiving and responding to vulnerability reports. While prior research has largely focused on the operational aspects of CVD implementation, this thesis investigates the upstream decision-making factors influencing vendors' adoption of such programs.

Using a multiple case study approach and guided by the Technology-Organization-Environment (TOE) framework and Stakeholder Theory, this study examines how technological readiness, organizational culture, and environmental pressures affect the adoption of CVD programs. The analysis is based on 15 semi-structured interviews with security professionals from vendors with and without CVD programs.

The findings reveal that successful CVD adoption is often driven by strong internal capabilities, openness to transparency, support from leadership, and external regulatory pressure. In contrast, barriers include resource limitations, reputational concerns, and unclear internal processes. The study highlights the importance of third-party platforms, legal guidance, and a tailored approach that aligns with the organization's risk profile and industry context.

This research contributes to the academic literature by shifting attention from post-adoption practices to the decision-making processes leading to adoption. It provides actionable recommendations for vendors and stakeholders to improve vulnerability management and increase preparedness in an increasingly complex digital environment.

Files

License info not available