About us

Litgrid > About us > Responsible disclosure of vulnerabilities in information systems

Responsible disclosure of vulnerabilities in information systems

We invite cyber security experts to contribute to the cyber security of the Lithuanian energy sector. If you notice a weakness or vulnerability in the information systems of “Litgrid”, please do not hesitate and notify us. Before starting to search for vulnerabilities in the information systems of “Litgrid”, we invite you to familiarize yourself with the vulnerability search procedure below. 
 
How can you look for vulnerabilities and (or) weaknesses in the systems of "Litgrid" without incurring legal liability? 
 
When searching for vulnerabilities and weaknesses in the information systems of "Litgrid", you are obliged to comply with the terms and conditions set out on this page and in the DESCRIPTION OF THE PROCEDURE FOR THE DISCLOSURE OF VULNERABILITIES IN THE INFORMATION SYSTEMS OF LITGRID AB (hereinafter - the Description). When submitting information about a vulnerability or a weakness in the systems of “Litgrid”, you confirm that you have read and agreed to comply with the requirements of the Description.  
 
If you are an employee of the Company, a member of a collegial management body, a supplier, a contractor or any other third party and, as a result of your relationship with “Litgrid” you have been granted access to the information systems of “Litgrid” and you have discovered a vulnerability in these systems, you must notify "Litgrid” of the vulnerability in accordance with the procedures set out in the agreement and the Company’s internal legislation that you have been familiarised with.     
 
When searching for vulnerabilities, you must comply with the following restrictions: 
 
– you must not interfere with or alter the operation, functionality of the information systems of “Litgrid”, the availability and integrity of the services and data provided; 
 
–once you are confident that a vulnerability is present, you must immediately stop the vulnerability search activity and inform “Litgrid”, and you must not use the discovered vulnerability to search for further vulnerabilities related to the discovered vulnerability; 
 
–you must not carry out DDoS or other attacks that may damage or otherwise affect the reliability, integrity and availability of information systems, services or data managed by “Litgrid”; 
 
–you must not seek or attempt to take any actions that would allow third parties (more than is necessary to validate) to monitor, record, intercept, acquire, retain, disclose, copy, modify, destroy, corrupt, or dispose of the data controlled and (or) processed by “Litgrid”; 
 
–you must not use social engineering attacks, try to guess passwords, use illegally obtained passwords, and manipulate “Litgrid” employees or other persons (e.g. contractors) with access to non-public information; 
 
–you must not attempt to physically affect the infrastructure or attempt to use physical means (attempting to enter the premises, facilities, damaging technical equipment); 
 
–you must not to attempt to exploit identified vulnerabilities for financial gain or in breach of the requirements of the legislation of the Republic of Lithuania; 
 
–you must not share information about the detected vulnerability except with “Litgrid” and (or) the National Cyber Security Centre without notifying “Litgrid” and agreeing to the terms and conditions of the disclosure of the information with  “Litgrid”. 
 
What kind of content do we expect you to report concerning vulnerabilities and (or) security weaknesses? 
 
If you think you have found a vulnerability or security weakness in the systems of Litgrid, please report it by filling in the form below and sending it to by email [email protected]
 
For information security please encrypt the email using our PGP key: 
 
-----BEGIN PGP PUBLIC KEY BLOCK-----  
mDMEZCQZ8xYJKwYBBAHaRw8BAQdAvcJz19zMRA302EHv/djooCaNjkNsyayjki5M  
W4hTgl20KkluY2lkZW50YWkgTGl0Z3JpZCA8aW5jaWRlbnRhaUBsaXRncmlkLmV1  
PoiZBBMWCgBBFiEEbhFBfltQfFQrrdznjlkmThhvxVQFAmQkGfMCGwMFCQloiJ0F  
CwkIBwICIgIGFQoJCAsCBBYCAwECHgcCF4AACgkQjlkmThhvxVSzGAEAlsC2f6Bo  
KF1qBYnirsKXTB2U7R07vR/CPfFRWEPzO8wA/iED2rGQCBf9OylytaAGbkMBMkcc  
w3kvR/EnBHRmFzYKuDgEZCQZ8xIKKwYBBAGXVQEFAQEHQDG/5s8dZifXN1lglMqv  
WcyqsHWomOGgg9fSizXMog9uAwEIB4h+BBgWCgAmFiEEbhFBfltQfFQrrdznjlkm  
ThhvxVQFAmQkGfMCGwwFCQloiJ0ACgkQjlkmThhvxVT0ZgD6A7EgsT++iAgr3ksi  
hLelSPNPzLbvHxAeNrbSx5a3lDkA/12jmluGk5UMzshvlmmh/r77ZgKx61irj+NL  
wNdEY5YF  
=YtFv  
-----END PGP PUBLIC KEY BLOCK-----  
  
 
Detailed information about a vulnerability or a gap is essential for us to be able to confirm or deny its presence immediately and, if confirmed, to take measures to correct it as soon as possible.  
 
Your contact details are important for us to be able to contact you to elaborate on the vulnerability or weakness and to fix it more quickly if it is confirmed.  
 
More information on the processing of personal data: https://www.litgrid.eu/index.php/about-us/personal-data-protection/32018  
 
Can you make public information about the vulnerability and (or) weakness you have discovered? 
 
You will be able to publish information about the vulnerability in accordance with the procedures set out in the Description after we have resolved the vulnerability or determined that there is no vulnerability. We recommend that you consult “Litgrid” on a case-by-case basis at the following email address [email protected].