サイバーセキュリティ戦略を効率的に進めるための5つの実践法 2023年6月02日 The number of cyber attacks continues to grow. Worldwide, according to researchers at Check Point Research, there was an increase of 28% in the third quarter of 2022 compared to the same period in 2021. Companies are obvious targets – the average number of attacks is now more than one per week. 続きを読む
CI&T、オーストラリアとニュージーランドに事業拡大! 2020年8月28日 グローバル企業のデジタル変革を支援するCI&Tは、本日、オーストラリアとニュージーランド(ANZ)への事業進出を発表いたします。 続きを読む
ITモダナイゼーション:ビジネスの競争力強化の鍵となる3つのポイント 2023年6月26日 ITモダナイゼーションとは? 近年、経済産業省やデジタル庁の取り組みを筆頭に、多くの企業や組織がデジタルトランスフォーメーション(DX)を推進し、ビジネスの競争力向上とイノベーションを促進しています。 続きを読む
Responsible Vulnerability Disclosure Our approach to securitySecurity is a shared responsibility. We genuinely appreciate the work of security researchers, ethical hackers, and members of the cybersecurity community who help make technology safer.While we do not operate a bug bounty or reward program, we welcome responsible, good-faith vulnerability reports that help us identify and mitigate potential risks. This policy explains how to report security issues safely and what you can expect from us in return.ScopeThis policy applies only to systems, applications, services, and infrastructure owned or directly operated by us.The following are out of scope:- Systems or environments owned by customers, partners, vendors, or third parties- Social engineering, phishing, or interactions with employees or users- Denial-of-service, brute-force attacks, or stress testing- Physical security testing- Findings with no practical security impact or purely informational issuesHow to report a vulnerabilityIf you believe you have identified a security vulnerability, please report it to: securitytalk@ciandt.comTo help us investigate efficiently, please include:- A clear description of the issue- The affected system, URL, endpoint, or component- Steps to reproduce the issue using a non-destructive proof of concept- The potential security impact- Suggested remediation, if available- Your preferred contact informationReports that lack sufficient detail may not be reviewed.Responsible research guidelinesWe ask that all research conducted under this policy:- Is performed in good faith and in compliance with applicable laws- Is limited to the minimum testing required to confirm the vulnerability- Does not access, modify, copy, or exfiltrate data belonging to users or systems- Stops immediately if sensitive data is encountered and is reported without delay- Avoids service disruption, performance degradation, or persistence- Does not involve lateral movement or privilege escalation beyond proof of existenceCoordinated disclosurePlease allow us a reasonable amount of time to investigate and remediate the issue before any public disclosure. Coordinated disclosure helps protect users and systems while ensuring fixes are properly validated.What you can expect from usWhen a valid report is received, we will:- Acknowledge receipt within a reasonable timeframe- Assess the report and prioritize remediation based on risk and impact- Communicate with you as needed during the investigation- Notify you once the issue has been addressedReports submitted in accordance with this policy and in good faith will not result in legal action by our organization.Bug Bounty and Compensation PolicyCI&T does not currently have a formal bug bounty program. However, we recognize and appreciate the ethical work performed by security researchers who responsibly identify and report potential security vulnerabilities. Historically, we have received and addressed vulnerability reports even in the absence of any established reward program.We invite you to share the details of the potential vulnerability with us so that we can properly analyze it. Based on our assessment and the quality and impact of the findings, we may evaluate, at our sole discretion, the possibility of providing a goodwill reward in recognition of your effort and good faith.Submitting a report does not create any contractual, financial, or legal obligation between you and our organization.Policy updatesThis policy may be updated periodically. The latest version published on our website is always the authoritative version. Contact us