Uploaded August 2026 | Updated September 2026, 12 minutes ago
Patrick Garrity (VulnCheck, US)
Coordinated Vulnerability Disclosure (CVD) is meant to create a predictable process for researchers and vendors to work together, yet researchers often bear the majority of the operational burden. Unresponsive suppliers, unclear disclosure channels, and inefficient communication workflows slow remediation and discourage future reporting.
This session introduces a researcher‑centric approach to CVD that shifts the operational load away from researchers and onto a dedicated coordination team. By validating findings, identifying the correct supplier, establishing communication channels, and managing timelines, this model allows researchers to focus on what they do best — finding vulnerabilities.
Attendees will learn how this approach differs from bug bounty programs, what patterns consistently improve vendor engagement, and what pitfalls to avoid when handling disclosures at scale. Whether you are a researcher, vendor, or PSIRT, you will leave with practical strategies to make CVD more predictable, efficient, and sustainable.
---
Patrick Garrity is a security researcher at VulnCheck where he focuses on vulnerabilities, vulnerability exploitation and threat actors.
Patrick Garrity (VulnCheck, US)
Coordinated Vulnerability Disclosure (CVD) is meant to create a predictable process for researchers and vendors to work together, yet researchers often bear the majority of the operational burden. Unresponsive suppliers, unclear disclosure channels, and inefficient communication workflows slow remediation and discourage future reporting.
This session introduces a researcher‑centric approach to CVD that shifts the operational load away from researchers and onto a dedicated coordination team. By validating findings, identifying the correct supplier, establishing communication channels, and managing timelines, this model allows researchers to focus on what they do best — finding vulnerabilities.
Attendees will learn how this approach differs from bug bounty programs, what patterns consistently improve vendor engagement, and what pitfalls to avoid when handling disclosures at scale. Whether you are a researcher, vendor, or PSIRT, you will leave with practical strategies to make CVD more predictable, efficient, and sustainable.
---
Patrick Garrity is a security researcher at VulnCheck where he focuses on vulnerabilities, vulnerability exploitation and threat actors.










