Vulnerability disclaimer
How to report a security vulnerability
Orica welcomes reports of suspected security vulnerabilities from customers, security researchers, suppliers, partners, and members of the public.
This statement explains how to report a suspected vulnerability affecting an Orica website, portal, application, system, service, or digital product. It also explains what we ask of people who conduct security research and what you can expect from Orica after submitting a report.
When to contact us
You do not need to confirm that a vulnerability exists before contacting us. If you are unsure whether something is a security vulnerability, please report it and provide as much detail as you can.
What you can report
You may report suspected vulnerabilities affecting Orica owned or Orica operated:
- public websites;
- customer, supplier, or partner portals;
- applications and mobile apps;
- Cloud hosted services;
- Internet accessible systems;
- APIs or online services; and
- digital products, software, firmware, or connected product components provided by Orica.
This statement does not authorise testing of systems, services, products, or environments that are not owned or operated by Orica.
How to report a vulnerability
Please email suspected vulnerability reports to: [email protected]
To help us assess your report, please include as much detail as you can. If you are a customer, please include what you observed, where you observed it, and any screenshots, error messages, or other information that may help us understand the issue.
- your name and contact details, if you are willing to provide them;
- the affected Orica website, portal, application, system, service, or digital product;
- a clear description of what you observed;
- the date and time you noticed the issue, if known;
- screenshots, error messages, or other supporting information; and
- whether you accessed any personal, confidential, customer, operational, or sensitive information.
If you are a security researcher, please also include technical details where relevant, such as steps to reproduce the issue, affected versions, API endpoints, proof-of-concept details, logs, and your assessment of the potential impact.
If your report contains sensitive information, please tell us in your email so we can discuss an appropriate way to exchange further details.
What you can expect from Orica
Orica will review reports submitted through this channel and will aim to acknowledge receipt within five business days where possible. We may contact you for more information if needed.
We will assess reported issues, prioritise confirmed vulnerabilities based on risk, and take appropriate action to address them. This may include working with relevant internal teams, product teams, suppliers, or third parties.
Where practical, we may provide updates on the status of our review. Some details may not be shared where doing so could create security, privacy, legal, contractual, or operational risks.
Where a reported issue affects an Orica digital product and may trigger regulatory reporting or customer notification obligations, Orica will assess and manage those obligations in accordance with applicable laws and regulations.
Orica does not currently operate a bug bounty program and does not offer financial rewards for vulnerability reports.
Responsible security research expectations
If you conduct security research, we ask that you:
- act in good faith and only test to the extent necessary to confirm the issue;
- avoid causing disruption, degradation, or damage to Orica systems, services, products, data, or operations;
- do not intentionally access, copy, alter, delete, download, or disclose data that does not belong to you;
- stop testing and notify Orica immediately if you inadvertently access personal, confidential, customer, operational, or sensitive information;
- keep vulnerability details confidential until Orica has had a reasonable opportunity to investigate and address the issue; and
- comply with applicable laws and regulations.
Activities that are not authorised
The following activities are not authorised:
- social engineering, phishing, vishing, smishing, or impersonation;
- physical security testing or unauthorised access to Orica facilities or customer sites;
- testing that may affect safety, operational technology, industrial control systems, manufacturing systems, mining operations, explosives-related operations, or other operational environments;
- denial-of-service or high-volume testing;
- destructive testing or actions that may affect availability, integrity, or confidentiality;
- malware deployment, ransomware simulation, persistence, or backdoor creation;
- credential stuffing, password spraying, brute-force attacks, or attempts to compromise accounts;
- accessing, copying, altering, deleting, downloading, or exfiltrating data;
- testing third-party systems, services, or products not owned or operated by Orica; and
- actions that breach applicable laws, regulations, contracts, privacy obligations, or intellectual property rights.
Coordinated disclosure
Orica supports coordinated vulnerability disclosure.
We ask that you do not publicly disclose or share details of a suspected vulnerability until Orica has had a reasonable opportunity to investigate and address the issue. Public disclosure before a vulnerability is addressed may increase risk to Orica, our customers, employees, suppliers, partners, or the public.
If you intend to publicly disclose a vulnerability, please notify Orica in advance so we can work with you on an appropriate disclosure approach and timeline.
Recognition
Orica appreciates people who responsibly report security vulnerabilities.
Where appropriate, and with your consent, Orica may acknowledge your contribution. Recognition is discretionary and may not be available where a report involves activity that is unlawful, harmful, disruptive, or inconsistent with this statement.
Other security or privacy enquiries
This vulnerability reporting channel is intended for suspected security vulnerabilities. For other security, privacy, customer support, or general enquiries, please use the relevant Orica contact channel.
