Developer docs
API playgroundTry for free, no card

Search company profiles

Dutch Institute for Vulnerability Disclosure

Full company profile

uuid00223cp

Namestring
Dutch Institute for Vulnerability Disclosure
Legal namestring
Stichting Dutch Institute for Vulnerability Disclosure
Websiteurl
divd.nl
Company typeenum
Private
Founded yearint
2019
Operating statusenum
Operating
Ownership categoryenum
Headcount rangeband
101–250
akta.pro rankint
HeadquartersDen Haag, Netherlands
HQ citystring
Den Haag
HQ countrystring
Netherlands
HQ regionstring
Europe
Markets served

Serves global market

Offices1 record

Each record includes

City, Country, Type, Description, Source

Keyword5 values
coordinated vulnerability disclosure, internet-wide vulnerability scanning, CVE numbering authority, incident response services, responsible disclosure
Industry2 codes
1Security Systems Monitoring & Dispatch (SOC/Remote Guarding)
CodeIMAIAEAFPrimaryYes
2Endpoint Forensics & Incident Response (DFIR)
CodeHDADAEAJPrimaryNo
NAICS code1 code
  • Security Systems Services (except Locksmiths)561621
SIC code1 code
  • Services-Detective, Guard & Armored Car Services7381
Product category
Cybersecurity Services
Social media profiles3 records
GTM motion1 record

Each record includes

Type, Description, Source

Revenue model1 record
1Donations and Grants
TypeOthers
Description

DIVD is a non-profit organization funded through donations and grants. The organization accepts donations from individuals and organizations. Several partners provide financial support including NCTV (funding for 2023–2025), SIDN Fund, Digital Trust Center (funding in 2022), Topsector Energie, Bureau Veritas, ESET, and VMware Foundation (through licenses and hardware funding). Board members are volunteers and receive no compensation.

divd.nl
Marketing channels7 records

Each record includes

Title, Type, Stage, Description, Source

Distribution channels5 records

Each record includes

Title, Type, Scope, Target buyer, Description, Source

Cost components5 values
Technology or R&D, Infrastructure, Operations, Personnel, Marketing or Sales
Pricing details1 tier
1Free Coordinated Vulnerability Disclosure Services
ModelFreemiumBilling cadenceMonthly
Notes

DIVD provides all services for free - scanning the internet for vulnerabilities, notifying affected organizations, assigning CVE IDs, and publishing research reports. No fees are charged for any of these services.

divd.nl
GTM typeB2B
B2B
Offering typeServices
Services
Core offering1 text field

DIVD is a volunteer-run non-profit that performs internet-wide vulnerability scanning, assigns CVE identifiers as an official CVE Numbering Authority (Root CNA under ENISA), and coordinates disclosure of discovered vulnerabilities to affected organizations and individuals. The organization operates a Computer Security Incident Response Team (CSIRT) that publishes case files, notifies vulnerable system owners via direct email, and analyzes leaked credential databases to warn victims of compromise (including via the Operation Endgame collaboration with Dutch Police).

Differentiator
Functional benefit
Problem solved
Quantifiable outcome1 of 4 values shown
  • Over 1.4 million vulnerable IP addresses notified
+3 more records
Product overview1 text field

Dutch Institute for Vulnerability Disclosure (DIVD) is a non-profit research institute operated by volunteers. It is not a traditional product company; rather, it provides coordinated vulnerability disclosure services, operating as an official CVE Numbering Authority (CNA). Its core offerings are its CSIRT operations (incident response, vulnerability scanning, and victim notification) and its CNA function (CVE ID assignment and disclosure management). Supporting these are DIVD Academy (educational e-learning), the DIVD Careers Portal (Google Workspace-hosted recruitment), and DIVD Community (Slack-based collaboration). The organization has a global reach and operates entirely for free, following principles of open, honest, and collaborative responsible disclosure.

Product and service4 records
1DIVD CSIRT
CategoryCybersecurity Services
Description

Computer Security Incident Response Team that handles case management, vulnerability coordination, CVE assignment, and victim notification for discovered vulnerabilities. Operates as an official CVE Numbering Authority within the CVE ecosystem.

2DIVD CNA (CVE Numbering Authority)
CategoryCybersecurity Services
Description

Official CVE Numbering Authority function that assigns unique CVE identifiers to vulnerabilities discovered by DIVD researchers or reported to DIVD for coordinated disclosure, within a defined scope of software vulnerabilities not covered by other CNAs. Publishes CVE records following a structured disclosure timeline.

3DIVD Academy
CategoryCybersecurity Services
Description

Educational e-learning platform providing introductory courses (e.g., DIVD Introduction), training materials, and advanced research training for DIVD volunteer researchers. Engages in energy-sector research collaborations.

4Operation Endgame Victim Notification
CategoryCybersecurity Services
Description

Victim notification service operated in collaboration with Dutch National Police and trusted partners (Have I Been Pwned, Spamhaus, NCSC, CSIRT-DSP, Digital Trust Center) to identify and notify victims of compromised credentials found in botnet and malware operations data.

Scale indicator7 records

Each record includes

Type, Value, Description, Source

Partnership19 partners
Strategic tierCoreTypeTechnology or IntegrationAnnounced on2021-01-01
Description

Erik Bais, owner of A2B-Internet helped DIVD get their own Autonomous System, providing DIVD with its own IP addresses (AS50559, 194.5.73.0/24) to scan from. This enables DIVD to conduct internet-wide vulnerability scanning from its own infrastructure.

Strategic tierCoreTypeTechnology or Integration
Description

Atom86 sponsors connectivity and rack space for DIVD's scanning infrastructure, enabling the organization's internet-wide vulnerability scanning operations.

Strategic tierCoreTypeTechnology or Integration
Description

BIT sponsors hosting space for DIVD's websites and mail server capacity, supporting DIVD's web presence and communication infrastructure.

Strategic tierCoreTypeTechnology or Integration
Description

Cisco provides free training to DIVD and DIVD.academy, contributing to the professional development of DIVD's volunteer researchers.

Strategic tierCoreTypeStrategic or Co-development Partner
Description

The Digital Trust Center provided funding to DIVD in 2022 and is listed as a trusted information sharing partner for coordinated vulnerability disclosure. DTC also provides funding for DIVD's vulnerability research.

Strategic tierCoreTypeStrategic or Co-development Partner
Description

DIVD collaborates with ElaadNL on the Energy project, converting newly discovered vulnerabilities in electric vehicle charging infrastructure and energy systems into CVEs.

Strategic tierCoreTypeTechnology or Integration
Description

Elastic sponsors DIVD by providing an Enterprise license, enabling DIVD's teams to perform large-scale data analysis and power their SIEM solution for effective vulnerability detection and response.

Strategic tierCoreTypeStrategic or Co-development Partner
Description

DIVD works together with ENCS on the Energy project to convert newly discovered vulnerabilities in energy sector systems into CVEs, particularly in smart grid and critical infrastructure.

9Internet Cleanup Foundation
Strategic tierMinorTypeStrategic or Co-development Partner
Description

The Internet Cleanup Foundation shares DIVD's mission of making the digital world safer and collaborates on vulnerability disclosure efforts.

divd.nl
Strategic tierCoreTypeTechnology or Integration
Description

DIVD has its office at LunaVia, which also helps with administrative tasks and acquiring funding for DIVD Academy.

Strategic tierCoreTypeStrategic or Co-development Partner
Description

Rapid7 supports DIVD by sharing their scanning data for research purposes, contributing to DIVD's vulnerability detection capabilities.

Strategic tierMinorTypeOthers
Description

Schouten Zekerheid Makelaars in Assurantiën serves as DIVD's insurance intermediary and supports the organization and its cause.

Strategic tierCoreTypeTechnology or Integration
Description

Schuberg Philis has provided DIVD with support from some of their employees and equipment for DIVD's scanning infrastructure.

Strategic tierMinorTypeStrategic or Co-development Partner
Description

SecurityBridge supports DIVD with in-depth expertise on SAP security and provides resources to help scan the internet for vulnerabilities in SAP systems.

Strategic tierMinorTypeStrategic or Co-development Partner
Description

SUPERP supports DIVD by allowing some of their employees to contribute to Research and CSIRT activities.

Strategic tierMinorTypeStrategic or Co-development Partner
Description

The Green Village is organizing hack events together with DIVD, promoting cybersecurity education and awareness.

Strategic tierCoreTypeStrategic or Co-development Partner
Description

Fox-IT scanned for vulnerable instances and collaborated with DIVD on Qlik Sense vulnerability research and Project Melissa, sharing scanning data for research purposes.

Strategic tierCoreTypeStrategic or Co-development Partner
Description

Northwave collaborated with DIVD as part of Project Melissa, contributing research on how Cactus ransomware exploits Qlik Sense vulnerabilities.

Strategic tierCoreTypeStrategic or Co-development Partner
Description

Responders BV collaborated with DIVD as part of Project Melissa on identifying potential Cactus ransomware victims through Qlik Sense vulnerability research.

Recent move7 records

Each record includes

Date, Type, Title, Description, Source

Expansion highlight6 records

Each record includes

Type, Description

Peers10 records
TypeDirect peer
Description

Largest commercial bug bounty and vulnerability disclosure platform. Operates a coordinated disclosure program and HackerOne-powered CVE Numbering Authority, directly comparable to DIVD's CNA/CSIRT function but delivered as a paid commercial product rather than a free non-profit service.

TypeDirect peer
Description

Commercial crowdsourced cybersecurity platform offering bug bounty, vulnerability disclosure, and attack surface management. Direct peer in coordinated disclosure and CVE handling, differentiated by its paid, platform-based model versus DIVD's free volunteer model.

TypeDirect peer
Description

European bug bounty and vulnerability disclosure platform headquartered in Belgium. Direct comparable in coordinated disclosure mechanics and target customer base, and notably employs DIVD's CSIRT Department Head in a senior triage role, indicating close ecosystem ties.

TypeOthers
Description

EU's cybersecurity agency and DIVD's Root CVE Numbering Authority. Sets the regulatory framework within which DIVD operates and through which DIVD's CVE authority is recognized; not a competitor but a structural enabler and an increasingly important counterparty.

TypeBroad incumbent
Description

US federal cybersecurity agency operating a major CSIRT, vulnerability management, and coordinated disclosure function (including the Known Exploited Vulnerabilities catalog). Provides a useful scale and scope comparison for a future EU-level equivalent that DIVD could evolve toward.

TypeDirect peer
Description

Breach notification service run by Troy Hunt that operates as a trusted information sharing partner in DIVD's Operation Endgame work. Directly comparable in victim notification mechanics, with a larger consumer-facing brand and global individual user base.

TypeDirect peer
Description

Dutch responsible disclosure and bug bounty platform that hosts DIVD's own responsible disclosure portal. Operates in the same Dutch market and coordinates vulnerability reports to and from organizations, making it the closest national peer to DIVD.

TypeOthers
Description

Dutch national CSIRT and DIVD's listed trusted information sharing partner. Performs overlapping vulnerability coordination, threat intelligence, and disclosure work, but as a government agency rather than an independent non-profit, and is itself a DIVD partner rather than a competitor.

TypeDirect peer
Description

European bug bounty and responsible disclosure platform operating a Vulnerability Disclosure Program (VDP) and Bug Bounty service. Comparable to DIVD in coordinated disclosure scope and European customer focus, though delivered as a paid commercial service.

TypeBroad incumbent
Description

Original federally-funded CSIRT based at Carnegie Mellon University, coordinating vulnerability disclosure globally for over 30 years. Direct operational analog to DIVD CSIRT and a fellow CVE Numbering Authority, with a broader historical scope and US-centric remit.

Market position
Strengths4 records

Each record includes

Headline, Details, Source

Weaknesses4 records

Each record includes

Headline, Details, Source

Competitive moat5 records

Each record includes

Type, Details

Key risks5 records

Each record includes

Headline, Details, Source

Key highlights7 records

Each record includes

Headline, Details, Source

Customer concentration

Classification, Details

Named customers9 records

Each record includes

Name, Industry, Type, Use case, Source, UUID

Segment5 records

Each record includes

Title, Type, Primary, Description, Pain point addressed, Use case, Source

Ideal customer profile4 records

Each record includes

Profile, Firmographic size, Sales motion, Sales cycle length, Buying structure, Purchase trigger, Buyer persona, Geography, Industry vertical, Primary use case, Description, Pain points, Evidence proof points, Target buyer

Technology focused
Yes
API detail
Has APIbool
No

Docs URL, Description

Integration1 record

Each record includes

Title, Type, Description, Source

AI maturity
App detail

Has app

Feature5 records

Each record includes

Title, Differentiator, Description, Source

Core technology
Revenue estimate
Valuation estimate
Number of profiles
Profiles5 records

Each record includes

Name, Designation, Designation category, Overview, Profile commentary, Source

No data
No data
Funding overview

Funding stage, Last funding date, Total funding USD

Funding rounds

Each record includes

Round, Amount USD, Date, Pre money valuation, Total investors, Investors, News

Investors

Each record includes

Name, Type, Date of entry, Rounds participated, Website

Funding detail is available on the Subscription and Enterprise plan.Contact sales →

M&A

Each record includes

Name, Acquisition type, Announced date, Completed date, Status, Website, News

Investment

Each record includes

Name, Round, Announced date, Lead investor, Website, News

M&A and investment is available on the Subscription and Enterprise plan.Contact sales →

Dutch Institute for Vulnerability Disclosure

Cybersecurity Servicesdivd.nl

Dutch Institute for Vulnerability Disclosure firmographics

Firmographics
Name
Dutch Institute for Vulnerability Disclosure
Legal name
Stichting Dutch Institute for Vulnerability Disclosure
Website
https://divd.nl
Company type
Private
Founded year
2019
Operating status
Operating
Headcount range
101–250 employees
Ownership category
akta.pro rank

Dutch Institute for Vulnerability Disclosure industry classification

Industry
Product category
Cybersecurity Services
NAICS
Security Systems Services (except Locksmiths) (561621)
SIC
Services-Detective, Guard & Armored Car Services (7381)
akta.pro primary industry
Security Systems Monitoring & Dispatch (SOC/Remote Guarding) (IMAIAEAF)
akta.pro secondary industry
Endpoint Forensics & Incident Response (DFIR) (HDADAEAJ)

Keywords

  • Coordinated vulnerability disclosure
  • Internet-wide vulnerability scanning
  • CVE numbering authority
  • Incident response services
  • Responsible disclosure

Where Dutch Institute for Vulnerability Disclosure is headquartered

Location

Headquarters

HQ city
Den Haag
HQ country
Netherlands
HQ region
Europe

Offices1 record

Markets served

Dutch Institute for Vulnerability Disclosure business model

Business model
GTM type
B2B
Offering type
Services
Cost components
Technology or R&D, Infrastructure, Operations, Personnel, Marketing or Sales

Revenue model

  1. Donations and Grants: DIVD is a non-profit organization funded through donations and grants. The organization accepts donations from individuals and organizations. Several partners provide financial support including NCTV (funding for 2023–2025), SIDN Fund, Digital Trust Center (funding in 2022), Topsector Energie, Bureau Veritas, ESET, and VMware Foundation (through licenses and hardware funding). Board members are volunteers and receive no compensation.

Pricing tiers

ModelBillingPrice
FreemiumMonthlyFree Coordinated Vulnerability Disclosure Services

Go-to-market motion1 record

Distribution channels5 records

Marketing channels7 records

Dutch Institute for Vulnerability Disclosure product offering

Product offering

Core offering

DIVD is a volunteer-run non-profit that performs internet-wide vulnerability scanning, assigns CVE identifiers as an official CVE Numbering Authority (Root CNA under ENISA), and coordinates disclosure of discovered vulnerabilities to affected organizations and individuals. The organization operates a Computer Security Incident Response Team (CSIRT) that publishes case files, notifies vulnerable system owners via direct email, and analyzes leaked credential databases to warn victims of compromise (including via the Operation Endgame collaboration with Dutch Police).

Product overview

Dutch Institute for Vulnerability Disclosure (DIVD) is a non-profit research institute operated by volunteers. It is not a traditional product company; rather, it provides coordinated vulnerability disclosure services, operating as an official CVE Numbering Authority (CNA). Its core offerings are its CSIRT operations (incident response, vulnerability scanning, and victim notification) and its CNA function (CVE ID assignment and disclosure management). Supporting these are DIVD Academy (educational e-learning), the DIVD Careers Portal (Google Workspace-hosted recruitment), and DIVD Community (Slack-based collaboration). The organization has a global reach and operates entirely for free, following principles of open, honest, and collaborative responsible disclosure.

Differentiator

Problem solved

Functional benefit

Products and services

  • DIVD CSIRT Computer Security Incident Response Team that handles case management, vulnerability coordination, CVE assignment, and victim notification for discovered vulnerabilities. Operates as an official CVE Numbering Authority within the CVE ecosystem.
  • DIVD CNA (CVE Numbering Authority) Official CVE Numbering Authority function that assigns unique CVE identifiers to vulnerabilities discovered by DIVD researchers or reported to DIVD for coordinated disclosure, within a defined scope of software vulnerabilities not covered by other CNAs. Publishes CVE records following a structured disclosure timeline.
  • DIVD Academy Educational e-learning platform providing introductory courses (e.g., DIVD Introduction), training materials, and advanced research training for DIVD volunteer researchers. Engages in energy-sector research collaborations.
  • Operation Endgame Victim Notification Victim notification service operated in collaboration with Dutch National Police and trusted partners (Have I Been Pwned, Spamhaus, NCSC, CSIRT-DSP, Digital Trust Center) to identify and notify victims of compromised credentials found in botnet and malware operations data.

Quantifiable outcome

  • Over 1.4 million vulnerable IP addresses notified
  • +3 more outcomes

Companies that use Dutch Institute for Vulnerability Disclosure

Customer profile

Named customers9 records

Segments5 records

Ideal customer profiles4 records

Dutch Institute for Vulnerability Disclosure technology and API

Technology

Technology focussed Yes

API detail

Has API
No
API docs
API detail

Core technology

AI maturity

App detail

Integration1 record

Feature5 records

Dutch Institute for Vulnerability Disclosure partnerships and signals

Strategic signal

Partnerships

19 partnerships are on record, tiered core and minor.

  • A2B InternetcoreTechnology or Integration · 1 January 2021Erik Bais, owner of A2B-Internet helped DIVD get their own Autonomous System, providing DIVD with its own IP addresses (AS50559, 194.5.73.0/24) to scan from. This enables DIVD to conduct internet-wide vulnerability scanning from its own infrastructure.
  • Atom86coreTechnology or IntegrationAtom86 sponsors connectivity and rack space for DIVD's scanning infrastructure, enabling the organization's internet-wide vulnerability scanning operations.
  • BITcoreTechnology or IntegrationBIT sponsors hosting space for DIVD's websites and mail server capacity, supporting DIVD's web presence and communication infrastructure.
  • CiscocoreTechnology or IntegrationCisco provides free training to DIVD and DIVD.academy, contributing to the professional development of DIVD's volunteer researchers.
  • Digital Trust Center (DTC)coreStrategic or Co-development PartnerThe Digital Trust Center provided funding to DIVD in 2022 and is listed as a trusted information sharing partner for coordinated vulnerability disclosure. DTC also provides funding for DIVD's vulnerability research.
  • ElaadNLcoreStrategic or Co-development PartnerDIVD collaborates with ElaadNL on the Energy project, converting newly discovered vulnerabilities in electric vehicle charging infrastructure and energy systems into CVEs.
  • ElasticcoreTechnology or IntegrationElastic sponsors DIVD by providing an Enterprise license, enabling DIVD's teams to perform large-scale data analysis and power their SIEM solution for effective vulnerability detection and response.
  • European Network for Cyber Security (ENCS)coreStrategic or Co-development PartnerDIVD works together with ENCS on the Energy project to convert newly discovered vulnerabilities in energy sector systems into CVEs, particularly in smart grid and critical infrastructure.
  • Internet Cleanup FoundationminorStrategic or Co-development PartnerThe Internet Cleanup Foundation shares DIVD's mission of making the digital world safer and collaborates on vulnerability disclosure efforts.
  • LunaViacoreTechnology or IntegrationDIVD has its office at LunaVia, which also helps with administrative tasks and acquiring funding for DIVD Academy.
  • Rapid7coreStrategic or Co-development PartnerRapid7 supports DIVD by sharing their scanning data for research purposes, contributing to DIVD's vulnerability detection capabilities.
  • Schouten ZekerheidminorOthersSchouten Zekerheid Makelaars in Assurantiën serves as DIVD's insurance intermediary and supports the organization and its cause.
  • Schuberg PhiliscoreTechnology or IntegrationSchuberg Philis has provided DIVD with support from some of their employees and equipment for DIVD's scanning infrastructure.
  • SecurityBridgeminorStrategic or Co-development PartnerSecurityBridge supports DIVD with in-depth expertise on SAP security and provides resources to help scan the internet for vulnerabilities in SAP systems.
  • SUPERPminorStrategic or Co-development PartnerSUPERP supports DIVD by allowing some of their employees to contribute to Research and CSIRT activities.
  • The Green VillageminorStrategic or Co-development PartnerThe Green Village is organizing hack events together with DIVD, promoting cybersecurity education and awareness.
  • Fox-ITcoreStrategic or Co-development PartnerFox-IT scanned for vulnerable instances and collaborated with DIVD on Qlik Sense vulnerability research and Project Melissa, sharing scanning data for research purposes.
  • NorthwavecoreStrategic or Co-development PartnerNorthwave collaborated with DIVD as part of Project Melissa, contributing research on how Cactus ransomware exploits Qlik Sense vulnerabilities.
  • Responders BVcoreStrategic or Co-development PartnerResponders BV collaborated with DIVD as part of Project Melissa on identifying potential Cactus ransomware victims through Qlik Sense vulnerability research.

Scale indicators7 records

Recent moves7 records

Expansion highlights6 records

Dutch Institute for Vulnerability Disclosure competitors and assessment

Company assessment

Direct peers

  • HackerOne: Largest commercial bug bounty and vulnerability disclosure platform. Operates a coordinated disclosure program and HackerOne-powered CVE Numbering Authority, directly comparable to DIVD's CNA/CSIRT function but delivered as a paid commercial product rather than a free non-profit service.
  • Bugcrowd: Commercial crowdsourced cybersecurity platform offering bug bounty, vulnerability disclosure, and attack surface management. Direct peer in coordinated disclosure and CVE handling, differentiated by its paid, platform-based model versus DIVD's free volunteer model.
  • Intigriti: European bug bounty and vulnerability disclosure platform headquartered in Belgium. Direct comparable in coordinated disclosure mechanics and target customer base, and notably employs DIVD's CSIRT Department Head in a senior triage role, indicating close ecosystem ties.
  • Have I Been Pwned: Breach notification service run by Troy Hunt that operates as a trusted information sharing partner in DIVD's Operation Endgame work. Directly comparable in victim notification mechanics, with a larger consumer-facing brand and global individual user base.
  • Zerocopter: Dutch responsible disclosure and bug bounty platform that hosts DIVD's own responsible disclosure portal. Operates in the same Dutch market and coordinates vulnerability reports to and from organizations, making it the closest national peer to DIVD.
  • YesWeHack: European bug bounty and responsible disclosure platform operating a Vulnerability Disclosure Program (VDP) and Bug Bounty service. Comparable to DIVD in coordinated disclosure scope and European customer focus, though delivered as a paid commercial service.

Others

  • ENISA (European Union Agency for Cybersecurity): EU's cybersecurity agency and DIVD's Root CVE Numbering Authority. Sets the regulatory framework within which DIVD operates and through which DIVD's CVE authority is recognized; not a competitor but a structural enabler and an increasingly important counterparty.
  • NCSC-NL (National Cyber Security Center Netherlands): Dutch national CSIRT and DIVD's listed trusted information sharing partner. Performs overlapping vulnerability coordination, threat intelligence, and disclosure work, but as a government agency rather than an independent non-profit, and is itself a DIVD partner rather than a competitor.

Broad incumbents

  • CISA (Cybersecurity and Infrastructure Security Agency): US federal cybersecurity agency operating a major CSIRT, vulnerability management, and coordinated disclosure function (including the Known Exploited Vulnerabilities catalog). Provides a useful scale and scope comparison for a future EU-level equivalent that DIVD could evolve toward.
  • CERT Coordination Center (CERT/CC): Original federally-funded CSIRT based at Carnegie Mellon University, coordinating vulnerability disclosure globally for over 30 years. Direct operational analog to DIVD CSIRT and a fellow CVE Numbering Authority, with a broader historical scope and US-centric remit.

Market position

Strengths4 records

Weaknesses4 records

Competitive moat5 records

Key risks5 records

Key highlights7 records

Customer concentration

Dutch Institute for Vulnerability Disclosure social profiles

Digital presence

Dutch Institute for Vulnerability Disclosure financial estimates

Financial estimate

Revenue estimate

Valuation estimate

Dutch Institute for Vulnerability Disclosure leadership team

Management profile

Number of profiles

Profiles5 records

Dutch Institute for Vulnerability Disclosure funding detail

Funding detail

Funding overview

Funding rounds

Investors

Funding detail is available on the Subscription and Enterprise plan.Contact sales →

Dutch Institute for Vulnerability Disclosure M&A and investment

M&A and investment

M&A

Investments

M&A and investment is available on the Subscription and Enterprise plan.Contact sales →

Frequently asked questions about Dutch Institute for Vulnerability Disclosure

What does Dutch Institute for Vulnerability Disclosure do?

DIVD is a volunteer-run non-profit that performs internet-wide vulnerability scanning, assigns CVE identifiers as an official CVE Numbering Authority (Root CNA under ENISA), and coordinates disclosure of discovered vulnerabilities to affected organizations and individuals. The organization operates a Computer Security Incident Response Team (CSIRT) that publishes case files, notifies vulnerable system owners via direct email, and analyzes leaked credential databases to warn victims of compromise (including via the Operation Endgame collaboration with Dutch Police).

Is Dutch Institute for Vulnerability Disclosure a public or private company?

Dutch Institute for Vulnerability Disclosure is a private company. It is classified as nonprofit foundation owned and is currently operating.

When was Dutch Institute for Vulnerability Disclosure founded?

Dutch Institute for Vulnerability Disclosure was founded in 2019. It employs 101 to 250 people.

Where is Dutch Institute for Vulnerability Disclosure based?

Dutch Institute for Vulnerability Disclosure is headquartered in Den Haag, Netherlands, in the Europe region.

How does Dutch Institute for Vulnerability Disclosure make money?

One revenue line is on record: donations and Grants.

Who are Dutch Institute for Vulnerability Disclosure's main competitors?

Direct peers on record are HackerOne, Bugcrowd, Intigriti, Have I Been Pwned, Zerocopter and YesWeHack. Others are ENISA (European Union Agency for Cybersecurity) and NCSC-NL (National Cyber Security Center Netherlands). Broad incumbents are CISA (Cybersecurity and Infrastructure Security Agency) and CERT Coordination Center (CERT/CC).

Does Dutch Institute for Vulnerability Disclosure have an API?

No public API is recorded for Dutch Institute for Vulnerability Disclosure.

What industry is Dutch Institute for Vulnerability Disclosure in?

Dutch Institute for Vulnerability Disclosure's product category is Cybersecurity Services. Its primary akta.pro industry code is IMAIAEAF, Security Systems Monitoring & Dispatch (SOC/Remote Guarding), with a secondary code of HDADAEAJ, Endpoint Forensics & Incident Response (DFIR). Its NAICS code is 561621 and its SIC code is 7381.

Unlock the full company data

50 free credits on sign-up, no credit card required.

Contact sales
Live signals
BleepingcomputerAutomated AI agent used to breach cybersecurity nonprofit DIVDThe Dutch Institute for Vulnerability Disclosure (DIVD) was hacked by an autonomous AI agent, which the organization called "loud and very very messy." The attack exploited an undisclosed technical vulnerability, and DIVD has not disclosed the flaw's type or patch state. The organization will provide a more detailed update on October 1 and notify other possible victims.IndustrialcyberENCS and DIVD partner to coordinate vulnerability disclosure and CVE registration for critical infrastructureENCS and DIVD signed a Memorandum of Understanding at ENCS's annual General Assembly in The Hague to strengthen cooperation on vulnerability discovery, disclosure, and resolution affecting Europe's power grids and critical infrastructure. The agreement combines ENCS's security testing expertise with DIVD's coordinated vulnerability disclosure and CVE registration experience, and includes the launch of a high-power IoT security testing programme. The collaboration aligns with EU focus on critical infrastructure vulnerability management under the Cyber Resilience Act, as digitalization of energy systems creates cross-border cybersecurity risks.PR NewswireCity of The Hague: Free cybersecurity support program for 200 humanitarian NGOs in The HagueA consortium comprising the CyberPeace Institute, The Hague Humanity Hub, DIVD, and CSIRT.global is launching a free cybersecurity support program for approximately 200 humanitarian NGOs in The Hague over the next 1.5 years. Co-funded by the City of The Hague, the initiative aims to strengthen cyber capacity through assessments, tools, and training to mitigate rising threats against organizations operating in conflict zones.SiliconANGLEAs fake updates target victims, Kaseya allegedly knew of exploited vulnerability in April - SiliconANGLEKaseya users are being targeted with fake Microsoft security updates that install Cobalt Strike, following a REvil ransomware attack. The Dutch Institute for Vulnerability Disclosure disclosed one of the exploited vulnerabilities to Kaseya in early April, but Kaseya's patches did not address all issues. Kaseya has not commented on the claim.