Report a vulnerability
Industrial Cybersecurity Partners Ltd (ICP)
Last updated: 25/09/26
How to report
Email security@icp.business (or sales@icp.business) with a description of the issue, the affected page or URL, and the steps needed to reproduce it.
Scope
This policy covers ICP's public website at icp.business. It does not cover customer systems, operational technology (OT) or industrial control systems, or any third-party service.
Please do not
- test against customer systems or any OT or industrial control system;
- include exploit code or payloads that target live OT systems in your report;
- run denial-of-service, spam or social-engineering tests, or access, change or delete other people's data;
- share details of the issue publicly before we have had a reasonable chance to fix it.
What we will do
We aim to acknowledge reports within five working days, keep you informed while we investigate, and tell you when the issue is resolved. If you act in good faith and follow this policy, we will not pursue legal action against you for your research.
Machine-readable contact
Our contact details are also published at /.well-known/security.txt.
