0

About UsInvestor RelationsSustainabilityNewsCareers
Suppliers
Retail Supplier
Non-Retail Supplier
Contact Us
Investor RelationsAbout UsSustainabilityNewsCareers
Suppliers
Retail Supplier
Non-Retail Supplier
Contact Us

Vulnerability Disclosure Policy

Purpose

The Vulnerability Disclosure Policy provides guidance on how independent security researchers can advise Endeavour Group of any potential or identified security vulnerabilities within Endeavour Group.

If you have any questions regarding its contents, we invite you to contact our Endeavour Group Cyber Security team at [email protected].

Scope

This Vulnerability Disclosure policy applies to independent security researchers for any internet facing systems or Software as a Service (SaaS) cloud services.

Policy

Endeavour Group holds significant amounts of information about our customers, Team Members, business partners and the communities we serve. We are entrusted with this information and care about protecting it. The security researcher community makes valuable contributions to the security of an organisation and we at Endeavour Group are eager to maintain a good relationship with this community. This relationship will help us to improve our own security.

1. Identifying Potential Security Vulnerabilities

If you believe you have discovered a security weakness (vulnerability), or potential security weakness, within Endeavour Group please report it to [email protected] as quickly as possible. 

We will try to address all identified issues in a timely manner and ask that you allow us a reasonable timeframe to review and address the issue before it is publicly disclosed. Details of any potential security vulnerabilities must not be publicly disclosed without our express written consent from an appropriately authorised endeavour group employee.

It will be viewed as a collaboration if security vulnerabilities are reported to us in accordance with this policy. In the event that a security vulnerability is not reported in accordance with this policy, we reserve all of our legal rights. 

We acknowledge that responsible security research will occur and will work with the security research community. 

The following list, which is not exhaustive, contains the types of techniques that are not permitted during research activities:

- Any activities that violate laws or regulations
- Clickjacking
- Social engineering or phishing attacks
- Accessing or attempting to access accounts or data
- Attempting to or actually destroying data
- Data exfiltration including site replication
- Denial of service (DoS) or distributed denial of service (DDoS) attack
- Physical attacks

2. How to Report a Security Vulnerability

‍To report a security vulnerability to the Endeavour Group Cyber Security team email [email protected] with the subject: INDEPENDENT SECURITY RESEARCHER ADVISORY. 

Please include as much information as possible to help us reproduce the vulnerability. This includes, but is not limited to: 

- An explanation of the potential security vulnerability.
- The steps taken to produce the vulnerability 
- Your contact details

When a report is made for a new vulnerability, we ask that you keep the information confidential and do not make your research public until we have completed our investigation and where applicable, have remediated or mitigated the vulnerability.

3. What Happens Next?

Once a security vulnerability has been reported we will aim to respond to you with an initial response within 5 business days. We will keep you informed of our progress on addressing the potential vulnerability. We will also inform you when the vulnerability has been remediated or mitigated.

We do not compensate individuals or organisations for identifying potential or confirmed security vulnerabilities but we will publicly recognise the researchers who discovered the vulnerability, subject to their consent.  

4. Recognition for Identifying Vulnerabilities

Below are the names or aliases of researchers who have identified and disclosed security vulnerabilities to us in accordance with our Vulnerability Disclosure Policy.

News
Careers
Suppliers
Retail Supplier
Non-retail Supplier
About Us
Investor Relations
Sustainability
Contact us
Head Office
Level 3/10 Shelley St, Barangaroo NSW 2000
1300 780 674
We acknowledge the Traditional Custodians of Country throughout Australia and recognise their continuing connection to land, waters and community. We pay our respects to Elders past, present and emerging and commit to continued listening to and learning from First Nations’ voices.
↑
Copyright © 2026
Endeavour Group Limited – All rights reserved
Terms & ConditionsPrivacy at Endeavour GroupWhistleblowing policy