Responsible Disclosure at St.George
St.George takes the protection of its customer information and confidential information very seriously.
We have rigorous security measures in place that protect the privacy and confidentiality of our customers, including industry best practice security and fraud detection techniques.
We also constantly monitor the environment for emerging cyber threats, security issues and potential vulnerabilities across the Westpac Group.
Our customers and others outside the organisation play an important role in providing us with information that supports our continuous efforts to keep our customers’ information safe and secure.
What to do if you receive a phishing or hoax email or SMS?
Customers may receive phishing or hoax emails, SMS or other correspondence from third-parties that may seek to impersonate our brand for the purposes of extracting information, or money from customers.
What to do if you have other information relating to potential security threats or issues?
We welcome any information you have on suspected cyber threats, or security issues. If you would like to report a suspected cyber threat, security issue or vulnerability, please send an email with the information to: firstname.lastname@example.org.
When making your report, please include as much detail as possible to assist us. To help us to action your concerns outlined in your report, we recommend you follow our Submission Guidelines outlined below.
Please include the following information in your report:
- Your name and contact information (optional)
- Date and time the suspected security issue or vulnerability was discovered
- IP address used when the suspected security issue or vulnerability was discovered
- A detailed description of the suspected security issue
- Vulnerable URL/application
- Vulnerable parameter (if applicable)
- Step-by-step instructions to reproduce the vulnerability.
What happens next?
We will firstly assess the report, based on any potential risks that it poses to St.George or its customers. If you choose to share your name and contact details, we will contact you within a reasonable time to acknowledge we’ve received your report, and to discuss how we intend to resolve the issue.
St.George appreciates your assistance in reporting suspected cyber threats, security issues and vulnerabilities. However, there are circumstances where we will not investigate all reported suspected cyber threats and security issues.
If we decide to investigate your report further or require more information, we may use your personal information to contact you about your report. We are bound by the Privacy Act and will protect your personal information in accordance with the Australian Privacy Principles.