Sympower, the Amsterdam-based company specialising in energy flexibility and balancing of national electricity grids, introduced a Responsible Disclosure Programme on 30 June 2026. The programme offers independent security researchers an official and authorised channel to report vulnerabilities in the company's internet-facing systems, applications and websites.
With this launch, Sympower is adopting a structured approach to external security findings. Given the company's role in critical energy infrastructure, managing more than 750 megawatts of flexible distributed energy resources, the security of its digital systems has direct consequences for customers and network operators.
Sympower operates in nine countries, including the Netherlands, Sweden, Finland, Norway and Israel, and had nearly one hundred employees in early November 2024. The company has raised a total of more than €74 million in funding, including a Series B round of €42 million with PGGM and Activate Capital as key investors.
How the programme works
Researchers who discover a vulnerability in Sympower's systems can report it via security@sympower.net. The company confirms receipt within three business days and keeps the reporter informed of progress throughout the entire process.
Sympower commits to investigating, validating and, where necessary, resolving reported vulnerabilities. Researchers who act in good faith and comply with the published policy need not fear legal action. That explicit legal protection is a common but not guaranteed feature of such programmes, and makes it more attractive for researchers to share their findings rather than keep them to themselves.
The programme does not offer financial rewards for submitted reports. However, researchers may, with their own consent, be listed on a public security acknowledgements page. This is standard practice in comparable programmes at both large technology companies and smaller specialist software firms.
Security and certification
Sympower holds ISO 27001 certification, the international standard for information security management. Among other requirements, this certification demands that an organisation maintain a systematic process for identifying, assessing and managing security risks.
The Responsible Disclosure Programme complements that existing framework by giving external researchers a formal role in the security process. CEO and founder Simon Bushell notes in a statement that a clear and authorised channel for independent researchers contributes to the continuous improvement of security for customer and partner data.
For a company whose software platform exerts real influence over industrial and commercial energy processes, the security of digital access points is far from a peripheral concern. Sympower's portfolio encompasses more than two hundred industrial and commercial customers, whose combined flexible energy resources represent more than 750 megawatts.
Broader significance for the sector
Responsible Disclosure Programmes have long been commonplace in the software industry, but in the energy sector, and particularly among companies operating at the intersection of software and critical infrastructure, they are less of a given. Sympower operates at precisely that intersection, and with this step follows a practice that is widely recommended in the cybersecurity community.
For other Dutch and European energy technology companies building similar platforms for grid management or demand response, this demonstrates that formal security programmes are increasingly becoming part of operational maturity, even for companies that are still in a growth phase. Investors and corporate customers are asking more questions about information security as part of their due diligence, which lowers the threshold for similar initiatives elsewhere in the ecosystem.