Earlier quoted context omitted.
> I don't know how you could see the CEO as a bully in this situation. someone tried to help him, he responded by making threats, and being rude. This is bully behavior. Why do you think responding to either email with a direct threat is reasonable? > The researcher clearly has "power" in this situation over the CEO You don't work in, or around information security do you? You're the first person to ever make any cla…
> someone tried to help him, he responded by making threats My whole point is that he doesn't actually know what the researcher wants, saw it as a threat, and responded to it as if it were a threat. > You're the first person to ever make any claim remotely close to saying any "researcher" has any kind of power. Having the entirety of their application database including customer PII, possibly the capability to encryp…
Your attempts to put any onus on the researcher are actively harmful. No one should point finger at the researchers trying to help. We should all point fingers at the primary person who's able to prevent bad things happening. You haven't once attempted to put any responsibility on the CEO. This is the first time. You asked in another reply if everyone else is being dense; but you're the one blaming the researcher, did you stop to consider if everyone disagrees with you, that maybe you're the problem?
edit:
> My whole point is that he doesn't actually know what the researcher wants, saw it as a threat, and responded to it as if it were a threat.
Yeah, and doing that was gross negligence. There's a reason you're not allowed waive harms arising from gross negligence.