Yeah, I don't like Sam Bowne's approach. His initial email read as someone looking to make a name for himself (this is the biggest security flaw I've ever found! You have 6 days to respond!).
Despite this, if I had received an email like this I would have sent back a personal thank you followed with an outline of action steps. If I get another email from Sam asking more questions I'd reply as quickly as possible. Every transaction between him and I would be professional.
I'm reminded of a time when someone was convinced I was a hacker. It's a bit of a long story; I was tasked with creating a certification course for 2,000 employees. They all get emails telling them to log in and one guy saw the domain (companyname.columbo-companyname.com) and thought it was a Phishing scam. This employee then pulled up my company, does a WHOIS, called my cell phone a few times* and then promptly sent an email to the CTO (and about 6 other VPs) about a rogue hacker.
The whole thing turned into a massive cluster, suddenly I'm getting emails and phone-calls about a hacker in MY site (the CTO assumed I had been hacked and they had been hacked by proxy, nobody knew what was going on).
Took a few days to sort out and when they found out where it started the CTO sent me an apology to which I responded "Hey, it's no big deal, it's great you have an employee willing to raise alarm bells like this.".
Problem Solved.
There's nothing to gain from pissing matches or threats.
* I suspect he's the one that called me, got a strange call & text right before all this went down from a number I didn't recognize.