Information on Product Cybersecurity
General
Information security and data protection are more important than ever, especially the security of our products. As a manufacturer, we appreciate all reports submitted by stakeholders regarding the identification and resolution of potential security issues in our products. These guidelines for responsible disclosure outline our policies and commitment regarding the reporting of security issues, such as exploited vulnerabilities or serious security incidents affecting our products. Our Product Security Incident Response Team (PSIRT) receives all reported security issues, coordinates communication both internally and externally, and ensures that security updates or other solutions are provided.
Scope
These guidelines apply to all products with digital components, including both hardware and software. Please report any anomalies that could indicate the exploitation of potential vulnerabilities.
These guidelines do not apply to any other incidents affecting the functional safety or availability of our products. In such cases, please contact our service partners first. They also do not apply to digital services that are not directly related to our products.
Guidelines for the Responsible Handling of Vulnerabilities
- Report security issues immediately to our central point of contact for vulnerability information. Please also report cases where a security issue is suspected but cannot yet be clearly identified.
- Provide us with all information that could help us reproduce and isolate reported security issues or suspected cases.
- Treat security issues confidentially and leave further communication to us in accordance with legal requirements. Give us the opportunity to address security issues as quickly as possible, and do not disclose information about them to third parties without our consent.
Process
The procedure for handling reported vulnerabilities follows a standardized process that is documented in our management system. It ranges from the receipt of a report regarding exploited vulnerabilities or serious security incidents, through their comprehensive analysis, any necessary notifications to authorities, and the provision of corrective measures, to the preparation of a detailed final report