AI-generated Illustration

PRODUCT SAFETY

CYBER SECURITY

Security throughout the entire product lifecycle

Cyber security is also becoming increasingly important for industrial products and systems. As a manufacturer of IoT systems, we address the security requirements for our products throughout their entire lifecycle.

With the Cyber Resilience Act (CRA), the European Union has established binding requirements for the cybersecurity of products with digital elements. We implement appropriate processes to identify security risks at an early stage, address vulnerabilities appropriately, and inform our customers transparently.

Security-related information

If you have discovered one or more vulnerabilities in connection with the use of an HK.DIGITAL product, you can contact us in confidence.

To enable us to process your vulnerability report quickly and efficiently, we ask you to include the following information:

  • Your contact details if you would like to be contacted, or remain anonymous and use an anonymous email transfer service
  • The type of vulnerability identified
  • Your item number
  • The HK.DIGITAL item number and serial number
  • The firmware or software version
  • A description of the potential risk
  • Violation of law/regulation?
  • The affected interface
  • Description of the impact of the vulnerability
  • Description of how the vulnerability can be exploited
  • Additional comments, images, or videos

REPORT

How to report a potential vulnerability

For security reports, please use our designated reporting form.

Alternatively, you can reach our security teams via the following email addresses:

Product Security Incident Response Team (PSIRT)
for security-related vulnerability reports at the product level:

Computer Security Incident Response Team (CSIRT)
for security reports at the infrastructure level, such as cyberattacks or data leaks:

The following public PGP key is available for encrypted communication:

CSIRT:
ID: 4DCE2017C6640A24
Fingerprint: BAB3 63A6 2AE7 6CB8 D7A3 6F6A 4DCE 2017 C664 0A24

PSIRT-DIGITAL:
ID: 5EB36A74D80CE920
Fingerprint: B2D3 EBD4 C456 FF80 6015 0949 5EB3 6A74 D80C E920

Please preferably submit your report in German or English.

OUR CVD POLICY

What happens after a vulnerability is reported?

Receipt

  • After you have reported a vulnerability, you will receive an acknowledgement of receipt by email
  • Incoming reports are recorded in the system and assigned a unique ID
  • The report is reviewed and the potentially affected products are identified
  • Based on the information available, an early warning is issued to the relevant authority and a report is made to the entity

Validation

  • The PSIRT checks whether the report is valid and whether it is reproducible

Triage

  • The vulnerability is classified and the severity is determined.
  • In addition, prioritization follows in the context of the reports already received
  • The affected (software) components and the associated versions are then identified

Mitigation

  • The PSIRT defines and implements immediate measures to mitigate the impact.
  • Issuing an interim report to the reporting entity and the responsible authorities

Resolution

  • To remediate the vulnerability, the relevant components are first analyzed in an isolated environment
  • Once the root cause has been identified, the issue is resolved (development, testing, and review)
  • The goal is a fix/update that fully resolves the vulnerability, or a workaround that prevents the vulnerability from being exploited.

Disclosure

  • The PSIRT coordinates the provision of the fix/update
  • Release notes are created which, depending on the severity of the resolved vulnerability, may also contain security advisories.
  • Disclosure is initially made to the reporting entity and customers
  • In consultation with the customer, public disclosure may be made if necessary