Help HIWIN ensure the secure design of our products incorporating digital elements.
HIWIN takes the security of its products seriously throughout their entire product lifecycle. In line with the requirements of the EU Cyber Resilience Act (CRA), we welcome reports of potential cybersecurity vulnerabilities, security breaches or security-related incidents. Early reporting enables us to assess risks, implement appropriate countermeasures and continuously improve the security of our products.
Scope:
This reporting centre applies to all HIWIN products containing digital components, as well as associated software, firmware and communication components.
What should be reported?
- Suspected security vulnerabilities in the software, firmware or digital functions of our products.
- Vulnerabilities that could compromise availability, integrity, confidentiality or authenticity.
- Indications of a possible exploitation of a vulnerability.
- Security-related malfunctions or configuration issues.
- Other security-related observations relating to HIWIN products.
Information to ensure effective processing:
Please provide as much detail as possible to enable efficient assessment and processing. The following are particularly helpful:
- Product name and version
- Description of the vulnerability
- Potential impact
- Steps to reproduce the issue
- Technical logs
- Screenshots or other supporting documents
Contact for vulnerability disclosure:
Email: psirt@hiwin.de
Alternatively, you may address your report to your usual HIWIN contact. If confidential information is to be transmitted, we recommend using encrypted communication channels. We can provide information on how to contact us securely upon request.
Handling and confidentiality:
All reports received are treated confidentially and assessed by the relevant specialist departments. HIWIN follows a Coordinated Vulnerability Disclosure process to analyse and rectify reported vulnerabilities responsibly and to inform affected parties appropriately.
Response time:
We usually confirm receipt of your report within five working days. Following an initial assessment, you will receive an update on the status of your report, provided we have your contact details. Critical vulnerabilities or those being actively exploited are treated as a priority. Where required by law, we will continue with further processing and reporting in accordance with the provisions of the EU Cyber Resilience Act.
Responsible Disclosure:
We usually confirm receipt of your report within five working days. Following an initial assessment, you will receive an update on the status of your report, provided we have your contact details. Critical vulnerabilities or those being actively exploited are treated as a priority. Where required by law, we will continue with further processing and reporting in accordance with the provisions of the EU Cyber Resilience Act.
We would like to thank you for your support in the ongoing improvement of the cybersecurity of our products and systems.
Cybersecurity contact:
- psirt@hiwin.de
- Alternatively, you can send your report to your usual HIWIN contact.
- Monday – Thursday:
8 a.m. to 12 p.m.
1 p.m. to 5 p.m. - Friday:
8 a.m. to 12 p.m.
1 p.m. to 3 p.m.