Cybersecurity

Safety Throughout the Entire Product Life Cycle

Cybersecurity is also becoming increasingly important for industrial products and systems. As a manufacturer of input systems, we address the security requirements for our products throughout their entire lifecycle.

With the Cyber Resilience Act (CRA), the European Union has established mandatory cybersecurity requirements for products containing digital elements. We establish appropriate processes to identify security risks early on, address vulnerabilities appropriately, and provide our customers with transparent information.

Cybersecurity is also becoming increasingly important for industrial products and systems. As a manufacturer of input systems, we address the security requirements for our products throughout their entire lifecycle.

With the Cyber Resilience Act (CRA), the European Union has established mandatory cybersecurity requirements for products containing digital elements. We establish appropriate processes to identify security risks early on, address vulnerabilities appropriately, and provide our customers with transparent information.

Safety Information

If you have discovered one or more vulnerabilities related to the use of a Hoffmann + Krippner product, please feel free to contact us.

To help us process your vulnerability report quickly and efficiently, please include the following information:

  • Your contact information, if you would like to be contacted, or you may remain anonymous and use an anonymous email forwarding service
  • The type of vulnerability identified (product / infrastructure)
  • How long have you been aware of the vulnerability?
  • Is the vulnerability being actively exploited?
  • Your item number
  • The Hoffmann + Krippner part number and serial number
  • The firmware or software version
  • A description of the potential hazard
  • Is personal information involved?
  • Is there a violation of the law?
  • The affected interface
  • Description of the Impact of the Vulnerability
  • Description of the Exploitation of the Vulnerability
  • Additional comments, images, or videos

How to Report a Potential Vulnerability

For security reports, please use our designated reporting form.

Alternatively, you can contact our security teams at the following email addresses:

Product Security Incident Response Team (PSIRT)
For security vulnerability reports at the product level:

Computer Security Incident Response Team (CSIRT)
For security alerts at the infrastructure level, such as cyberattacks or data breaches:

The following public PGP keys are available for encrypted communication:

PGP Key PSIRT-HMI
ID: 1B47681479FA52AB
Fingerprint: 1E90 DFA1 C17F 8510 E860 E50A 1B47 6814 79FA 52AB

PGP Key CSIRT
ID: 4DCE2017C6640A24
Fingerprint: BAB3 63A6 2AE7 6CB8 D7A3 6F6A 4DCE 2017 C664 0A24

Please send us your message, preferably in German or English.