Security of our products and solutions
The increasing connectivity of machines, systems and digital solutions also creates new requirements for IT and product security. KASTO therefore takes the security of its products and solutions very seriously.
The KASTO Product Security Incident Response Team (PSIRT) is the central point of contact for reports of potential security vulnerabilities and security incidents relating to our products, machines, systems, software and digital services.
Our aim is to identify potential vulnerabilities at an early stage, assess them and initiate appropriate measures. We therefore expressly encourage security experts, independent security researchers, customers, partners and other individuals to report potential security issues to us.
Early and coordinated reporting enables us to assess matters jointly, coordinate the necessary measures and continuously improve the security of our products and solutions.
Processing security reports
Upon receipt of a report, the KASTO PSIRT reviews the information provided and assesses its potential security relevance.
Depending on the type, scope and complexity of the reported vulnerability, the investigation may take varying amounts of time. If further information is required for the assessment, we will contact the person who submitted the report.
Once the analysis has been completed, we decide on the necessary measures. These may include, for example, technical modifications, software or firmware updates, configuration changes or additional protective measures.
In the case of security-relevant vulnerabilities, we inform affected customers and users in an appropriate manner about the issue and the recommended measures.
Coordinated disclosure
KASTO generally follows a coordinated approach when handling security vulnerabilities.
The aim is to allow sufficient time for technical analysis and the development of appropriate measures before information about a vulnerability is made public. This helps to minimise risks to our customers, users and third parties.
Where disclosure is necessary or appropriate, KASTO will provide the relevant information in a suitable form.
Security Advisories
For confirmed and security-relevant vulnerabilities, KASTO may publish Security Advisories.
A Security Advisory provides information about an identified security vulnerability and may include, where relevant, for example:
- a description of the vulnerability,
- an assessment of the potential impact and severity,
- affected products and versions,
- information on whether and how products are affected,
- recommended protective and remedial measures,
- available updates or fixes, and
- where applicable, acknowledgement of the person or organisation that reported the vulnerability.