
SUPCON PSIRT
Trusted Response for Industrial Cybersecurity
OVERVIEW
What is SUPCON PSIRT?
The SUPCON Product Security Incident Response Team (PSIRT) is a dedicated global team responsible for receiving, investigating, and disclosing security vulnerabilities related to SUPCON products.
We welcome reports from security researchers, customers, industry organizations, and suppliers. SUPCON PSIRT follows a structured vulnerability management process to assess risks, coordinate remediation, and ensure timely and responsible disclosure.
We welcome reports from security researchers, customers, industry organizations, and suppliers. SUPCON PSIRT follows a structured vulnerability management process to assess risks, coordinate remediation, and ensure timely and responsible disclosure.

Responsibilities & Process
Managing Security Vulnerabilities
SUPCON PSIRT is responsible for receiving, assessing, and coordinating the resolution of product security vulnerabilities. Following internationally recognized standards such as ISO/IEC 30111 and ISO/IEC 29147, we work to ensure vulnerabilities are addressed in a timely, transparent, and responsible manner.
Core Responsibilities:
Receive and validate vulnerability reports
Analyze impact, root causes, and risk level
Coordinate investigation and develop remediation measures
Manage responsible disclosure and security communication
Steps
Our Standard Process
Discovery
Monitor and systematically collect suspected vulnerabilities
Assessment
Complete the vulnerability qualification and issue reproduction
Remediation
Design and implement vulnerability remediation schemes
Disclosure
Promptly disclose vulnerabilities and release mitigation strategies
Feedback
Incorporate customer and team feedback for ongoing improvement
Security Process
Security Disclosure & Improvement
At SUPCON, we do not only respond to vulnerabilities — we continuously improve our systems and engineering practices based on real-world security findings.
Each confirmed vulnerability is handled through our secure development lifecycle:
Each confirmed vulnerability is handled through our secure development lifecycle:
Receive and validate vulnerability reports
Engineering review and product remediation
Integration into R&D quality and security controls
Public disclosure via Security Bulletins after fixes are released
This closed-loop process ensures that every security report, internal or external, is used to strengthen our products and improve overall system security, resilience, and reliability.

Security is not a one-time fix — it's a disciplined, transparent, and evolving process we embed in our DNA.
contact expert
Security Process
Report a Vulnerability
All reports will be reviewed promptly under our vulnerability management process.
Please include, where applicable:
Product or driver name, version, and branch
Vulnerability type and potential impact
Steps to reproduce
Proof-of-concept (PoC) or exploit code (if available)
SUPCON is committed to handling all reports with confidentiality, professionalism, and transparency.

Kickstart Your Digitalization Journey by Harnessing the Power of AI to Optimize Operations
contact us