Cybersecurity

Cybersecurity

Reporting product security vulnerabilities and cyber incidents

How to report a product security issue

At Scanreco, product security is an integral part of the products we develop and support throughout their lifecycle. We continuously work to strengthen the security of our products by identifying and addressing potential vulnerabilities and responding to security incidents that may affect them.

This page provides a dedicated channel for reporting potential security vulnerabilities and cyber incidents affecting Scanreco products.

Reports are reviewed by our Product Security team and handled through a structured process to assess the issue and determine the appropriate response.

Reporting Process

What to report and what happens next

Find out what information to include in your report and learn how we handle security vulnerability and cyber incident reports once they are submitted. 

What information should you provide?

To help us assess your report efficiently, please provide as much relevant information as possible.

This may include:

  • Product: affected Scanreco product and, where applicable, product Type and Serial Number
  • Issue: clear description of the suspected vulnerability or cyber incident
  • Impact: potential security or operational impact
  • Steps to replicate:  clear and detailed steps required to reproduce the issue, where applicable. Please include the relevant conditions, inputs, or actions that trigger the issue 
  • Evidence: relevant logs, screenshots or other technical information
  • Mitigation: any known workaround or mitigation already applied

Please do not include personal or confidential information unless it is necessary to describe or investigate the security issue.

How we handle your report

Every security report is reviewed by our Product Security team and handled in accordance with the reporting obligations established by the Cyber Resilience Act (CRA).

Depending on the nature of the report, our process may include:

1. Review
We review the information provided and determine whether the report concerns a potential product security vulnerability or cyber incident.

2. Assessment
We assess the potential impact and severity of the reported issue.

3. Investigation
Where necessary, we investigate the issue and determine which products, versions or configurations may be affected.

4. Mitigation and remediation
Where appropriate, we identify and implement measures to address or reduce the identified risk.

5. Communication and Regulatory reporting 
Where applicable, we provide feedback to the reporter and fulfil the relevant reporting obligations under the Cyber Resilience Act (CRA).

Our approach is focused on responsible handling of security issues and on continuously improving the security of our products.

service_and_support

What this page is NOT for

This reporting channel is dedicated to product security vulnerabilities and cyber incidents.

It is not intended for general product support or service requests, including:

  • Product troubleshooting
  • Technical support
  • Questions about product configuration or operation
  • Spare parts or replacement requests
  • Warranty or repair requests
  • General product or service enquiries

For these matters, please use the appropriate Scanreco Support channels.

Report a security issue

Submit your report

Use the form to report a product security vulnerability or cyber incident to our Product Security team.

Please provide as much relevant information as possible to help us assess and respond to your report. 

 

Complete the form

11b4b72af66c696958cb0ddac5dd0603-min

Loking for more information?Get in touch with us.