Product Safety & Security Incidents at IKA
Working Together for Safe Products and Secure IT Systems
IKA collaborates with security researchers, customers, partners, and CERTs to address security vulnerabilities and incidents quickly, transparently, and responsibly.Reporting Product-Specific Vulnerabilities (PSIRT)
Have you discovered a vulnerability in an IKA product, software, firmware, or digital service?Email: [email protected]
Reporting Security Incidents in Corporate IT (CSIRT)
Would you like to report a cyberattack, phishing incident, misuse of IKA systems, or any other IT security incident?Email: [email protected]
Our Commitment
- Confidential handling of all reports
- Prompt acknowledgment and assessment
- Responsible Disclosure of Vulnerabilities
Our Engagement
Collaboration with the Security Community
The security of our products and services is constantly evolving. Therefore, IKA welcomes the responsible reporting of security vulnerabilities by security researchers, customers, partners, suppliers, CERTs, and other stakeholders. We carefully review every report and work constructively with those who report them to minimize risks to customers, partners, and IKA.Responsible Disclosure
Assurances to Reporters
When security research is conducted in good faith, responsibly, and in accordance with this policy, IKA commits to:- to treat your report confidentially
- to promptly acknowledge receipt of the report
- Carefully review and appropriately assess the report
- To work constructively with you as needed
- Not to take any legal action in connection with the report, provided that no unlawful or harmful acts have been committed
- to disclose information about the reporter only with their consent or as required by law
- to strive for coordinated disclosure, if disclosure is necessary
Reporting Process
1. Submit a Report
Please provide the following information if possible:- Affected product or system
- Product, software, or firmware version
- Description of the vulnerability or incident
- Steps to reproduce the issue
- Expected and actual behavior
- Assessment of potential impacts
- Screenshots, log files, or other evidence
2. Confirmation of Receipt
We will endeavor to acknowledge receipt of your report within five business days.3. Assessment
As part of the assessment, IKA determines whether the report concerns an actively exploited vulnerability or a serious security incident and whether there are any legal reporting or disclosure obligations, particularly under the Cyber Resilience Act. If necessary, IKA will take the necessary steps with the relevant authorities and affected users.4. Processing
Confirmed security vulnerabilities are handled according to their severity, and appropriate measures are taken. Affected customers or users are informed if this is necessary to minimize risk or due to legal requirements. Disclosure is coordinated and does not include any personal data of the person who reported the vulnerability.5. Closure
The process is concluded when the report has been deemed unfounded or when appropriate measures have been completed or initiated.Requirements for Valid Reports
A report should:- pertain to an IKA product or an IKA system
- contain sufficient technical information
- be reproducible and verifiable
- do not consist exclusively of automated scanner results
- Do not refer to information that is already publicly known
Code of Conduct for Security Researchers
We ask all reporters to adhere to the following guidelines:Permitted
- Security analyses conducted in good faith
- Creation of a proof of concept (PoC), provided it is submitted to IKA on a strictly confidential basis
- Responsible Disclosure of Vulnerabilities
Not Permitted
- Modifying or deleting data
- Access to personal data
- Distribution of exploit code
- Attacks on system availability
- Social engineering
- Phishing
- Denial-of-Service Attacks (DoS/DDoS)
- Activities outside the defined scope of testing
Contact
Product Security Incident Response Team (PSIRT)
Product security vulnerabilities in:- Products
- Software
- Firmware
- Cloud services
- APIs
- Digital services
Cyber Security Incident Response Team (CSIRT)
IT security incidents such as:- Cyberattacks
- Phishing
- Malware
- Misuse of IKA systems
- Security incidents in the company’s IT system