PSIRT – Product Security Incident Response Team

What is HAWE PSIRT?

The HAWE Product Security Incident Response Team (PSIRT) is the central point of contact for reports of vulnerabilities and security risks related to the cybersecurity of HAWE products. The PSIRT coordinates communication and collaboration between reporters, product experts, and development teams to analyze, assess, and address reported security issues by initiating appropriate countermeasures.

Why is your report important?

Responsible disclosure of security vulnerabilities helps us identify potential cyber risks at an early stage and provide suitable protective measures for our customers. By analyzing and resolving reported vulnerabilities, we can continuously improve the security of our products and support operators in using them safely. If you have discovered what you suspect to be a security vulnerability in a HAWE product, please report it by email to psirt (at) hawe.de.

What happens to your report?

Once your report has been received, it will be reviewed and processed by the HAWE PSIRT. You will receive an acknowledgment of receipt in a timely manner. Our experts will then evaluate the information provided, verify whether the vulnerability can be reproduced, and analyze its potential impact on affected products and users. If the report is confirmed, appropriate measures will be taken to mitigate the risk and remediate the vulnerability. Throughout the handling process, all information provided will be treated confidentially and used exclusively for the investigation and resolution of the reported security issue.

  

Report a Vulnerability to the HAWE PSIRT!

Vulnerabilities in HAWE IT Infrastructure

Security vulnerabilities affecting HAWE websites, online services, or other HAWE-operated IT systems are outside the scope of the HAWE PSIRT. Please report such findings to our Computer Emergency Response Team (CERT): cert (at) hawe.com

PSIRT vs. CERT: Different Focus, Common Goal

PSIRT

  • Focus on products and digital components
  • Handles known or reported vulnerabilities
  • Responsible for vulnerability management and product security
  • Coordinates the analysis, assessment, and remediation of product vulnerabilities
  • Protects customers and products

     

CERT

  • Focus on enterprise IT and operational technology
  • Responds to active security incidents and cyber attacks
  • Responsible for incident response and digital forensics
  • Investigates and addresses security incidents within the corporate environment
  • Protects business operations and corporate infrastructure