Cyber Resilience Act (CRA)

Security and resilience for
Industrial Motion Control

Sipro has adopted a Coordinated Vulnerability Disclosure policy in compliance with EU Regulation 2024/2847, ensuring advanced protection and operational continuity for its products and partners.

Cyber Resilience Act

Cybersecurity & Coordinated Vulnerability Disclosure

A structured, transparent and responsible approach to safeguarding the integrity of automation systems.

Design and Active Protection

The cyber resilience of our motion control systems is a core requirement. We continuously design and test hardware, firmware and software applications to meet the most demanding security standards in the industrial sector.

Transparent Collaboration

In line with EU Regulation 2024/2847, we foster an ecosystem of open collaboration with customers, partners and security researchers, so that any potential vulnerability can be identified and mitigated in advance.

The Four Pillars of Our Policy

Guidelines and operating procedures for reporting and securely handling vulnerabilities.

01

Scope

This policy covers cyber vulnerabilities affecting the Sipro products currently supported:

  • Siax M-EVO
  • Siax A-EVO
  • Siax XPC
  • HMIS Series
02

Code of Conduct

We ask that you act ethically in order to protect the operation of live plants:

  • No impact on or disruption to live production processes.
  • Details of the flaw kept confidential until the patch is released.
  • Secure handling of data, with no alteration of third-party information.

Sipro undertakes not to take legal action against anyone acting in good faith and in accordance with these guidelines.

03

Submitting a Report

To allow us to analyse and reproduce the vulnerability, please include the following information in your report:

  • Product model, serial number and exact firmware version.
  • Detailed technical description of the vulnerability, including any Proof of Concept (PoC) or steps to reproduce it.
  • Assessment of the potential impact on the system and on the features affected.

Submit a Secure Report

📧 Email: Contact our Cyber Security team directly, providing the required information, at:

Email address
cybersec(AT)sipro.vr.it

🔐 Encryption recommended: if your report contains sensitive information, we recommend encrypting the message with our PGP public key, so that confidentiality is preserved until the fix is released.

PGP public key fingerprint
89EE 749B DB37 20ED AD77 6119 5C87 6282 4ABF 4FE2
Download the PGP Public Key
04

Handling and Timelines

We guarantee a fast, traceable resolution process, promptly notifying the relevant authorities (CSIRT / ENISA) in the cases required by law:

48h Acknowledgement
10 days Validation
Patch Fix release