Cybersecurity at Erhardt+Leimer

Why Cybersecurity?

At Erhardt+Leimer, the protection of machines, equipment, and production processes is a top priority. For this reason, we use state-of-the-art security mechanisms to provide the best possible protection for systems, data, and communications against unauthorized access and tampering. These include, among other things, measures to protect application software and configuration data using the latest encryption and authentication methods. In addition, role-based user and permission models enable controlled management of access rights at the engineering, service, and operational levels. Secure and encrypted communication channels are supported for communication between devices, controllers, and higher-level systems. In addition, backup and recovery mechanisms, as well as appropriate availability concepts, help minimize downtime and increase operational reliability. Through the continuous refinement of the security measures in place, Erhardt+Leimer helps operators run their automation solutions securely and reliably.

Security

More Information


Our Commitment to Cybersecurity:

The security of our products, systems, and services is a top priority for Erhardt+Leimer. As industrial plants and processes become increasingly interconnected, the demands for protection against cyber threats are also rising. That is why we take security considerations into account throughout the entire product lifecycle and continuously refine our security measures.
Our goal is to provide customers and partners with secure and reliable solutions and to communicate transparently about identified security risks and available countermeasures.

Product Security Incident Response Team (PSIRT):

The Erhardt+Leimer PSIRT coordinates the handling of security-related reports concerning the company’s products and solutions. The PSIRT’s responsibilities include:

  • Receiving security reports
  • Analyzing and assessing reported vulnerabilities
  • Coordinating countermeasures and software updates
  • Communicating with customers, partners, and security researchers
  • Publishing security advisories

CRA Security Formular

Type of Report

What are the implications of the vulnerability or incident?

*Required field

Guidelines on Responsible Reporting and Misuse Responsible Reporting of Security Incidents and Vulnerabilities

We welcome reports of potential vulnerabilities, security incidents, or security-related defects in our products and services. These reports help us fulfill our obligations under the Cyber Resilience Act (CRA) and contribute to improving the cybersecurity of our products and systems.
All reports are reviewed, assessed, and documented by our security team. The information provided is treated confidentially and used exclusively to address the reported issue.

 

Requirements for Submitting a Report

By submitting a report, the reporter confirms that:

  • the information provided is accurate to the best of their knowledge and belief,
  • the report is based on actual observations or verifiable evidence,
  • no knowingly false, misleading, or manipulated information has been provided,
  • the report is not being made for the purpose of causing harm, extortion, unfair competition, or harassment,
  • no unauthorized or unlawful actions were taken to obtain information for the report.

 

Review of All Reports

Every report received is analyzed by qualified professionals and assessed for:

  • plausibility,
  • technical verifiability,
  • relevance,
  • completeness, and
  • possible regulatory reporting requirements.

The company reserves the right to request additional information or supporting documentation if necessary for the assessment.

 
Abusive or intentionally false reports

Misuse of this reporting channel is prohibited.
This includes, in particular:

  • knowingly false security reports,
  • fabricated or fictitious vulnerabilities,
  • repeated submission of obviously unfounded reports,
  • intentionally misleading the company,
  • attempts at extortion or demands based on alleged vulnerabilities,
  • the submission of manipulated or falsified evidence,
  • the misuse of the reporting process to disrupt business operations.

 

Legal Consequences of Abuse

If we suspect that a report is abusive, fraudulent, or intentionally false, we reserve the right to

  • subject the report to an expanded technical and organizational review,
  • to involve internal compliance and legal departments,
  • to evaluate existing log and evidence data,
  • to have the facts legally assessed,
  • and to initiate civil, labor, or criminal proceedings, provided that the legal requirements are met. 

This applies in particular when intentionally false statements result in costs, operational disruptions, reputational damage, or unnecessary regulatory reporting procedures.

 

Protection of Whistleblowers Acting in Good Faith

Individuals who act in good faith and responsibly report a suspected or actual vulnerability need not fear any adverse consequences resulting from an erroneous report.
A report is not considered abusive merely because a reported issue turns out to be unfounded following a technical review. What matters is the demonstrable intent to report honestly and responsibly.

 

CRA-Related Note

Reports may be reviewed, documented, and, where applicable, forwarded to the relevant authorities or agencies in accordance with our obligations under the Cyber Resilience Act (EU) 2024/2847, provided that statutory reporting obligations exist.