Vulnerability management
KI-generiertes Bild.
Safety is part of our product responsibility.
Industrial operating systems, panel PCs, and terminals are now networked devices – and therefore potential targets for attack. With the European Cyber Resilience Act (CRA, Regulation (EU) 2024/2847), cybersecurity becomes a legal obligation across the entire product lifecycle. For us, it already is: We develop our products according to the principle of Security-by-Design and address vulnerabilities in a structured, transparent, and traceable manner. The regulations described below apply to products within the scope of the CRA (networked products with digital elements placed on the market).
How we deal with vulnerabilities
-
Structured process: We receive vulnerability disclosures, evaluate them and process them according to a fixed procedure (Coordinated Vulnerability Disclosure).
-
Transparent Information: We inform affected users about relevant vulnerabilities and remedial measures. We report actively exploited vulnerabilities to the responsible CSIRT body and ENISA (CRA Art. 14) in a timely manner, in accordance with legal requirements.
-
Free security updates: We provide affected customers with security-relevant updates for GETT components free of charge and without any access barriers – throughout the entire support period. Published updates remain available long-term.
-
Clear support period: For our products, we specify how long we will provide security updates.
Overview of update responsibilities
-
GETT Components: For BIOS/UEFI firmware, drivers and pre-installed GETT software, GETT provides free security updates during the specified support period.
-
Integrated Third-Party Software: For third-party software components integrated by GETT, GETT monitors relevant information sources on security vulnerabilities on a risk-based approach and provides updates as soon as they are available and tested. If a third-party provider's support ends within the GETT support period, GETT assesses the risk, informs affected customers via a security advisory, and recommends appropriate measures (e.g., workaround, configuration recommendation, component replacement, or migration path).
-
Operating system (Windows): Selected devices ship with Microsoft Windows. Security updates are provided by Microsoft; the Microsoft lifecycle policies of the installed Windows version apply.
Safe commissioning
For secure operation, we provide a checklist based on BSI IT baseline protection for the secure commissioning of your Window PC. (System hardening, cryptography, identity and rights management, patch management, etc.):
Report a vulnerability
Have you discovered a potential security vulnerability in a GETT product? We appreciate any information and will treat it confidentially.
We acknowledge receipt of your message and will keep you updated on its processing status.
Safety instructions
Safety information regarding our products and updates will be available shortly [here / in the support area].
Subscribe to the security newsletter
Stay informed before things get critical. With our security newsletter, you will automatically receive notifications about:
-
new safety instructions for our products,
-
available security updates,
-
relevant regulatory developments (CRA, NIS2).
KI-generiertes Bild.