Cyber security at GF

Cyber security

At GF, we care about the security and data protection of our products, services, and customers, and we are committed to resolving security issues in a timely manner.

GF is committed to complying with laws and regulations, including the Cyber Resilience Act in the European Union. Under Article 14 of the EU Cyber Resilience Act (CRA), GF must notify both the European Union Agency for Cybersecurity (ENISA) and the designated coordinating CSIRT when it becomes aware of an actively exploited vulnerability or a severe security incident affecting one of its products. This initial early-warning notification must be submitted without undue delay, and at the latest within 24 hours. Where a reported vulnerability meets these criteria, GF initiates the formal reporting process immediately and runs it in parallel with its internal remediation work.

IEC 62443-4-1: Certified secure product development process

Certain GF businesses maintain certifications and secure development processes aligned with internationally recognized cybersecurity standards. Certification according to IEC 62443-4-1 is vital as it ensures that our products and their lifecycle management adhere to the highest international security standards. This is crucial for providing our customers with optimal security for their production facilities, minimizing potential risks of operational disruptions or cyberattacks.

Reporting a vulnerability

If you identify a vulnerability or security issue in our product, please report it using the form below or by email at dea.ps@georgfischer.com, and provide the following information:

  • The GF product affected by the vulnerability
  • The technical details of the vulnerability
  • Instructions and proof-of-concept code to reproduce the issue
  • Potential impact

You should receive a confirmation of our receipt of your email or similar response within 48 hours. Our response will include additional information to enable secure communication. Please follow up with us if you have not received a response within this time frame.

Cyber security alerts and notifications

Id
Product
Advisory
Impact
CVE
Last updated
Version
Attachment
Id Product Advisory Impact CVE Last updated Version Attachment
<GF_VD_xx> <Product related> <Title of the issue> <CRITICAL / HIGH / MEDIUM / LOW>        

Report a vulnerability

Please fill all mandatory fields marked with *

Form cannot be sent. Please review the marked fields.