Introduction

At Delta Engineering, we design our industrial automation machinery according to Secure-by-Design principles. Our products are intended to be used in a trusted customer environment. In compliance with the European Union Cyber Resilience Act (EU 2024/2847), we are committed to providing transparent security support, timely software patches, and a Coordinated Vulnerability Disclosure (CVD) process for all our connected machinery and software components.

However, vulnerabilities can never be completely eliminated, despite best efforts. When vulnerabilities are identified and exploited, it puts at risk the confidentiality, integrity or availability of the Delta Engineering systems and the information processed therein.

This vulnerability disclosure policy describes what systems and types of tests are authorised and how to send vulnerability reports. We encourage you to contact us to report potential security issues in our systems by following this policy.

Authorisation

We welcome reports from security researchers, customers, system integrators, and independent auditors regarding potential vulnerabilities in our machinery (PLCs, HMI applications, drives and remote maintenance gateways).

If you are acting in good faith to identify and report vulnerabilities on Delta Engineering systems, while complying with this policy we will work with you to understand and resolve the issues quickly.
Delta Engineering will not pursue legal action related to your activities of identifying vulnerabilities on our systems as long as you follow the guidelines in this policy.

Any services not expressly listed above are excluded from the scope and are not authorised for testing.
Moreover, vulnerabilities found in systems from vendors are also excluded from scope and should be reported directly to the vendor according to their own disclosure policy (if applicable).

Guidelines

While carrying out your activities, it is imperative that you

  • do not take advantage of the vulnerability or problem you have discovered, for example by downloading more data than necessary to demonstrate the vulnerability, deleting, or modifying other people’s data
  • only use harmless exploits to confirm that a vulnerability is present
  • do not reveal any data downloaded during the discovery to the public or any other parties
  • do not reveal the vulnerability or problem to the public or other parties until it has been resolved
  • stop your tests when you discover any sensitive information (Personally Identifiable Information – PII, medical, financial, proprietary information or trade secrets) and notify us immediately and do not disclose any obtained data to anyone else

Do not perform the following actions

  • place malware (virus, worm, Trojan horse, etc.) on any system
  • compromise any systems using exploits to gain full or partial control
  • copy, modify or delete data from the system
  • make changes to the system
  • repeatedly access the system or share access with the public or any other parties
  • use any access obtained to attempt access other systems
  • change access rights of other users
  • use automated scanning tools
  • cause denial-of-service or use social engineering (phishing, vishing, spam, etc.)
  • harm machine physically

Reporting a vulnerability

What we would like to see from you

If you have identified a vulnerability, please

  • e-mail your findings as soon as possible to CRA-Security@delta-engineering.be, specifying whether you agree to your name or pseudonym being made publicly available as the discoverer of the problem
  • encrypt your findings using our PGP key to prevent this critical information from falling into the wrong hands
  • provide us with sufficient information to reproduce the problem so that we can resolve it as quickly as possible.
  1. Affected Machine Model / Serial Number Range / Firmware Version.
  2. Description of the vulnerability and potential impact.
  3. Step-by-step proof-of-concept (PoC) to reproduce the issue.
  • provide your report in English preferably.

What you can expect from us

In return, we promise the following when you report a vulnerability to us, that is to

  • respond to your report within seven (7) business days with our evaluation of the report
  • handle your report with strict confidentiality
  • where possible, inform you when the vulnerability has been remedied
  • process the personal data that you provide (such as your e-mail address and name) in accordance with the applicable data protection legislation and will not pass on your personal details to third parties without your permission
  • publish your name as the discoverer of the problem, if you have agreed to this in your initial e-mail, when and if we disclose the problem publicly

Product Security Lifecycle & Support Period

Under Article 13 of the EU CRA, Delta Engineering guarantees security update support for a minimum period of 5 years after market placement.

Note for System Integrators & Machine Owners: Security updates are provided free of charge through the most appropriate delivery channel (typically via remote patch or secure portal). Where a digital update method is available, requesting local service technician support for manual installation may incur service charges.

Mandatory Regulatory Incident Reporting (CRA Art. 14)

In accordance with EU CRA requirements, Delta Engineering maintains active monitoring for exploited vulnerabilities:

  • Actively Exploited Vulnerabilities: Will be reported to the designated CSIRT / ENISA Single Reporting Platform (SRP) within 24 hours of awareness.
  • Severe Incidents: Full incident notifications and remediation details will be shared with affected industrial customers without undue delay  and within 72 hours of awareness.

Subscribe to the newsletter