Cybersecurity at CE+T Power

Cybersecurity is an integral part of the design, development and lifecycle management of CE+T Power products.

Our products are used in industrial power conversion systems, including applications where availability, integrity and secure remote or local access are important operational requirements. We therefore continuously work to improve the cybersecurity of our products, development processes and support practices.

Our approach to product cybersecurity

CE+T Power applies a risk-based approach to product cybersecurity throughout the product lifecycle.

Depending on the product and its intended use, this includes measures such as:

  • Secure product architecture and network segmentation;
  • Authentication and access control;
  • Protection of firmware and software updates;
  • Use of cryptographic mechanisms where appropriate;
  • Management of third-party and open-source software components;
  • Monitoring and remediation of known vulnerabilities;
  • Security testing and review during product development;
  • Secure configuration guidance for customers and system integrators;
  • Vulnerability handling and coordinated disclosure processes.

Cybersecurity requirements are reviewed as products evolve and as applicable standards, regulations and industry practices develop.

Regulations and standards

CE+T Power monitors and progressively implements applicable cybersecurity requirements and recognised industry standards relevant to its products.

This includes, where applicable:

  • European Cyber Resilience Act — Regulation (EU) 2024/2847
  • Guidance from applicable cybersecurity standards for industrial automation and control systems, including the IEC 62443 family;
  • Recognised secure development and vulnerability management practices;

The applicability of individual regulations and standards depends on the product, its intended purpose, configuration and market.

Compliance statements, certificates or detailed product-specific cybersecurity information should therefore be requested for the relevant product rather than assumed to apply to all CE+T Power products.

Reporting a cybersecurity vulnerability

CE+T Power welcomes responsible reports from customers, integrators, security researchers and other parties who identify a potential cybersecurity vulnerability affecting a CE+T Power product.

Single point of contact to report security vulnerabilities
cybersecurity@cet-power.com

Important: this address is not a support contact !

This mailbox is monitored by CE+T Power’s Information Security team during Belgian business hours. It is our single point of contact under Article 13(17) of Regulation (EU) 2024/2847 (the Cyber Resilience Act), and the contact address required by Annex I, Part II, point 6 of that Regulation. You may write to us in English, French or Dutch.

When reporting a vulnerability, please provide as much relevant information as possible, such as:

  • The product name and commercial reference (for example Inview X);
  • Affected product firmware/software version;
  • The serial number of the unit, if you have it;
  • Description of the observed or suspected vulnerability and its potential impact;
  • Steps or conditions required to reproduce the issue;
  • The configuration or environment in which you observed it;
  • Potential security impact;
  • Supporting logs, screenshots or technical details where appropriate;
  • How and if you would like to be credited, if the issue is later published;
  • Your contact information if you would like us to follow up with you.

Please avoid including passwords, private keys, customer-confidential information or other sensitive credentials unless specifically requested through an agreed secure communication channel.

What happens next

Stage
What we commit to
Acknowledgement
We confirm receipt within 3 business days.
First assessment
Within 10 business days we tell you whether we can reproduce the issue and how we have classified it.
Progress
We keep you informed at least every 30 days until the matter is closed.
Resolution
We agree the timing of publication with you, ordinarily publishing once a fix or a mitigation is available.

Where a vulnerability is being actively exploited, or an incident severely affects the security of one of our products, we are also required to notify ENISA and the Belgian national CSIRT (CCB / CERT.be) within the deadlines set by Article 14 of the Cyber Resilience Act. Reporting to us creates no notification obligation of your own.

Important: this address is not a support contact 

cybersecurity@cet-power.com is intended exclusively for reporting suspected cybersecurity vulnerabilities or product related cybersecurity incidents affecting CE+T Power products.

It must not be used for: 

  • General technical support;
  • Installation or commissioning questions;
  • Product configuration assistance;
  • Questions about cybersecurity features or available security options;
  • Requests for documentation, certificates or compliance statements;
  • Account or access issues unrelated to a suspected vulnerability.

For questions about the cybersecurity capabilities of a product, applicable standards, product compliance, or available security options, please contact your CE+T Power sales representative.

For questions about data protection and privacy requests, please see our Privacy Policy.

For technical questions related to product installation, configuration or operation, please use the CE+T Power technical support portal.

Responsible disclosure

We ask security researchers and other reporters to act responsibly when investigating and reporting potential vulnerabilities.

In particular, please:

  • Avoid actions that may disrupt customer systems or operational installations;
  • Do not access, modify or destroy data that does not belong to you;
  • Do not attempt to compromise systems belonging to CE+T Power customers without explicit authorisation;
  • Avoid publicly disclosing technical details before CE+T Power has had a reasonable opportunity to investigate and, where necessary, provide a mitigation or corrective update;
  • Provide sufficient information to allow the issue to be reproduced and assessed.
  • Give us a reasonable opportunity to fix the issue before making it public, 90 days from acknowledgement is our normal expectation, and we will tell you promptly if a fix will take longer;

CE+T Power aims to work constructively with reporters to understand and address legitimate security issues. CE+T Power does not operate a paid bug bounty programme. We offer no financial reward, but we do recognise the researchers who help us.

Product security updates

When a cybersecurity issue requires corrective action, CE+T Power may provide one or more of the following, depending on the nature and severity of the issue:

  • Firmware or software updates;
  • Configuration recommendations;
  • Temporary mitigation measures;
  • Technical advisories;
  • Customer-specific communications;
  • Updated product documentation.

Customers are encouraged to keep supported CE+T Power products up to date and to follow the network architecture, access-control and security recommendations provided in the relevant product documentation.

Cybersecurity Advisories

CE+T Power publishes security advisories for confirmed cybersecurity vulnerabilities affecting supported products. These advisories provide information about affected products, severity, remediation measures and fixed software or firmware versions.

View all published cybersecurity advisories

Contact summary

Report a suspected cybersecurity vulnerability or security incident
cybersecurity@cet-power.com
Product cybersecurity, compliance or security-feature questions
Contact your CE+T sales rep
Technical support, configuration or operational questions
Go to MYCET

 

Days
Hours
Min
Sec
Prisma is here
Our new Power Conversion System is now available. Compact, flexible, and ready for your energy challenges.
Learn more