Bonfiglioli Product Security Incident Response Team (PSIRT)
Report a Product Security Vulnerability or Security Incident
1. Scope
This process applies to cybersecurity vulnerabilities and security incidents related to Bonfiglioli Products with Digital Elements, including drives, inverters, motion systems, controllers, IoT devices, communication modules, gateways, embedded software, firmware, companion applications and cloud services associated to the products.
If you are unsure whether your report falls within scope, please submit it and the PSIRT will perform an initial assessment.
2. What Should Be Reported
Bonfiglioli welcomes reports from customers, distributors, integrators, suppliers, partners and security researchers.
Security Vulnerabilities include authentication weaknesses, privilege escalation, hardcoded credentials, insecure configurations, weak cryptography, insecure update mechanisms, exposed interfaces and any weakness potentially impacting confidentiality, integrity, availability, authenticity or safety-related functions.
Security Incidents shall provide evidence of active exploitation by a malicious adversary, including malware execution, unauthorized access, compromise of firmware or software components, supply-chain related compromises and cybersecurity events affecting products already deployed in the field.
3. Coordinated Vulnerability Disclosure (CVD)
Bonfiglioli supports Coordinated Vulnerability Disclosure and encourages responsible reporting.
We kindly ask reporters to:
• Avoid public disclosure until Bonfiglioli has had a reasonable opportunity to validate the report and develop appropriate mitigations.
• Provide sufficient technical details for reproducibility
• Allow reasonable time for investigation and remediation
• Cooperate with Bonfiglioli throughout the assessment process
Where appropriate, Bonfiglioli may acknowledge contributors unless anonymity is requested.
4. Product Security Reporting Form
Reports should be submitted through the Bonfiglioli Product Security Reporting Form.
The form is designed to support rapid triage and collects structured information including:
• Reporter identity and contact details
• Product family
• Material number and serial number (when available)
• Type of report (Vulnerability, Security Incident, Suspected Security Issue)
• Technical description of the issue
• Evidence of exploitation or malicious activity
• Potential impact on product operation and safety-related functions
• Potential impact on Bonfiglioli products different than the one subject of the report
• Reproducibility information
• Supporting files such as logs, screenshots, traces or proof-of-concept material
Providing complete information significantly improves assessment speed and response effectiveness.
If you share any information with Bonfiglioli in the context of responsible disclosure, you agree that the information you submit will be considered non-proprietary. Bonfiglioli is allowed to use shared information, or part of it, without any restriction, including the actions related to regulatory reporting obligations.
5. Internal Handling process
Initial Triage and Classification
All reports are reviewed by the Bonfiglioli PSIRT.
The PSIRT performs an initial assessment to determine:
• Information completeness
• Scope applicability
• Security relevance
• Vulnerability versus Incident classification
• Urgency level
Reports that are not cybersecurity-related may be redirected to the appropriate support channel.
Cybersecurity-relevant reports are assigned to the responsible product team for technical investigation.
Vulnerability Assessment Process
For vulnerability reports, the responsible product team performs technical validation activities including reproducibility analysis, exploitability assessment, root cause identification, severity evaluation and safety impact assessment where applicable.
Security Incident Assessment Process
For security incidents or suspected incidents, the responsible product team performs incident analysis activities to determine whether exploitation has occurred, whether products are affected in the field and whether containment or mitigation actions are required.
Remediation and Corrective Actions
Depending on the assessment outcome, Bonfiglioli may implement:
• Security patches
• Firmware or software updates
• Configuration recommendations
• Product documentation updates
• Security hardening measures
• Customer notifications
• Security advisories
Remediation activities are prioritized based on severity, exploitability and customer impact.
6. Regulatory Reporting
Actively exploited vulnerabilities and severe security incidents.
Bonfiglioli evaluates confirmed vulnerabilities and security incidents against applicable regulatory obligations, including the EU Cyber Resilience Act (CRA).
Where required, Bonfiglioli may submit notifications and follow-up reports to competent authorities, including reports related to actively exploited vulnerabilities and severe security incidents.
Regulatory reporting activities are coordinated through the appropriate internal functions and governance processes.
Security Advisories and Customer Communication
When necessary, Bonfiglioli may issue Product Security Advisories.
Advisories may include:
• Affected products and versions
• Severity information
• Technical impact
• Mitigation recommendations
• Corrective actions
• Availability of patches or updates
Where appropriate, advisories may be communicated directly to affected customers and partners through the established channels.
7. Out of Scope
The following are generally outside the scope of the PSIRT process:
• Product quality issues without cybersecurity implications
• Functional defects unrelated to security
• Social engineering attacks against individuals
• Issues requiring unrealistic physical access and presenting no meaningful security impact
• Vulnerabilities affecting standalone third-party products not integrated into Bonfiglioli products
Bonfiglioli reserves the right to evaluate reports on a case-by-case basis.
8. Legal and Safe testing
Please do not disrupt services or customer operations, access or modify data without authorization, or test systems you do not own or have permission to test. Any testing must comply with applicable laws and agreements.
Contact