Cybersecurity Vulnerability Management Policy
Antaira proactively complies with EU Cyber Resilience Act (CRA) standards to guarantee unwavering protection for industrial networks.
Our Commitment to Product Cybersecurity
At Antaira, we are dedicated to ensuring the highest level of cybersecurity for our products throughout their lifecycle. We take a proactive approach to vulnerability management, providing our customers with reliable guidance to help minimize risk and secure their operational networks.
Vulnerability Assessment and Remediation
Our Product Security Incident Response Team (PSIRT) and development engineers evaluate potential threats using the Common Vulnerability Scoring System (CVSS) alongside industry-leading, risk-based vulnerability management frameworks. When a potential vulnerability is identified, our PSIRT establishes a strict, prioritized remediation timeline based on the following factors:
• Security Context: How the vulnerability interacts with specific operational environments.
• Exploitability: The likelihood of the vulnerability being actively targeted or exploited.
• Potential Impact: The severity of the risk to our customers' operations and data.Global Regulatory and Industry Compliance
Global Regulatory and Industry Compliance
We are committed to transparency and maintain full alignment with mandatory international reporting standards and top-tier industrial cybersecurity frameworks. Our security protocols and development processes ensure stringent adherence to the EU Cyber Resilience Act (CRA), as well as the IEC 62443-4-1 (Secure Product Development Lifecycle) and IEC 62443-4-2 (Technical Security Requirements for IACS Components) standards.
How to Contact Us About Cybersecurity Vulnerabilities
Please inform us immediately if you identify a potential vulnerability in an Antaira product. At Antaira, timely detection of vulnerabilities is essential to safeguarding the security of our products. You may report potential cybersecurity vulnerabilities by emailing our Product Security Team. Please use Antaira's PGP key to encrypt any files you send.
When reporting a cybersecurity vulnerability, please include the following details to support our risk assessment and the subsequent development of remediation or mitigation measures:
• Product name and model
• Firmware or software version
• Equipment and software required to reproduce the issue
• Steps to recreate issues (please attach images or codes, if available)
• Proof-of-concept exploit code
• Description of how an attacker could exploit the vulnerability
• Packet capture (for example, using a tool such as Wireshark)
• Any other information you believe is relevant
Email address: psirt@antaira.com
Download: Antaira’s PGP key
Disclaimer
The content of this Cybersecurity Vulnerability Management Policy may change depending on the circumstances of individual cases. We cannot guarantee specific responses to issues or categories of issues. You will be responsible for any risks arising from using the information in this document or any content linked. Antaira reserves the right to revise any content in this document without prior notice. Any modifications to this document will be published on Antaira's official website: https://www.antaira.com/Cybersecurity