Coordinated Vulnerability Disclosure Policy 

PUBLIC POLICY FOR REPORTING, HANDLING AND COORDINATED DISCLOSURE OF CYBERSECURITY VULNERABILITIES

1. Purpose

CNi Group welcomes reports from customers, machine manufacturers, system integrators, security researchers and other parties concerning potential cybersecurity vulnerabilities in CNi Group products. This policy describes how to submit a report, how CNi Group handles and coordinates the report, and how information relating to a confirmed and remediated vulnerability will be communicated and publicly disclosed in accordance with applicable legal requirements. This policy supports the vulnerability-handling requirements of Regulation (EU) 2024/2847 (Cyber Resilience Act), including the establishment and enforcement of a coordinated vulnerability disclosure policy and the provision of a contact address for reporting vulnerabilities.

2. Scope

This policy applies to all CNi Group hardware, firmware and software products, including the associated configuration, programming, update and maintenance tools. Vulnerabilities in third-party components integrated into a CNi Group product fall within the scope of this policy where they may compromise the security of that product. CNi Group accepts reports concerning all its products. For products and versions within their declared support period, CNi Group will analyse and remediate identified vulnerabilities without undue delay. Corrective measures may include security updates, mitigation measures, configuration guidance or other appropriate remediation. For products outside the support period, CNi Group may provide, where reasonably practicable, risk information, mitigation measures, upgrade guidance or recommendations for product replacement. A reported issue may be considered outside the scope applicable to CNi Group products where it concerns only: third-party products, systems or infrastructure not supplied or controlled by CNi Group; customer-developed machine applications, unless the issue is caused by a vulnerability in a CNi Group product; customer networks, remote-access systems or security measures not supplied by CNi Group; social engineering activities, fraud or physical-security issues unrelated to a CNi Group product vulnerability.

3. How to report a potential vulnerability

Send reports to: service@cnigroup.net

Reports may be submitted in Italian or English. Please use a clear subject line, for example: “Potential vulnerability report – [product name/model]”

Where available, include the following information:

hardware revision and serial number, where relevant;
firmware or software version;
description of the potential vulnerability and the observed behaviour;
steps required to reproduce the issue;
proof-of-concept information or diagnostic evidence;
potential impact on confidentiality, integrity, availability, machine operation or safety;
indication of whether exploitation of the vulnerability has already been observed or is suspected;
reporter name, organisation and contact details;
preferred method for continued communication.

Sensitive information. CNi Group does not currently provide a public PGP key or a public secure-upload portal.
Do not include credentials, customer production data, confidential machine programs, personal data or detailed exploit material in the initial email. It is sufficient to state that sensitive information is available; where necessary, CNi Group will arrange an appropriate communication method.

4. Responsible reporting and testing conditions

Testing must be conducted exclusively on systems owned by the reporter or on systems for which the reporter has received explicit authorisation from the owner. Because CNi Group products may control industrial machinery, testing activities must not create risks to persons, machinery, production or the environment.

Reporters are requested to:

use a non-production environment or otherwise controlled test environment;
avoid accessing, altering, copying or deleting data beyond what is strictly necessary to demonstrate the issue;
avoid persistence techniques, lateral movement within systems, social engineering activities and physical intrusion;
avoid denial-of-service attacks, resource exhaustion and high-volume automated testing;
avoid any test that may cause machine movement, unexpected output activation, loss of control or other hazardous conditions;
stop testing immediately if a safety, operational, privacy or data-protection risk becomes apparent;
provide CNi Group with a reasonable opportunity to investigate and resolve the issue before proceeding with public disclosure;
coordinate the timing and content of any public disclosure with CNi Group.

This policy does not authorise unlawful activity and does not grant immunity from any civil, criminal, contractual or regulatory consequences.

5. Monitoring and acknowledgement

Reports may be submitted at any time. The Service mailbox is monitored during the following business hours:

from Monday to Friday: 09:0013:00 and 14:0018:00;
time zone: local time Europe/Rome (CET/CEST);
Saturday and Sunday: closed.

This policy does not authorise unlawful activity and does not grant immunity from any civil, criminal, contractual or regulatory consequences.

6. CNi Group handling process

CNi Group handles reports through a documented vulnerability-management process. Depending on the reported issue, the process includes:

registering the report and assigning a case identifier;
confirming the affected product, its version and support status;
assessing whether the reported behaviour actually constitutes a cybersecurity vulnerability;
evaluating severity, exploitability, potential operational or safety impact and any evidence of active exploitation;
identifying other products, versions or third-party components that may be affected;
defining the necessary corrective measures, security updates, mitigations or operational guidance;
verifying and validating the corrective measure;
coordinating communications with the reporter and with affected customers, machine manufacturers or system integrators;
publishing or distributing, where appropriate, information relating to the vulnerability and instructions for its remediation or mitigation;
retaining case documentation and relevant evidence.

Where reasonably practicable, CNi Group will provide status updates at significant stages of the investigation. The nature and frequency of such updates will depend on the complexity, severity and sensitivity of the case.

7. Assessment and prioritization

CNi Group may use a documented method for assessing vulnerability severity, such as the Common Vulnerability Scoring System (CVSS), together with product-specific technical judgement.

Factors considered may include:

required access and privileges;
ease and reliability of exploitation;
affected products and versions;
impact on confidentiality, integrity and availability;
impact on machine control, production continuity or safety;
availability of mitigation measures or compensating controls;
evidence of active exploitation;
support status and product use or deployment context.

8. Corrective measures and security updates

Where a confirmed vulnerability requires action, CNi Group will address and remediate it without undue delay during the applicable support period. Corrective measures may include one or more of the following actions:

a firmware or software security update;
a revised configuration or parameter modification;
instructions to disable or restrict an affected service or protocol;
network-segmentation, firewall or access-control measures;
operational restrictions or temporary mitigation measures;
upgrade, replacement or migration guidance.

Security updates and related instructions will be distributed securely and without undue delay through authorised CNi Group channels or through the relevant machine manufacturer or system integrator.

Security updates will be accompanied by clear information describing the actions affected users should take. Security updates will be provided free of charge, unless otherwise agreed between CNi Group and a business user in relation to a tailor-made product with digital elements.

Where technically feasible, new security updates will be provided separately from functionality updates.

9. Coordinated disclosure

CNi Group will determine disclosure timing on a case-by-case basis, taking into account the severity of the vulnerability, any active exploitation, potential safety consequences, the availability of a correction or mitigation measure, validation requirements and the time reasonably required for affected machine manufacturers, system integrators and users to implement corrective measures.

Once a security update or other effective corrective measure is available, CNi Group will publicly disclose information relating to the fixed vulnerability. Such information will enable affected users to identify the relevant product and affected versions, understand the nature, impact and severity of the vulnerability, and apply the available remediation or mitigation measures.

Public disclosure may be delayed only in duly justified cases where the security risks arising from publication outweigh the security benefits, and only until affected users have had the opportunity to apply the relevant patch or other corrective measure.

CNi Group requests that reporters do not publicly disclose vulnerability details before a coordinated disclosure date has been agreed or before affected users have had a reasonable opportunity to apply the available corrective measures.

10. Security advisories and customer notification

Relevant security advisories, corrective measures and mitigation instructions will be communicated to affected customers through the relevant machine manufacturer or system integrator, or directly by CNi Group where a direct customer relationship exists.

A security advisory concerning a fixed vulnerability will include, at minimum:

affected products and versions;
a description of the vulnerability;
the impact and severity of the vulnerability;
the available correction, mitigation measures or operational guidance;
the fixed version, where available, and clear remediation or mitigation instructions.

Where appropriate, the advisory may also include an advisory identifier, publication date, information on known exploitation of the vulnerability and revision history.

11. Reporter acknowledgement

With the reporter’s explicit consent, CNi Group may acknowledge the contribution of the reporter or the reporter’s organisation in a security advisory. Such acknowledgement may be withheld where attribution could create confidentiality, privacy, legal, contractual, safety or operational concerns.

CNi Group does not currently operate a bug-bounty or financial-reward programme.
Submission of a report does not create an entitlement to payment, compensation or other reward.

12. Regulatory notifications

CNi Group assesses reported vulnerabilities and security incidents to determine whether notification obligations under Article 14 of Regulation (EU) 2024/2847 (Cyber Resilience Act) or other applicable law are triggered.

A report submitted under this policy does not automatically trigger an obligation to notify the competent authorities. Where the criteria established by applicable law are met, CNi Group will make the required notifications through the designated reporting channels and within the applicable deadlines.

13. Confidentiality and personal data

Vulnerability reports will be handled on a need-to-know basis. CNi Group will use the information received exclusively to investigate, remediate, coordinate and document the reported issue, as well as to comply with applicable legal obligations.

The reporter’s identity will not normally be made public without the reporter’s explicit consent, except where disclosure is required by law, a competent authority or a binding legal process.

Reporters are requested not to submit personal data or confidential information that is not strictly necessary for the vulnerability report.

14. Report outcomes and policy changes

Not every submitted report will necessarily result in a security update or the publication of a security advisory. This may occur, for example, where the issue is not reproducible, is a duplicate report, falls outside the scope of this policy or does not constitute a cybersecurity vulnerability.

This section does not limit CNi Group’s obligation to address and remediate confirmed vulnerabilities or to disclose information relating to fixed vulnerabilities where required by applicable law.

CNi Group may update this policy to reflect changes in products, processes, standards or applicable law.

15. Contact information

Legal EntityCni Informatica Srl
Operating under the name CNi Group
AddressVia del Lavoro 13, Alfonsine (RA), 48011
PSIRT E-mailservice@cnigroup.net
Websitewww.cnigroup.net
LanguagesEnglish / Italian

Scroll to Top