- Purpose
This policy defines the formal procedures by which IMET receives, assesses, manages, and discloses security vulnerabilities affecting its products with digital elements for which it is the manufacturer. The objective is to ensure a secure, transparent, and collaborative channel for mitigating risks.
- ApplicabilitàScope
The provisions of this policy apply to all products with digital elements placed on the market by IMET that fall within the scope of Regulation (EU) 2024/2847 (Cyber Resilience Act – CRA), whose applicability begins on 11 September 2026.
- Definitions
For the purposes of this policy, the following definitions shall apply in accordance with the CRA:
- Product with digital elements (Product): Any hardware or software product and its related remote data processing solutions, including software or hardware components intended to be integrated, placed on the market, including when placed on the market separately;
- Support period: The support period during which the manufacturer ensures that vulnerabilities affecting a product are managed effectively, promptly, and in compliance with the essential cybersecurity requirements;
- Vulnerability: A weakness, susceptibility, or defect in products or digital services that can be exploited by a cyber threat;
- Exploitable vulnerability:A vulnerability in a product that can be effectively exploited by a malicious user under real-world operating conditions;
- Actively exploited vulnerability: A vulnerability for which there is reliable evidence that a malicious actor has exploited or used it in a system without the authorization of the system owner;
- Incident: Any accidental or intentional event capable of compromising the fundamental properties of data and corporate systems (Confidentiality, Integrity, Availability, and Authenticity), resulting in service disruption or unauthorized access to information;
- Serious indicent: An incident that adversely affects, or is capable of adversely affecting, the product’s ability to protect sensitive data or functions, or that has resulted, or may result, in the introduction or execution of malicious code in the product or in the networks of the product user.
- General Principles
IMET recognizes the strategic importance of collaboration with the security research community, customers, and end users. We are committed to:
- encourage and promote the responsible and coordinated reporting of vulnerabilities.
- ensure the strictest confidentiality of the information received throughout the entire analysis process;
- handle each report with due diligence, promptness, and impartiality, without discrimination;
- adopt a Safe Harbor principle: IMET will refrain from taking legal action against reporters (e.g., ethical security researchers) who act in good faith, in compliance with this policy and applicable lawsdottare un principio di Safe Harbor.
- Vulnerability Reporting
5.1. Reporting Procedure
To enable the secure receipt of vulnerability reports, IMET has established the following dedicated points of contact:
- E-mail: cybersecurity@imet.eu;
- Web Portal: https://www.imetradioremotecontrol.com/it/cybersecurity
Note: Each report received will receive an automatic acknowledgment of receipt sent by email to the reporter within the timeframes specified by international guidelines.
5.2. Content of the report
To enable rapid validation, the report should include:
- a valid e-mail address for maintaining communications;
- precise identification of the Product (model, serial number or SID, software/firmware version, hardware version);
- a detailed description of the vulnerability, the conditions or steps required to reproduce it (PoC – Proof of Concept), and any indication of suspected active or malicious exploitation;
- any other useful technical details (e.g., logs, screenshots, configurations).
- Vulnerability Analysis and Remediation
All reports received in accordance with the provisions set out in Section 5.1 are handled by the internal security team and classified according to the following operational scenarios:
- product outside the support period: in this case, IMET will provide the reporter with a formal response specifying the end of the support period for the specific model.
- product within the support period:
- integrated third-party component: IMET will forward the report to the manufacturer of the affected component in accordance with the CRA supply-chain obligations, through the formal tracking of dependencies (SBOM), while implementing temporary mitigation measures where possible
- no actual risk (False Positive): A technical explanation will be provided to the reporter outlining why the anomaly does not compromise the cybersecurity of the product;
- confirmed vulnerability: in this case, the internal remediation procedure is initiated, which may involve the development of updates (new versions) or, in more serious cases, a physical recall campaign for the affected batches.
6.1. Product Security Software Updates
In the event of a confirmed vulnerability, as described in Section 6, that requires code changes, IMET shall proceed as follows:
- develops and tests the necessary software update or security release;
- precisely identifies all affected batches, models, and software versions;
- traces and identifies known customers and users of the affected products;
- promptly notifies the relevant parties by email (or equivalent operational channels), providing detailed instructions for applying the update;
If the update cannot be deployed remotely, alternative procedures will be defined, including targeted maintenance campaigns or physical product recall campaigns.
In accordance with the CRA, security updates will remain available for download or installation for a minimum period of 10 years from the placing of the product on the market, or for the entire duration of the support period if this is longern.
- Vulnerability Information Disclosure
Following validation and the availability of the security release (or an effective mitigation), IMET shall prepare a Security Advisory containing:
- unique vulnerability identifier;
- type, model, and versions of the affected Product;
- technical description, severity level, and potential impact;
- clear instructions for applying the remediation measures for the identified vulnerability (e.g., firmware update, configuration changes, etc.)
This information is immediately provided to the reporter and affected customers. At the company’s discretion, a summary of the advisories may be published on the company’s website.
- Permitted and Prohibited Conduct (Disclosure Guidelines)
To ensure that vulnerability research and testing activities are conducted safely and ethically, reporters are required to comply with the following guidelines. Compliance with these conditions ensures the application of the Safe Harbor principle set out in Section 4.
8.1. Permitted Conduct
- security testing activities on the Product are permitted only to the extent strictly necessary to demonstrate the existence of the vulnerability;
- all activities must be minimized to avoid any adverse impact or disruption to operational systems, data integrity, and the end-user experience.
8.2. Unadmitted Conduct
The following activities are strictly prohibited:
- accessing, modifying, downloading, or exfiltrating personal, confidential, or sensitive data belonging to the company or third parties that is not strictly necessary to demonstrate the existence of the vulnerability;
- compromising the operational continuity or availability of the Product’s services or connected infrastructure (e.g., through Denial-of-Service (DoS/DDoS) attacks).
- introducing, testing, or executing malware or ransomware on the Product or connected systems;
- copying, altering, manipulating, or deleting system data and files;
- making permanent or unauthorized changes to the configuration or code of the Product under analysis;
- conducting automated brute-force attacks or social engineering techniques (e.g., phishing) against IMET personnel or its customers;
- exploiting the identified vulnerability for profit, extortion, or purposes other than reporting it to IMET;
- publishing, selling, or disclosing details of the vulnerability to third parties without IMET’s prior written authorization and coordinated approval.
- Acknowledgment of Vulnerability Reporters
I IMET values the contributions of the cybersecurity community. At its sole discretion, IMET may acknowledge the contributions of individuals who have reported vulnerabilities in a valid and timely manner and in compliance with this Coordinated Vulnerability Disclosure (CVD) Policy.
Such acknowledgments, subject to the reporter’s explicit written consent, may include:
- publication of the individual’s name (or pseudonym) on the official acknowledgment page (Hall of Fame) in dedicated;
- official acknowledgment of the reporter in the public vulnerability disclosure documents (Security Advisories) described in Section 7.
- Policy Updates and Review
This Coordinated Vulnerability Disclosure Policy is subject to periodic review to ensure its alignment with technological developments, ENISA guidelines, and the harmonized standards established under the Cyber Resilience Act (CRA).
- IMET reserves the right to amend or update this document at any time.
- The currently applicable and legally binding version of this document is continuously made available for public consultation on the following web page: https://www.imetradioremotecontrol.com/it/cybersecurity.
- Mandatory Notification Obligations to Authorities (Article 11 of the CRA)
In accordance with the mandatory provisions of Article 11 of the Cyber Resilience Act (CRA), IMET shall adopt the following emergency procedures in the event of critical vulnerabilities:
- Actively exploited vulnerabilities: If a vulnerability in our product is identified as being actively exploited by malicious third parties in the market, IMET shall submit a formal preliminary notification to the competent national CSIRT and ENISA within 24 hours of becoming aware of it. A comprehensive technical report shall be submitted within 72 hours.
- Serious cybersecurity incidents: Any cybersecurity incident that significantly impacts the availability, integrity, or confidentiality of the Product shall be promptly reported to the CSIRT and ENISA within 24 hours (initial emergency notification), followed by a detailed analysis within 72 hours. At the same time, urgent mitigation communications shall be issued to the end users of the affected batches.