At Markem-Imaje cybersecurity is an integral part of how we design, develop, manufacture, deploy, and maintain our products. We are committed to protecting our customers, partners, and stakeholders by continuously improving the security and resilience of our products throughout their lifecycle.
We recognize the important role that customers, partners, security researchers and the broader security community play in identifying and responsibly reporting potential vulnerabilities. Our Coordinated Vulnerability Disclosure (CVD) process provides a clear and transparent mechanism for reporting security vulnerabilities and working collaboratively towards their timely resolution.
Our vulnerability management and disclosure practices are aligned with industry-recognized security principles and applicable regulatory requirements, including relevant obligations under the EU Cyber Resilience Act (CRA).
A customer, security researcher, partner, supplier, or other stakeholder reports suspected security vulnerability through our designated reporting channels.
Our Product Security Incident Response Team (PSIRT) reviews the submission and acknowledges receipt of the report, typically within a reasonable timeframe.
The reported issue is assessed to determine:
The Product security incident response team (PSIRT) coordinates with product engineering, software development, quality, compliance, and other stakeholders to investigate the issue, determine root cause, and assess risk.
Appropriate remediation actions may include:
Where appropriate, customers are informed through security advisories, release notes, direct communications, or other approved communication channels.
We support responsible and coordinated disclosure practices. Public disclosure should occur only after remediation or mitigation is available, or after an agreed disclosure timeline has been reached.
Lessons and improvements from vulnerability investigations are incorporated into our secure development lifecycle, threat modeling activities, security testing programs, and product security governance processes.
In Scope include:
Reported vulnerabilities may be evaluated based on:
We encourage responsible disclosure of suspected vulnerabilities affecting our products and services.
Product Security Incident Response Team (PSIRT)
Information to include
To assist with our investigation, please include:
What Happens After Submission?
Upon receiving your report:
Expectations for Security Researchers
We welcome responsible security research and ask researchers to:
Researchers who act responsibly and in good faith in accordance with this policy will be treated as valued contributors to our security program.
The Product Security Incident Response Team (PSIRT) is responsible for managing product security vulnerabilities throughout their lifecycle and coordinating vulnerability response activities across the organization.
The PSIRT is responsible for:
The PSIRT operates under the organization's Product Security Governance Framework and works closely with:
Vulnerabilities are prioritized using a risk-based approach considering exploitability, customer impact, safety implications, business impact, and applicable regulatory requirements.
To promote transparency and customer awareness, Markem-Imaje publishes security advisories for confirmed vulnerabilities affecting our products and services.
Security advisories may include:
Published advisories, mitigation guidance, and remediation notices are available at this Security Advisory section.
Customers are encouraged to review advisories regularly and implement recommended updates.
Note – we do not have any notifications as on date, and this section shall be populated as we encounter such in the future.
As part of our product security program, reported vulnerabilities may be assessed against applicable regulatory, legal, contractual, and industry obligations.
Where required, Markem-Imaje may notify relevant authorities, affected customers, distributors, partners, and other stakeholders regarding significant cybersecurity vulnerabilities or incidents in accordance with applicable laws and regulations, including the EU Cyber Resilience Act.
Our objective is to ensure vulnerabilities are addressed in a timely, risk-based, and transparent manner while protecting customers and maintaining product resilience.
This Coordinated Vulnerability Disclosure Policy is intended solely for reporting legitimate security vulnerabilities affecting products and services owned, developed, maintained, and supported by Markem-Imaje.
By submitting a vulnerability report, you acknowledge that:
Any personal data submitted as part of a vulnerability report will be processed solely for the purposes of evaluating, investigating, remediating, and managing the reported vulnerability, as well as complying with applicable legal and regulatory obligations. Reporters should avoid including unnecessary personal data, confidential customer information, credentials, or production data unless strictly necessary to demonstrate the reported vulnerability. Any personal data received through this process will be processed in accordance with the Markem-Imaje Privacy Notice and retained only for as long as necessary for these purposes. While Markem-Imaje will review vulnerability reports submitted in good faith, it does not guarantee that every submission will result in remediation, acknowledgement, or further communication. Where applicable, personal data may be shared with other Markem-Imaje entities, Dover group companies, or service providers strictly involved in the investigation and remediation of the reported vulnerability, subject to appropriate confidentiality, security, and data protection safeguards.