Digital product security

PSIRT

Product security incident response team and coordinated disclosure.

What it involves

What we do

A PSIRT manages the vulnerabilities affecting your products: receiving reports, triage, coordinating fixes, publishing advisories and communicating with customers, researchers and authorities, as required by the CRA.

What's included

  • Coordinated vulnerability disclosure policy
  • Report intake channel and triage
  • Fix, release and security advisory procedure
  • Notification to ENISA and authorities under the CRA
  • Communication with customers and researchers
  • Process metrics and improvement

Who it's for

  • Manufacturers subject to the Cyber Resilience Act
  • Software companies with a large customer base
  • Organisations that receive vulnerability reports

Deliverables

  • Operational PSIRT
  • Disclosure policy
  • Security advisory templates

Reference frameworks and standards

CRAISO/IEC 29147ISO/IEC 30111FIRST PSIRT Framework

Reference frameworks used to design, implement, review and evidence. They are not presented as our own certifications unless contractually applicable.

How we approach it

  1. DiscoverWe get to know your business, environment, risks and priorities.
  2. AnalyseWe assess maturity, exposure, compliance and real capabilities.
  3. DesignWe define strategy, roadmap, architecture and action plan.
  4. ImplementWe deliver controls, processes, technology and evidence.
  5. OperateWe monitor, respond and support continuous improvement.
  6. OptimiseWe measure results, reduce risk and evolve capabilities.

Let's talk

Does PSIRT fit your situation?

Tell us about your challenges and let's design together the best strategy to protect and strengthen your business.