OMET Coordinated Vulnerability Disclosure Policy

1. Purpose

OMET designs and manufactures printing and converting machines. A modern machine is a connected system, and its security depends on the design, on the components integrated into it, and on how it is operated. This policy describes how OMET receives, assesses and resolves reports of security vulnerabilities affecting its products, and what those who report can expect in return.

The policy applies to reports from any source: customers, security researchers, suppliers, authorities and members of the public.

2. Scope

This policy covers:

Vulnerabilities in third party components integrated into an OMET machine also fall within this policy: see section 7.

The following are outside the scope of this policy and should be directed through the usual OMET contact channels: machine faults with no security relevance, requests for technical assistance, spare parts and documentation, security questionnaires and compliance documentation, and reports concerning the infrastructure or configuration of a customer network rather than the machine itself.

3. How to report

Reports are submitted through the OMET security vulnerability reporting form at https://omet.com/en/vulnerabilita-della-sicurezza-e-segnalazione-degli-incidenti/, which is the single point of contact for product security.

The form is served over an encrypted connection (TLS). If a report includes material that should not be transmitted through a web form, such as an exploit, extensive log files or data belonging to a third party, the report should describe the finding at a level sufficient to allow triage and state that further material is available. A secure exchange channel will then be agreed directly with the reporter.

Reports may be submitted in Italian or English.

4. Information to include

A report can be assessed more quickly when it contains:

An incomplete report is still worth sending. Missing details can be requested during triage.

5. How OMET handles a report

Acknowledgement. OMET acknowledges receipt of every report submitted through the single point of contact within five working days.

Triage. The PSIRT, which brings together product security, software engineering, machine safety and service, verifies the finding and assesses its severity and its impact on the machines concerned. A report indicating a possible effect on a safety function is escalated to the machine safety function immediately and is not closed until both functions have signed off.

Remediation. Where a finding is confirmed, OMET determines the affected platforms, versions and installed base, develops a correction or a mitigation, and prepares the deployment guidance required to apply it without compromising production continuity or machine qualification.

Closure. A report is closed when a correction or a documented mitigation is available, or when the analysis concludes that the finding does not constitute a vulnerability in an OMET product. In either case the outcome is communicated to the reporter with the reasoning behind it.

6. Communication with the reporter

OMET keeps the reporter informed of the progress of the analysis and of the remediation, agrees a disclosure timeline, and shares the content of the planned advisory before publication where the reporter wishes to review it.

OMET asks that the reporter treat the details of the report as confidential until the agreed disclosure date.

7. Third party components

An OMET machine integrates drives, controllers, safety devices, inspection systems, sensors and software supplied by specialised manufacturers.

Where a reported vulnerability concerns such a component, OMET notifies the manufacturer or maintainer of that component, assesses whether and how the vulnerability affects the configurations OMET places on the market, and coordinates remediation. The reporter is not expected to approach the supplier separately, although they remain free to do so.

Where OMET identifies a vulnerability in an integrated component through its own analysis, the same notification applies.

8. Public disclosure

Once a security update or a documented mitigation is available, OMET publishes a security advisory describing the vulnerability, identifying the affected products and versions, stating the impact and severity, and giving the information users need to remediate.

Publication may be deferred where disclosing before users have had a realistic opportunity to apply the update would increase rather than reduce risk. Machines installed in production cannot be updated at the speed of internet delivered software, and OMET weighs this in setting a disclosure date.

Where the reporter consents, they are credited in the advisory.

9. What OMET asks

Those reporting a vulnerability are asked to:

Testing on a machine in production is not acceptable under any circumstances.

10. Protection for good faith reporters

OMET will not pursue or support legal action against anyone who reports a vulnerability in good faith and acts in accordance with this policy. This applies even where the report turns out to be unfounded, provided the conduct described in section 9 has been observed.

11. Regulatory reporting

Where a vulnerability in an OMET product is actively exploited, OMET is required to notify ENISA and the relevant CSIRT under Regulation (EU) 2024/2847. Such a notification may take place before public disclosure and independently of the timeline agreed with the reporter. Personal data of the reporter is not included in these notifications.

12. Recognition

OMET does not operate a bug bounty programme and does not offer financial rewards for vulnerability reports. Recognition takes the form of credit in the published advisory, where the reporter wishes it.

13. Personal data

Personal data provided when submitting a report is processed solely for the purpose of handling the report and fulfilling the related legal obligations. See the privacy notice: https://www.iubenda.com/privacy-policy/23723745.