{"id":532,"date":"2026-09-03T07:42:15","date_gmt":"2026-09-03T07:42:15","guid":{"rendered":"https:\/\/omet.com\/?page_id=532"},"modified":"2026-09-03T07:42:53","modified_gmt":"2026-09-03T07:42:53","slug":"policy-omet-di-divulgazione-coordinata-delle-vulnerabilita","status":"publish","type":"page","link":"https:\/\/omet.com\/en\/policy-omet-di-divulgazione-coordinata-delle-vulnerabilita\/","title":{"rendered":"OMET Coordinated Vulnerability Disclosure Policy"},"content":{"rendered":"<p><\/p>\n<h2 id=\"1-purpose\">1. Purpose<\/h2>\n<p>OMET designs and manufactures printing and converting machines. A modern machine is a connected system, and its security depends on the design, on the components integrated into it, and on how it is operated. This policy describes how OMET receives, assesses and resolves reports of security vulnerabilities affecting its products, and what those who report can expect in return.<\/p>\n<p>The policy applies to reports from any source: customers, security researchers, suppliers, authorities and members of the public.<\/p>\n<h2 id=\"2-scope\">2. Scope<\/h2>\n<p>This policy covers:<\/p>\n<ul>\n<li>machines designed and manufactured by OMET, including the control software, human machine interfaces and industrial PCs supplied with them<\/li>\n<li>software products, applications and tools distributed by OMET<\/li>\n<li>remote assistance and remote data processing solutions provided by OMET as part of a machine<\/li>\n<li>OMET websites and customer facing web services<\/li>\n<\/ul>\n<p>Vulnerabilities in third party components integrated into an OMET machine also fall within this policy: see section 7.<\/p>\n<p>The following are outside the scope of this policy and should be directed through the usual OMET contact channels: machine faults with no security relevance, requests for technical assistance, spare parts and documentation, security questionnaires and compliance documentation, and reports concerning the infrastructure or configuration of a customer network rather than the machine itself.<\/p>\n<h2 id=\"3-how-to-report\">3. How to report<\/h2>\n<p>Reports are submitted through the OMET security vulnerability reporting form at <a href=\"https:\/\/omet.com\/en\/vulnerabilita-della-sicurezza-e-segnalazione-degli-incidenti\/\">https:\/\/omet.com\/en\/vulnerabilita-della-sicurezza-e-segnalazione-degli-incidenti\/<\/a>, which is the single point of contact for product security.<\/p>\n<p>The form is served over an encrypted connection (TLS). If a report includes material that should not be transmitted through a web form, such as an exploit, extensive log files or data belonging to a third party, the report should describe the finding at a level sufficient to allow triage and state that further material is available. A secure exchange channel will then be agreed directly with the reporter.<\/p>\n<p>Reports may be submitted in Italian or English.<\/p>\n<h2 id=\"4-information-to-include\">4. Information to include<\/h2>\n<p>A report can be assessed more quickly when it contains:<\/p>\n<ul>\n<li>the machine platform, model and serial number, or the name and version of the software product<\/li>\n<li>the software or firmware version of the affected component<\/li>\n<li>a description of the vulnerability and of its potential impact, including any effect on machine safety functions<\/li>\n<li>the conditions required to exploit it, for example network position, level of access or physical presence at the machine<\/li>\n<li>the steps required to reproduce it, with any logs, screenshots or proof of concept<\/li>\n<li>whether the machine concerned is currently in production<\/li>\n<li>contact details for follow up, and whether public credit is desired<\/li>\n<\/ul>\n<p>An incomplete report is still worth sending. Missing details can be requested during triage.<\/p>\n<h2 id=\"5-how-omet-handles-a-report\">5. How OMET handles a report<\/h2>\n<p><strong>Acknowledgement.<\/strong> OMET acknowledges receipt of every report submitted through the single point of contact within five working days.<\/p>\n<p><strong>Triage.<\/strong> The PSIRT, which brings together product security, software engineering, machine safety and service, verifies the finding and assesses its severity and its impact on the machines concerned. A report indicating a possible effect on a safety function is escalated to the machine safety function immediately and is not closed until both functions have signed off.<\/p>\n<p><strong>Remediation.<\/strong> Where a finding is confirmed, OMET determines the affected platforms, versions and installed base, develops a correction or a mitigation, and prepares the deployment guidance required to apply it without compromising production continuity or machine qualification.<\/p>\n<p><strong>Closure.<\/strong> A report is closed when a correction or a documented mitigation is available, or when the analysis concludes that the finding does not constitute a vulnerability in an OMET product. In either case the outcome is communicated to the reporter with the reasoning behind it.<\/p>\n<h2 id=\"6-communication-with-the-reporter\">6. Communication with the reporter<\/h2>\n<p>OMET keeps the reporter informed of the progress of the analysis and of the remediation, agrees a disclosure timeline, and shares the content of the planned advisory before publication where the reporter wishes to review it.<\/p>\n<p>OMET asks that the reporter treat the details of the report as confidential until the agreed disclosure date.<\/p>\n<h2 id=\"7-third-party-components\">7. Third party components<\/h2>\n<p>An OMET machine integrates drives, controllers, safety devices, inspection systems, sensors and software supplied by specialised manufacturers.<\/p>\n<p>Where a reported vulnerability concerns such a component, OMET notifies the manufacturer or maintainer of that component, assesses whether and how the vulnerability affects the configurations OMET places on the market, and coordinates remediation. The reporter is not expected to approach the supplier separately, although they remain free to do so.<\/p>\n<p>Where OMET identifies a vulnerability in an integrated component through its own analysis, the same notification applies.<\/p>\n<h2 id=\"8-public-disclosure\">8. Public disclosure<\/h2>\n<p>Once a security update or a documented mitigation is available, OMET publishes a security advisory describing the vulnerability, identifying the affected products and versions, stating the impact and severity, and giving the information users need to remediate.<\/p>\n<p>Publication may be deferred where disclosing before users have had a realistic opportunity to apply the update would increase rather than reduce risk. Machines installed in production cannot be updated at the speed of internet delivered software, and OMET weighs this in setting a disclosure date.<\/p>\n<p>Where the reporter consents, they are credited in the advisory.<\/p>\n<h2 id=\"9-what-omet-asks\">9. What OMET asks<\/h2>\n<p>Those reporting a vulnerability are asked to:<\/p>\n<ul>\n<li>allow OMET reasonable time to remediate before making details public, and agree a disclosure date rather than setting one unilaterally<\/li>\n<li>limit testing to systems they own or operate, or for which they hold the operator&#8217;s written authorisation<\/li>\n<li>avoid any action that could interrupt production, damage a machine, endanger persons, or affect the integrity or availability of data<\/li>\n<li>refrain from accessing, modifying or extracting data belonging to others, and stop and report immediately if such data is encountered<\/li>\n<li>refrain from social engineering, physical intrusion and denial of service testing<\/li>\n<\/ul>\n<p>Testing on a machine in production is not acceptable under any circumstances.<\/p>\n<h2 id=\"10-protection-for-good-faith-reporters\">10. Protection for good faith reporters<\/h2>\n<p>OMET will not pursue or support legal action against anyone who reports a vulnerability in good faith and acts in accordance with this policy. This applies even where the report turns out to be unfounded, provided the conduct described in section 9 has been observed.<\/p>\n<h2 id=\"11-regulatory-reporting\">11. Regulatory reporting<\/h2>\n<p>Where a vulnerability in an OMET product is actively exploited, OMET is required to notify ENISA and the relevant CSIRT under Regulation (EU) 2024\/2847. Such a notification may take place before public disclosure and independently of the timeline agreed with the reporter. Personal data of the reporter is not included in these notifications.<\/p>\n<h2 id=\"12-recognition\">12. Recognition<\/h2>\n<p>OMET does not operate a bug bounty programme and does not offer financial rewards for vulnerability reports. Recognition takes the form of credit in the published advisory, where the reporter wishes it.<\/p>\n<h2 id=\"13-personal-data\">13. Personal data<\/h2>\n<p>Personal data provided when submitting a report is processed solely for the purpose of handling the report and fulfilling the related legal obligations. See the privacy notice: <a href=\"https:\/\/www.iubenda.com\/privacy-policy\/23723745\">https:\/\/www.iubenda.com\/privacy-policy\/23723745<\/a>.<\/p>","protected":false},"excerpt":{"rendered":"<p>1. Purpose OMET designs and manufactures printing and converting machines. A modern machine is a connected system, and its security [&hellip;]<\/p>\n","protected":false},"author":1,"featured_media":0,"parent":0,"menu_order":0,"comment_status":"closed","ping_status":"closed","template":"","meta":{"ngg_post_thumbnail":0},"acf":[],"_links":{"self":[{"href":"https:\/\/omet.com\/en\/wp-json\/wp\/v2\/pages\/532"}],"collection":[{"href":"https:\/\/omet.com\/en\/wp-json\/wp\/v2\/pages"}],"about":[{"href":"https:\/\/omet.com\/en\/wp-json\/wp\/v2\/types\/page"}],"author":[{"embeddable":true,"href":"https:\/\/omet.com\/en\/wp-json\/wp\/v2\/users\/1"}],"replies":[{"embeddable":true,"href":"https:\/\/omet.com\/en\/wp-json\/wp\/v2\/comments?post=532"}],"version-history":[{"count":2,"href":"https:\/\/omet.com\/en\/wp-json\/wp\/v2\/pages\/532\/revisions"}],"predecessor-version":[{"id":534,"href":"https:\/\/omet.com\/en\/wp-json\/wp\/v2\/pages\/532\/revisions\/534"}],"wp:attachment":[{"href":"https:\/\/omet.com\/en\/wp-json\/wp\/v2\/media?parent=532"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}