Central point of contact for security‑relevant reports about SIG filling equipment
The SIG Product Security Incident Response Team
The SIG Product Security Incident Response Team (SIG PSIRT) is the central point of contact for handling and evaluating security‑relevant reports concerning our equipment. As a machine builder and system integrator, SIG designs, integrates and services complete filling lines — so cybersecurity is treated as a priority across the entire life cycle of a line, from engineering and commissioning through operation, service and secure decommissioning.
Potential vulnerabilities are analyzed according to clearly defined processes, coordinated internally with the responsible engineering teams, and classified according to their risk. Confirmed vulnerabilities are disclosed responsibly following the principle of Coordinated Vulnerability Disclosure (CVD). Affected users will be kept up to date with the latest developments and security advisories.
What is Coordinated Vulnerability Disclosure (CVD)?
CVD is the established industry standard under ISO/IEC 29147: a vulnerability is first reported confidentially to SIG, we assess and remediate it in coordination with the reporter, and details are not published until a fix or mitigation is available. This protects our customers’ production lines before information becomes public — unlike immediate full disclosure or keeping issues secret.
Our customer‑security promise

We listen
A monitored single point of contact and an online form, in English or German, open to everyone.

We coordinate
We triage, involve the right engineers and upstream suppliers, and keep you updated through the case.

We protect
We remediate based on risk, publish advisories, and inform users so lines stay protected.
Reporting a vulnerability
E‑mail (PSIRT)
Send an e-mail to the SIG Product Security Incident Response Team.
Online form
Use the “Report a vulnerability” form to submit a structured report.
In an emergency
If you have evidence that a vulnerability is being actively exploited in a SIG product, please state this clearly in the subject line (e.g. “ACTIVE EXPLOITATION”) so we can trigger our accelerated handling and regulatory reporting process without delay.
To help us reproduce and assess an issue quickly, please provide as much detail as possible. Many SIG lines fulfil important functions in food and beverage production, so we ask for cooperation in the coordinated disclosure of vulnerabilities and request that information is not disclosed prematurely.
- Affected product and version/firmware if known.
- Type and description of the vulnerability and its potential impact.
- Step‑by‑step instructions to reproduce.
- Any known exploitation, public references or CVE identifiers.
- Your contact details and how you would like to be credited.
How we handle your report
- Report & acknowledgement
We register your report, assign a tracking reference and confirm receipt. - Triage & analysis
We check relevance and completeness, involve the responsible teams, and assess validity, severity and affected products. - Remediation
Product teams develop a corrective or mitigating measure appropriate to the risk; we may share it with you for validation. - Coordinated disclosure
We agree a disclosure timing, coordinate with suppliers/CSIRTs where relevant, and publish a security advisory once a fix is available. - Post‑release
We monitor effectiveness, maintain the case and feed lessons learned back into development and integration.
Regulatory context
SIG operates its PSIRT in line with the EU Cyber Resilience Act, Regulation (EU) 2024. Where a vulnerability in a SIG equipment with digital elements is actively exploited, SIG additionally follows its statutory reporting obligations under CRA Article 14 (applicable from 11 September 2026), including early warning to the competent authorities via the coordinated reporting channel.