sig
Cybersecurity at SIG

Central point of contact for security‑relevant reports about SIG filling equipment

Cybersecurity is a top priority for SIG throughout the entire life cycle of our filling equipment. If you have found a potential vulnerability, the SIG PSIRT is here to receive, assess and resolve it with you — confidentially and professionally.

The SIG Product Security Incident Response Team

The SIG Product Security Incident Response Team (SIG PSIRT) is the central point of contact for handling and evaluating security‑relevant reports concerning our equipment. As a machine builder and system integrator, SIG designs, integrates and services complete filling lines — so cybersecurity is treated as a priority across the entire life cycle of a line, from engineering and commissioning through operation, service and secure decommissioning.

 

Potential vulnerabilities are analyzed according to clearly defined processes, coordinated internally with the responsible engineering teams, and classified according to their risk. Confirmed vulnerabilities are disclosed responsibly following the principle of Coordinated Vulnerability Disclosure (CVD). Affected users will be kept up to date with the latest developments and security advisories.

What is Coordinated Vulnerability Disclosure (CVD)?

CVD is the established industry standard under ISO/IEC 29147: a vulnerability is first reported confidentially to SIG, we assess and remediate it in coordination with the reporter, and details are not published until a fix or mitigation is available. This protects our customers’ production lines before information becomes public — unlike immediate full disclosure or keeping issues secret.

Our customer‑security promise

Your production lines must stay safe, available and resilient. SIG commits to take every credible security report seriously, to act with confidentiality and professionalism, and to keep you informed. We accept reports from anyone — regardless of customer status — and neither a non‑disclosure agreement (NDA) nor any other contract is required to work with us.

We listen

A monitored single point of contact and an online form, in English or German, open to everyone.

We coordinate

We triage, involve the right engineers and upstream suppliers, and keep you updated through the case.

We protect

We remediate based on risk, publish advisories, and inform users so lines stay protected.

Reporting a vulnerability

Reports about potential vulnerabilities or other security incidents connected to SIG products are welcome at any time and from anyone — security researchers, customers, system integrators, suppliers, universities, CERTs/CSIRTs, authorities and partners. SIG PSIRT aims to process every report with confidentiality and professionalism, together with the reporting party, following the principle of Coordinated Vulnerability Disclosure.

E‑mail (PSIRT)

Send an e-mail to the SIG Product Security Incident Response Team.

PSIRT@sig.biz

Online form

Use the “Report a vulnerability” form to submit a structured report.

Online form

In an emergency

If you have evidence that a vulnerability is being actively exploited in a SIG product, please state this clearly in the subject line (e.g. “ACTIVE EXPLOITATION”) so we can trigger our accelerated handling and regulatory reporting process without delay.

 

To help us reproduce and assess an issue quickly, please provide as much detail as possible. Many SIG lines fulfil important functions in food and beverage production, so we ask for cooperation in the coordinated disclosure of vulnerabilities and request that information is not disclosed prematurely.

  • Affected product and version/firmware if known.
  • Type and description of the vulnerability and its potential impact.
  • Step‑by‑step instructions to reproduce.
  • Any known exploitation, public references or CVE identifiers.
  • Your contact details and how you would like to be credited.

How we handle your report

  1. Report & acknowledgement
    We register your report, assign a tracking reference and confirm receipt.
  2. Triage & analysis
    We check relevance and completeness, involve the responsible teams, and assess validity, severity and affected products.
  3. Remediation
    Product teams develop a corrective or mitigating measure appropriate to the risk; we may share it with you for validation.
  4. Coordinated disclosure
    We agree a disclosure timing, coordinate with suppliers/CSIRTs where relevant, and publish a security advisory once a fix is available.
  5. Post‑release
    We monitor effectiveness, maintain the case and feed lessons learned back into development and integration.

Regulatory context

SIG operates its PSIRT in line with the EU Cyber Resilience Act, Regulation (EU) 2024. Where a vulnerability in a SIG equipment with digital elements is actively exploited, SIG additionally follows its statutory reporting obligations under CRA Article 14 (applicable from 11 September 2026), including early warning to the competent authorities via the coordinated reporting channel.