Security

The security of our products, systems and online services is a high priority for Big Dutchman. If you discover a potential security vulnerability, this page provides all the information you need on how to report it to us and how we handle such reports.

1. Scope

Report a security vulnerability

Security is an integral part of how Big Dutchman’s designs, develops and maintains its products. Even with careful engineering and testing, vulnerabilities can never be ruled out entirely - whether in our own products and firmware, in third-party and open-source components we integrate, or in our websites and online services. When vulnerabilities are found, what matters is that they reach us quickly and can be fixed in a coordinated way.

If you believe you have discovered a security vulnerability in a Big Dutchman’s product, in one of its software components, or in our online infrastructure, we encourage you to report it to us. This page describes how to reach our product security team, what information helps us investigate, and what you can expect from us in return. This process and the commitments on this page apply to everyone who reports in good faith: security researchers, customers, partners, coordinating bodies and component suppliers alike.

Please note: this channel is reserved for security vulnerabilities. For questions about product functionality, quality, warranty or general support, please contact our customer service at Contact - you will get a faster answer there, and it keeps this channel free for security reports.

2. How to report

How to report a vulnerability

You can reach our product security team through the following channel, in English or German:

E-mail: customerhelpdesk@bigdutchman.com

3. What to include in a report

What a good report contains

The more precisely we can reproduce an issue, the faster we can confirm and fix it. Where applicable, a report should include:

  • The affected product, device model, software or service, including the exact version or firmware level.
  • A description of the vulnerability and its security impact as you assess it.
  • Any configuration, deployment conditions, privileges or authentication needed to trigger the issue.
  • Step-by-step instructions that allow us to reproduce the issue independently.
  • Supporting material where available: proof-of-concept, logs, screenshots or network captures. For findings produced by automated tools, please include evidence of actual exploitability.
  • Your assessment of the potential consequences - which systems, data or users could be affected.
  • If you plan to publish the finding, your intended timeline, so that we can coordinate disclosure with you.

4. Coordinated disclosure

We follow the principle of coordinated vulnerability disclosure. Our aim is to remediate confirmed vulnerabilities and enable public disclosure within 90 days of the report. Where remediation is demonstrably more complex - for example when a fix must be validated for products deployed in industrial environments, or when third-party components are involved - this period can be extended by up to a further 90 days in coordination with the reporter.

Once a fix or mitigation is available, we publish a security advisory describing the vulnerability, the affected products and versions, its severity and impact, and the remediation or mitigation steps, and we credit the reporter if desired (see below). Where appropriate we request a CVE identifier for the vulnerability. We may involve the responsible coordinating body - in Germany, CERT-Bund at the Federal Office for Information Security (BSI) - in the coordination of a disclosure.

5. Rules of engagement (good-faith research)

To keep security research safe for everyone - including the operators of systems built on our products - we ask you to observe the following when investigating potential vulnerabilities:

  • Only test against your own devices and installations or in a lab environment. Never test against productive systems of our customers or against live industrial installations: our products are used in operational environments where interference can have physical consequences.
  • Do not go further than necessary to demonstrate the vulnerability. Do not read, modify, delete or exfiltrate data that is not your own; if you inadvertently access third-party or personal data, stop immediately and include this in your report.
  • Do not degrade the availability of our services or products (no denial-of-service testing), and do not use social engineering, phishing, spam or physical attacks against Big Dutchman’s employees, customers or partners.
  • Do not publish details of the vulnerability before a coordinated disclosure date has been agreed.

Provided you comply with these rules and act without criminal intent, Big Dutchman’s will not pursue legal action against you in connection with your research and report. This commitment cannot cover actions of third parties or conduct outside these rules.

6. Out of scope

What is out of scope

The following are generally outside the scope of this process:

  • Vulnerabilities that are already publicly known, have a CVE assigned, or are already fixed - unless your report shows a new impact, significant new information, or that the fix is incomplete.
  • Products, services or versions that have reached end of support, or issues that are resolved in the supported version we recommend customers to use.
  • Findings without a realistic security impact, such as purely informational results, missing best-practice hardening without an exploitable weakness, or raw output of automated scanners without evidence of exploitability.
  • Issues that consist of social engineering or phishing rather than a technical vulnerability in a Big Dutchman’s product or service.
  • Vulnerabilities in third-party products or services that Big Dutchman’s does not develop, maintain or operate. Please report these to the respective vendor; if a third-party component inside one of our products is affected, do report it to us - we will pass it on to the component manufacturer as required.

7. Recognition

We value the work of security researchers and are happy to publicly acknowledge reporters who wish to be named once the vulnerability has been fixed and disclosed. Big Dutchman’s does not operate a bug bounty program; the submission of a report does not create an entitlement to monetary reward or other compensation.

8. Data protection notice

Personal data you provide with your report (such as your name and e-mail address) is processed solely for handling the vulnerability report and coordinating its disclosure. Details, including your rights as a data subject, can be found in our privacy policy.
 

My account

myBigDutchman

The full overview: your orders and invoices at a glance! Including a handy user management.

Sign in

Sign in with your credentials to benefit from your account and all advantages.

Open Sign In

No account yet? Register now!

Create your personal customer account in the myBigDutchman customer portal.

Create account