Looking for GESTRA products and services?

Report a cybersecurity vulnerability

Our commitment

This page allows customers and other stakeholders to report potential security vulnerabilities affecting GESTRA products, software, firmware, connected solutions and associated digital services. GESTRA is committed to supporting the security and resilience of its products throughout their lifecycle. We welcome the responsible reporting of potential cybersecurity vulnerabilities affecting GESTRA products, software, firmware or associated digital services.

Cyber Resilience Act (CRA) and Product Security

The Cyber Resilience Act (CRA) is European legislation intended to strengthen the cybersecurity of products with digital elements and improve the management of cybersecurity vulnerabilities throughout a product's lifecycle. We encourage responsible disclosure and welcome information that helps us assess, manage and, where appropriate, address potential product security concerns.

How to report a vulnerability

If you believe you have identified a potential product security vulnerability, please submit a report using one of the following methods:

Email: productsecurity@uk.spiraxsarco.com

or

Complete the form opposite. 

What do you need to send us?

Please provide where available:

  • Name
  • Organisation (optional)
  • Email
  • Country
  • Report Type: (Product Vulnerability / Security Concern / Third-Party Component / Research Finding / Other)
  • Product name and model
  • Software or firmware version
  • Description of the issue
  • Potential impact
  • Supporting evidence
  • Contact details for follow-up

What happens to my submission?

 Step:  Description:
1  Receive  You submit: Your report through our approved reporting channel. We: Receive and record your submission.
2  Review  We: Review the information provided and carry out an initial validation.
3  Assess  We: Determine whether an GESTRA product or service is affected and assess the potential severity and impact
4  Respond   We: Investigate the issue and identify appropriate mitigation or corrective action where required
5  Communicate  You can expect: Relevant updates or customer communication where appropriate.
6  Close  We: Record the outcome, retain relevant evidence and close the submission.