Cybersecurity response

CKD NIKKI DENSO CO., LTD. monitors prevalent security threats to protect our products from cyberattacks. We develop and provide cyber-secure products that our customers can use safely and with peace of mind.

Product security policy

CKD NIKKI DENSO proactively collects information about vulnerabilities in products and services and adequately responds to those vulnerabilities to ensure our customers can use our products with peace of mind.

In accordance with the principles of Coordinated Vulnerability Disclosure, CKD NIKKI DENSO works together with external reporters, customers and relevant organizations to improve security.

Vulnerability disclosure policy

To ensure our customers can use our products with peace of mind, we handle the information about the vulnerabilities identified internally and externally, as follows.

Reception of vulnerability information

If you find vulnerabilities in our products, please contact our contact point for vulnerability reporting.

We will notify you of the review results of the reported product vulnerability as soon as they are available. If you contact us on our holidays, please be aware that it may take longer than usual for us to respond.

The information you provide (including the content of your inquiry, our response, and other information) may be forwarded to relevant departments within CKD NIKKI DENSO and recorded for the purpose of responding to your inquiry, and may also be used for providing information concerning vulnerabilities in CKD NIKKI DENSO products.

Vulnerability investigation and remediation

If a vulnerability is reported, the technology department in charge of the related product will examine its impact and severity, among others, and consider appropriate remediation action in conjunction with the relevant coordinating organization as necessary. We will contact you with details as soon as our security update plan is finalized.

Disclosure of vulnerability information

As soon as the remediation for the reported vulnerability is finalized, we will coordinate with the stakeholders and disclose the vulnerability information on our website.

When making such a disclosure, we will provide customers with the information they need to address the vulnerability, including the affected products, the impact and severity of the vulnerability, remediation methods, security patches, and workarounds.
The disclosed vulnerability information will be posted on the “Vulnerability information” page of our website.

Request for vulnerability reporters

Please refrain from making your vulnerability information public before our investigation and remediation process is complete, so as to minimize the impact of the vulnerability on our customers and society at large.
We respond to vulnerabilities sincerely and quickly and stay committed to enhancing the security of our products and services.