Our Model for Incident Response
Ezurio builds cybersecurity and resiliency requirements into its hardware and software design controls from the outset. These design processes are part of Ezurio's Quality System and are audited and certified under ISO 9001.
Ezurio’s Product Security Incident Response Team monitors not just the experiences and concerns of our immediate customers, but Single Reporting Platforms (SRPs) such as Mitre (https://www.cve.org/), CISA (https://www.cisa.gov/) and in particular to the EU ENISA (https://www.enisa.europa.eu/). Part of how we accomplish this is with automated processes tied to the Software Bill-of-Materials (SBOM) for our software products. We check and cross reference the entirety of our software offerings against Known Vulnerabilities and Exposures (KVEs). This allows us to stay ahead of global research and provide the most up-to-date and secure instances of the many software packages we integrate into our own offerings.
In addition, Ezurio provides a mechanism to report any found vulnerabilities directly to Ezurio for evaluation. Customers can report known vulnerabilities to Ezurio at the following link: https://www.ezurio.com/security/report. When reported, the members of our PSIRT reviews and reports to those vulnerability platforms in compliance with the requirements of the CRA. That means disclosing an early warning within 12 hours, a detailed description within 72 hours, and a detailed report of mitigation after 14 days.
Not only does Ezurio report to these SRPs, but we’ll post them on our website as well, in the disclosures section of the Our Approach to Security page on Ezurio.com: https://www.ezurio.com/security/our-approach-to-security#disclosures. This allows all customers the ability to monitor these issues in real time, at each of the early warning, detailed description, and mitigation stages.