Working Together to Improve Product/System Security

At Invertek, the security, reliability, and resilience of our products are a key priority. As systems in general become increasingly connected, cybersecurity plays an important role in ensuring the continued safe and reliable operation of equipment and infrastructure.

To support this commitment, we have established a coordinated vulnerability disclosure process that enables customers, researchers, partners, and other stakeholders to responsibly report potential cybersecurity vulnerabilities affecting our products.

This process aligns with the objectives of the European Union Cyber Resilience Act (CRA), which aims to improve the cybersecurity of products with digital elements throughout their lifecycle.

Cybersecurity specialists monitoring systems

What is the Cyber Resilience Act (CRA)?

The Cyber Resilience Act is a European regulation designed to raise the cybersecurity standards of connected products sold within the European market.

The regulation introduces requirements for manufacturers to:

  • Design and develop products with cybersecurity in mind.
  • Manage cybersecurity risks throughout the product lifecycle.
  • Address identified vulnerabilities in a timely manner.
  • Provide security-related information to users and customers.
  • Establish mechanisms for receiving and handling vulnerability reports.

The CRA promotes a coordinated approach to cybersecurity, helping manufacturers, customers, security researchers and regulatory authorities work together.

Why does the Cyber Resilience Act (CRA) exist?

The CRA has been introduced to address a growing set of systemic weaknesses in the cybersecurity of connected products.

  • Increasing frequency and impact of cyberattacks.
  • Rapid growth of connected devices.
  • Widespread insecure products on the market.
  • Fragmented regulations across Europe.
  • Unclear accountability for cybersecurity.
  • Poor vulnerability management and support practices.
Cybersecurity specialist monitoring systems

Why Vulnerability Reporting Matters

Cybersecurity vulnerabilities can occasionally be discovered in any technology product, including variable frequency drives or systems containing variable frequency drives.

Responsible vulnerability reporting allows potential issues to be:

  • Evaluated by our Product Security Response Team.
  • Prioritised according to their security impact.
  • Addressed through corrective actions where appropriate.
  • Communicated transparently to affected stakeholders.

By reporting potential vulnerabilities through the appropriate channel, you help us maintain the security, integrity, and resilience of our products and services.

Our Commitment

When a vulnerability report is submitted, we are committed to:

  • Acknowledging receipt of the report.
  • Reviewing and validating the information provided.
  • Assessing potential impact and risk.
  • Working to develop appropriate remediation measures where necessary.
  • Maintaining confidential communication with the reporter throughout the investigation process.

We value the contributions of customers, partners, and security researchers who help identify opportunities to improve product security.

Responsible Disclosure Principles

We encourage responsible and coordinated disclosure practices.

When submitting a potential vulnerability, we ask that you:

  • Provide sufficient technical information to allow investigation.
  • Avoid public disclosure until the reported issue has been assessed and addressed.
  • Refrain from activities that could negatively impact customers, systems, services, or data.
  • Act in good faith and in accordance with applicable laws and regulations.

Our objective is to work collaboratively to understand, assess, and resolve legitimate security concerns.

Engineers examining connected drive equipment
  • SGS ISO 9001
  • SGS ISO 14001

GBManufactured in the UK

Invertek’s products are designed and manufactured in the UK to the quality and environmental management system principals of ISO 9001 and ISO 14001:2015

About Invertek Drives
  • CE Logo
  • CULUS Logo
  • RCM Mark
  • UKCA Logo
  • TUV Logo
  • TUV Approved
  • ECA ETL Logo
  • RohS Logo