Cyber Resilience Act
Our commitment to cyber security
The security of digital products and solutions is a priority for ITALTEL.
For this reason, ITALTEL has adopted a dedicated process for managing cyber vulnerabilities, in line with Regulation (EU) 2024/2847 – the Cyber Resilience Act (CRA).
What is the Cyber Resilience Act?
The Cyber Resilience Act (CRA) is the European Union regulation that establishes a common framework of cybersecurity requirements for products containing digital components. The aim of the regulation is to improve the security of digital products throughout their entire life cycle, from design to end-of-life.
The regulation requires manufacturers to:
- develop secure products in accordance with the principles of ‘security by design’ and ‘security by default’;
- monitor and manage security vulnerabilities;
- provide updates and patches where necessary;
- put in place processes to receive and handle reports of vulnerabilities from users, customers, researchers and other stakeholders;
- notify the competent authorities of certain actively exploited vulnerabilities and serious security incidents.
How do you report a vulnerability?
A manufacturer may become aware of vulnerabilities and security incidents through a variety of activities and channels. However, Annex I, Part II of the CRA requires the manufacturer to have, amongst other things, a single point of contact for receiving reports of vulnerabilities, to establish and enforce a coordinated vulnerability disclosure policy, and to take measures to facilitate the sharing of information on potential vulnerabilities.
Italtel invites researchers, customers, partners, suppliers and other interested parties to report any vulnerabilities or security issues encountered in products containing digital components developed by ITALTEL or marketed under the ITALTEL brand, including those relating to third-party components integrated into such products.
To report any vulnerabilities discovered, Italtel therefore provides customers, partners and other third parties with a dedicated public contact point.
By clicking on the following link ‘Report a vulnerability’, you will be asked to complete a form containing your contact details and a brief description of the issue.
Your report will be handled by the relevant internal Italtel team responsible for managing reports, who will contact you via a dedicated email address within 3 working days. The email will set out the procedures to follow for the secure exchange of further information, in order to protect its confidentiality and ensure that it is accessible only to authorised personnel.
All reports received are examined and handled through a dedicated process, designed to ensure a prompt response and the appropriate handling of any vulnerabilities identified.
Safe Harbor
Italtel encourages the responsible reporting of security vulnerabilities and recognises the contribution made by the research community to the protection of its products, services and IT systems.
Provided that a report is made in good faith, in accordance with the guidelines set out in this Policy and without intentionally causing damage, service disruption or unauthorised access to data, Italtel will not take legal action against the reporter for activities reasonably necessary to identify and report the vulnerability.
Reporters are required to act in accordance with applicable laws and regulations. Should you intend to carry out activities that may not be expressly covered by this policy, you are advised to contact Italtel in advance to seek clarification and agree on the most appropriate course of action.
Italtel will assess each situation on a case-by-case basis, taking into account the reporter’s good faith, compliance with the established rules and the timeliness of communication with the company. A proactive and transparent dialogue with Italtel will be considered a key factor in the assessment of the activities carried out.
Privacy Notice
Privacy Notice on the Processing of Personal Data
In accordance with Articles 13 and 14 of Regulation (EU) 2016/679 (“GDPR”), ITALTEL S.p.A. hereby informs you that the personal data provided via this form will be processed in accordance with the principles of lawfulness, fairness, transparency, data minimisation and confidentiality.
1. Data controller
The Data Controller is ITALTEL S.p.A., with its registered office at Via Caldera 21, Milan, and can be contacted at the following email address: privacy@italtel.com.
2. Purposes of processing
The personal data provided will be processed exclusively for the following purposes:
- to receive, record, analyse and manage reports of vulnerabilities relating to products, systems and applications attributable to ITALTEL;
- to communicate with the reporter in order to request clarifications or further information, or to provide updates regarding the report;
- to prevent, detect, analyse and mitigate vulnerabilities and cyber security incidents;
- implement the necessary corrective and security measures;
- comply with applicable regulatory obligations regarding cybersecurity, network and information system security, personal data protection and cooperation with the competent authorities.
3. Legal basis for processing
Processing is carried out in accordance with:
- Article 6(1)(c) of the GDPR, for the fulfilment of legal obligations to which ITALTEL is subject;
- Article 6(1)(f) of the GDPR, for the pursuit of ITALTEL’s legitimate interest in ensuring the security of its products, services, systems, infrastructure and data, as well as in effectively managing cyber vulnerabilities and threats.
The provision of data marked as mandatory is necessary to enable the handling of the report.
Google reCAPTCHA
Some forms may use Google reCAPTCHA as a technical security measure to prevent spam, automated submissions, fraud, abuse and other forms of misuse. In connection with the service, technical data relating to the device, browser, network and interaction with the form may be processed, and cookies or similar technologies necessary for risk assessment may be used.
The processing is carried out on the basis of ITALTEL’s legitimate interest pursuant to Article 6(1)(f) of the GDPR, aimed at ensuring the security of the services and preventing fraudulent or abusive activities. The use of reCAPTCHA for these purposes is not subject to obtaining the user’s specific consent.
4. Recipients of the data
The data may only be processed by authorised ITALTEL staff involved in handling the report (such as the Cyber Security, PSIRT, IT, Legal & Compliance departments and other relevant departments).
The data may also be disclosed, within the limits of the purposes set out above, to:
- service providers and specialist consultants who assist ITALTEL in managing vulnerabilities and security incidents;
- companies within the ITALTEL Group that may be involved in handling the report;
- public authorities, cybersecurity authorities, CSIRTs, judicial authorities or other bodies to whom disclosure is required by law or necessary to comply with regulatory obligations.
5. Data retention
Personal data will be retained for the period strictly necessary to manage the report, implement any corrective measures and comply with applicable regulatory obligations. Once this period has elapsed, the data will be erased or anonymised, unless further retention is required by law or necessary to protect the Data Controller’s rights.
6. Rights of the data subject
The data subject may, in the cases provided for by applicable legislation, exercise the rights of access, rectification, erasure, restriction of processing, objection and data portability, in accordance with Articles 15–22 of the GDPR.
The data subject also has the right to lodge a complaint with the Data Protection Authority.
To exercise your rights or for any enquiry regarding the processing of personal data, please contact the Data Protection Officer (DPO) at dpo@italtel.com.
7. Recommendation for the reporter
The reporter is advised not to include unnecessary personal data or confidential information relating to third parties in the form, except where strictly necessary to describe the vulnerability or the reported incident.