News & Articles Articles

PSIRT: Clear processes for product security

EvelinJakobi 13 August 2026 7 min. read
5 views 0 comments LoadingSave
Articles

PSIRT: Clear processes for product security

Product Security Incident Response Team
Product Security Incident Response Team

Cybersecurity is part of daily responsibilities when machines, plants, controllers, apps and IT systems are interconnected. The more open and networked automation becomes, the more important robust processes, clear responsibilities and transparent information are. This is exactly where our Product Security Incident Response Team (PSIRT) comes in.

The PSIRT centralizes activities related to potential vulnerabilities in products, solutions and services. It evaluates reports, coordinates follow-up actions and ensures transparent communication.

What is a PSIRT?

A PSIRT is a specialized team dedicated to addressing security vulnerabilities in products. It receives reports, analyzes them technically, assesses the risk and, if necessary, coordinates the publication of security advisories.

This involves more than just technical analysis. A good PSIRT combines product knowledge, security expertise, structured communication and responsible collaboration with external security researchers, partners and organizations. The goal is to identify potential vulnerabilities early on, classify them in a transparent manner and provide appropriate mitigation or remediation measures.

This structured approach is particularly important for industrial applications. This is because what matters here are not only individual software functions, but also availability, integrity, traceability and secure operation over long lifecycles.

PSIRT by Phoenix Contact

More freedom. More responsibility.

In modern automation systems, IT and OT are increasingly converging. Controllers communicate with engineering tools, cloud systems, edge applications, visualizations and apps. This creates new opportunities but also increases the demands on cybersecurity.

Open platforms, such as PLCnext Technology, deliberately offer developers and machine builders greater freedom: apps, open source, high-level languages, classic IEC 61131 programming, cloud connectivity and modern software development can all be combined. This openness is a major advantage, but at the same time requires a professional and reliable approach to security throughout the entire lifecycle.

And that’s where our PSIRT comes into play. It ensures that reported vulnerabilities are not considered in isolation but are embedded in an established process. This includes analysis, assessment, prioritization, communication and technical implementation. In this way, individual vulnerability reports give rise to a continuous improvement process.

Security is more than a feature

Security is also an important part of the PLCnext Technology Ecosystem. The PLCnext Store gives users access to apps and software components that can be used in industrial applications. This makes trusted sources, secure distribution and transparent update processes especially important.

Technical mechanisms such as signed apps, integrity checks, secure distribution, role and permission management and monitoring functions support the responsible use of software. Together, these elements help create a reliable framework for open and secure automation.

A few security basics go a long way

To ensure the secure operation of PLCnext Control and apps from the PLCnext Store, we generally recommend the following:

  • Keep firmware and software up to date
  • Install apps only from trusted and verified sources, like the PLCnext Store
  • Check the integrity of downloads where checksums are provided
  • Limit access to engineering and management interfaces
  • Use strong authentication and secure credentials
  • Configure firewall rules according to the application
  • Monitor security-related events, for example via logging or Syslog
  • Disable functions that are not required during operation
  • Review security advisories regularly or subscribe to the PSIRT newsletter

These measures are not a one-time task, but rather part of professional security management in an industrial environment.

Security is never a one-time task

Cybersecurity in industry is an ongoing process. New insights, evolving threat landscapes and increasing connectivity make it necessary to regularly assess and further develop systems.

Our PSIRT provides an important foundation for this. It brings structure to the handling of potential vulnerabilities, provides transparent information and supports customers with clear recommendations for action. In combination with PLCnext Technology, the PLCnext Store and the platform’s security mechanisms, this creates a robust framework for open, flexible and secure automation.

For more information about Phoenix Contact’s Product Security Incident Response Team, visit the official website: PSIRT | Phoenix Contact

Evelin Jakobi
Evelin Jakobi
5 views 0 comments LoadingSave

Discussion

Please login/register to comment

Login/Register

Leave a Reply

Newsletter
Never miss a new article
Sign up for the newsletter
Never miss news about PLCnext Technology
Get interesting content via newsletter four times a year
Receive exclusive information before all other users