At our company, we regard "product security" as one of the most important priorities for products that are increasingly networked and software-driven, and we are working to improve it so that customers can use our products with confidence. Led by a company-wide specialist organization, we establish development guidelines with a strong security focus, build and periodically review our framework, and work across the group to deliver products that are safe, trustworthy, and secure.
1. Continuous Information Gathering and Internal Coordination
We continuously collect information about threats and vulnerabilities related to our products and share that information with relevant departments. We reflect these insights in internal activities and strive to improve our product security measures.
2. Security-Conscious Product Development
During the development phase, we identify the assets and functions that must be protected and assess possible attack scenarios. Based on those assessments, we design and implement appropriate security measures as the situation requires.
3. Post-Release Response and Customer Collaboration
If a vulnerability is discovered, we promptly assess its impact and consider and implement corrective measures such as updates. We also take steps to prevent recurrence when necessary and work closely with customers throughout the process.
4. Providing Information for Safe Operation
We make efforts to provide comprehensive information so that customers can operate our products safely and with peace of mind.
5. Alignment with Regulations and Standards
We monitor laws, regulations, and guidelines in each region (for example, developments related to the European Cyber Resilience Act) and endeavor to ensure appropriate alignment for the products to which they apply. While referring to commonly used frameworks in industrial sectors, we aim to enhance the practical effectiveness of our product security.
Secure Use of Our Products
This document outlines the basic security measures that customers are required to follow when using KEYENCE products.
For specific measures for each item, please also check the latest security guidelines issued by relevant countries and organisations then take appropriate action.
For detailed precautions for each product, please refer to the user's manual.
1. Network Environment
Please connect to and use the product on a secure network.
Please use the product in an environment that is physically and logically separated from external networks (such as the internet or networks at other sites).
2. Access Control and Password Settings
Please set and manage access rights and passwords appropriately.
3. Management of the Installation Environment
Please manage access to the product appropriately so that only trusted individuals can access it.
4. Software Updates
Please perform updates regularly to keep the software up to date.
Please use only genuine software provided by KEYENCE.
5. Data Protection
Regarding the handling of product data, please take appropriate protective measures according to your operating environment.
6. Management of Removable Media
Please appropriately manage the import and export of data via removable media such as USB flash drives.
Please implement security measures, such as virus scans, on removable media.
7. Data Protection at Product Disposal
When disposing of the product, please take measures such as data initialisation/deletion or physical destruction to prevent unauthorised use of any data remaining on the device.
KEYENCE Product Vulnerability Reporting Contact
KEYENCE PSIRT accepts reports of vulnerabilities regarding our products. We will work with relevant departments to confirm and evaluate reported vulnerabilities, and do our best to promptly implement appropriate countermeasures.
In addition, based on the concept of coordinated vulnerability disclosure, we handle vulnerability information appropriately, and as necessary, report to relevant authorities, notify affected customers, and provide information regarding fix information and security updates. Information regarding fixed vulnerabilities and related security updates will be published or notified as necessary.
Please report information regarding vulnerabilities using the form below.