Cybersecurity Center

HD Hyundai Power Transformers has established a cybersecurity framework based on international security standards to ensure the safe operation of its products and services.

Security Activity Notifier

Introduction to Security Activity Notifier

HD Hyundai Power Transformers systematically manages cybersecurity across all products and services based on international standards and global security frameworks.

Based on international standards

Based on international standards

Conducting regular audits

Conducting regular audits

Continuous Improvement

Continuous Improvement

Transparent disclosure

Transparent disclosure

Cybersecurity Management System

Secure SDLC

  • Incorporate security requirements from the design stage
  • Conduct static/dynamic analysis and security testing

Operations security

  • Security Monitoring
  • Manage vulnerabilities and operate the patch process

Audit and Evaluation Activities

SOC 2 Type II

Security Check

  • Penetration Test
  • Code security review

External audit

  • Regular audits by certification bodies
  • Response to security assessments requested by customers

Internal audit

  • Conduct internal information security audits at least once a year
  • Review of vulnerability management, access control, and log management

Continuous Improvement Activities

Security Risk Management

  • Analysis of new threats
  • Risk assessment and remediation measures

Security Training

  • Regular security training for employees
  • Operation of security training for developers

Vulnerability Management

  • Management of externally reported and internally discovered vulnerabilities
  • Provision of security notices and patches

Security Notice

Vulnerability Information Guide

HD Hyundai Power Transformers transparently discloses vulnerability information and provides guidance to enable customers to respond promptly.

  1. 1

    Vulnerability Management Principles

    HD Hyundai Power Transformers identifies and evaluates security vulnerabilities according to international standards and responds by prioritizing them based on severity.

  2. 2

    CVE Management Standards

    Identified vulnerabilities are managed according to CVE standards when necessary.

  3. 3

    Disclosure Principles

    Vulnerability information is disclosed at an appropriate time, considering customer impact and whether security updates can be provided.

  4. 4

    Customer Recommendations

    We recommend applying the latest security updates for safe operations.

  5. 5

    Vulnerability Reporting

    Security vulnerabilities can be reported through the Vulnerability Report page.

Report Vulnerabilities

Vulnerability Reporting Procedure

Reported vulnerabilities are systematically reviewed and processed according to the procedures below.

  1. Report Submission

    • After reviewing the submitted content, notification of receipt is sent via email
    • Additional materials for the reproduction environment may be requested if necessary
  2. Vulnerability Analysis

    • Cause analysis and testing following vulnerability verification
    • Additional inquiries may arise during the testing process
  3. Action Taken

    • Cause analysis → Vulnerability patch development → Application
    • CVE Code application/registration (if applicable)
    • Sharing action results via security announcement upon patch completion
  4. Closing

    • Response to the vulnerability report ends after action is completed
    • The reporter is notified separately of the final processing result

How to Report Vulnerabilities

To help maintain a safe security ecosystem, please report any vulnerabilities you discover using one of the methods below.

Email Report

Sender information can be verified via email only, without the need for separate registration.

Report Email Address

cybersecurity@hhiamerica.com

Vulnerability Disclosure Policy

HD Hyundai Power Transformers manages security vulnerabilities safely and systematically through Responsible Disclosure.

Principles of Responsible Disclosure

We disclose vulnerability information only after patches or mitigation measures have been established to prevent exploitation.

Protection of Researchers in Good Faith

We do not pursue legal liability for reports of security vulnerabilities made in good faith.

Vulnerability Handling Procedures

Received vulnerabilities undergo internal review, after which a severity assessment and remediation plan are established.

Scope and Method of Disclosure

Vulnerability information is disclosed via Security Advisories as necessary, in accordance with Common Vulnerabilities and Exposures (CVE) standards.

Communication with Reporters

The vulnerability handling process and results are communicated to the reporter to the extent possible.

Important Notes Before Reporting a Vulnerability

  • Actions that cause Denial of Service (DoS) are not permitted.
  • Access to customer data and unauthorized account creation are prohibited.
  • Please do not disclose discovered vulnerabilities to third parties.
  • Please reproduce vulnerabilities within the minimum necessary scope.

FAQ

We accept reports regarding the following technical security vulnerabilities:

[In-Scope]

  • Cross-Site Scripting (XSS)
  • Injection vulnerabilities (e.g., SQL Injection)
  • Authentication/Authorization bypass
  • Exposure of sensitive information (e.g., personal data, authentication credentials)
  • Security vulnerabilities caused by server or product misconfiguration
  • Remote Code Execution (RCE)
  • Command Injection
  • Improper file access (e.g., Path Traversal)
  • Weak encryption or authentication methods
  • Exposure of critical authentication credentials (e.g., hardcoded accounts, passwords, or encryption keys)
  • Insecure updates or vulnerabilities in the update verification process
  • Denial of Service (DoS) vulnerabilities resulting from flawed product handling
  • Other security vulnerabilities affecting the confidentiality, integrity, or availability of the product

[Out-of-Scope]

  • Spam or phishing email reports
  • Social engineering attempts
  • General physical intrusion or access attempts
  • General Denial of Service (DoS/DDoS) attacks themselves
  • Simple security events unrelated to product vulnerabilities
  • Simple re-reports of publicly known vulnerabilities without new information or impact on the product

If you are unsure whether an issue falls within the scope, please submit a report anyway, we will review it and provide guidance.