HD Hyundai Electric
Cybersecurity Center

HD Hyundai Electric has established a cybersecurity framework based on international security standards
to ensure the safe operation of its products and services. We have obtained global certifications including
ISO/IEC 27001, and manage security risks primarily through the CISO (Chief Information Security Officer)
organization.

  • Cybersecurity Center
  • Security Activity Notifier
  • Security Notice
  • Report Vulnerabilities

Vulnerability Reporting Procedure

Reported vulnerabilities are systematically reviewed and processed according to the procedures below.

  • Report Submission

    • After reviewing the submitted content, notification of receipt is sent via email
    • Additional materials for the reproduction environment may be requested if necessary
  • Breach Analysis

    • Cause analysis and testing following vulnerability verification
    • Additional inquiries may arise during the testing process
  • Action Taken

    • Cause analysis → Vulnerability patch development → Application
    • CVE Code application/registration (if applicable)
    • Sharing action results via security announcement upon patch completion
  • Closing

    • Response to the vulnerability report ends after action is completed
    • The reporter is notified separately of the final processing result

How to Report Vulnerabilities

To help maintain a safe security ecosystem, please report any vulnerabilities you discover using one of the methods below.

Vulnerability Disclosure Policy

HD Hyundai Electric manages security vulnerabilities safely and systematically through Responsible Disclosure.

  • Principles of Responsible Disclosure

    We disclose vulnerability information only after patches or mitigation measures have been established to prevent exploitation.

  • Protection of Researchers in Good Faith

    We do not pursue legal liability for reports of security vulnerabilities made in good faith.

  • Vulnerability Handling Procedures

    Received vulnerabilities undergo internal review, after which a severity assessment and remediation plan are established.

  • Scope and Method of Disclosure

    Vulnerability information is disclosed via Security Advisories as necessary, in accordance with Common Vulnerabilities and Exposures (CVE) standards.

  • Communication with Whistleblowers

    The vulnerability handling process and results are communicated to the whistleblower to the extent possible.

Important Notes Before Reporting a Vulnerability

  • Actions that cause Denial of Service (DoS) are not permitted.
  • Access to customer data and unauthorized account creation are prohibited.
  • Please do not disclose discovered vulnerabilities to third parties.
  • Please reproduce vulnerabilities within the minimum necessary scope.