HD Hyundai Electric
Cybersecurity Center

HD Hyundai Electric has established a cybersecurity framework based on international security standards to ensure the safe operation of its products and services. We have obtained global certifications including ISO/IEC 27001 and manage security risks primarily through the CISO (Chief Information Security Officer) organization.

More

Vulnerability Reporting Procedure

Reported vulnerabilities are systematically reviewed and processed according to the procedures below.

  • Report Submission

    • After reviewing the submitted content, notification of receipt is sent via email
    • Additional materials for the reproduction environment may be requested if necessary
  • Breach Analysis

    • Cause analysis and testing following vulnerability verification
    • Additional inquiries may arise during the testing process
  • Action Taken

    • Cause analysis → Vulnerability patch development → Application
    • CVE Code application/registration (if applicable)
    • Sharing action results via security announcement upon patch completion
  • Closing

    • Response to the vulnerability report ends after action is completed
    • The reporter is notified separately of the final processing result

How to Report Vulnerabilities

To help maintain a safe security ecosystem, please report any vulnerabilities you discover using one of the methods below.

Vulnerability Disclosure Policy

HD Hyundai Electric manages security vulnerabilities safely and systematically through Responsible Disclosure.

  • Principles of Responsible Disclosure

    We disclose vulnerability information only after patches or mitigation measures have been established to prevent exploitation.

  • Protection of Researchers in Good Faith

    We do not pursue legal liability for reports of security vulnerabilities made in good faith.

  • Vulnerability Handling Procedures

    Received vulnerabilities undergo internal review, after which a severity assessment and remediation plan are established.

  • Scope and Method of Disclosure

    Vulnerability information is disclosed via Security Advisories as necessary, in accordance with Common Vulnerabilities and Exposures (CVE) standards.

  • Communication with Whistleblowers

    The vulnerability handling process and results are communicated to the whistleblower to the extent possible.

Important Notes Before Reporting a Vulnerability

  • Actions that cause Denial of Service (DoS) are not permitted.
  • Access to customer data and unauthorized account creation are prohibited.
  • Please do not disclose discovered vulnerabilities to third parties.
  • Please reproduce vulnerabilities within the minimum necessary scope.