Reporting Security Risks and Vulnerabilities

The security of our products is important to us. If you identify a potential vulnerability, cybersecurity risk or cybersecurity incident in a be quiet! product with digital elements, you can report it to us using the security contact listed below. This page explains which information is helpful for our assessment and how we handle incoming reports.

What can be reported

You may report suspected or confirmed vulnerabilities, possible active exploitation of a vulnerability, as well as cybersecurity incidents that may affect the security of a be quiet! product with digital elements.

How to submit a report

Please send security reports by email to [email protected]. Use this address only for information about potential vulnerabilities, cybersecurity risks or cybersecurity incidents. For general support requests, please use the regular support channels on our website.

Our security.txt file is available at https://www.bequiet.com/.well-known/security.txt. It contains the security contact, the preferred languages for reports and a link to this policy.

Information that is helpful

  • affected product, model and software or firmware version
  • as precise a description as possible of the suspected vulnerability or cybersecurity incident
  • steps to reproduce the issue, technical evidence or log files, if available
  • an assessment of possible effects on confidentiality, integrity, availability or the security of the product with digital elements
  • information on whether a vulnerability is already being actively exploited or is publicly known
  • a contact option for follow-up questions, if you would like to receive a response

How we handle reports

After receiving a report, we first check whether sufficient information is available for an initial assessment. If necessary, we may ask for additional details. We then assess whether a product with digital elements is affected and whether there may be an actively exploited vulnerability or a severe incident having an impact on the security of the product with digital elements.

If corrective or mitigating measures are required, we plan and coordinate their implementation. These measures may include security updates, technical advisories, workarounds or other actions to reduce risk. To support coordinated vulnerability management, we recommend postponing public disclosure of information about reported vulnerabilities until the assessment has been completed and, where applicable, until corrective or mitigating measures have been made available.

Notifications to competent authorities

Where the legal requirements are met, we notify the competent authorities of actively exploited vulnerabilities or severe incidents having an impact on the security of a product with digital elements via the CRA Single Reporting Platform. We comply with the applicable legal timelines and requirements.

Communication and closure

We inform affected users in an appropriate manner if this is necessary to reduce risk or to implement corrective or mitigating measures. After completion, we document the assessment, the measures taken and, where relevant, the effectiveness of those measures.