IT Security and Incident Reporting

SENECA S.r.l. attaches the utmost importance to information security, data protection, the continuity of its digital services, and the security of its products with digital elements.

SENECA adopts technical and organizational measures as well as cybersecurity management processes in compliance with applicable European and national regulations, including:

  • Regulation (EU) 2016/679 – GDPR;
  • Directive (EU) 2022/2555 – NIS2 and relevant national transposition legislation;
  • Regulation (EU) 2024/2847 – Cyber Resilience Act (CRA);
  • ISO/IEC 27001 standards and other applicable cybersecurity frameworks and standards;
  • Industrial cybersecurity standards, where applicable.

 

Incident and Vulnerability Reporting

SENECA provides a single point of contact for reporting cybersecurity incidents and potential vulnerabilities:

security@seneca.it

The address can be used by customers, partners, distributors, integrators, suppliers, security researchers, and other parties to report:

  • Incidents or potential breaches regarding SENECA's information systems, digital services, or data;
  • Vulnerabilities or security issues regarding SENECA products with digital elements;
  • Vulnerabilities related to firmware, embedded software, applications, web interfaces, APIs, or digital services associated with SENECA products;
  • Vulnerabilities related to third-party software components integrated into SENECA products;
  • Evidence or suspicion of active vulnerability exploitation;
  • Incidents that may impact the security of a SENECA product.

The same address is used as the entry point for reports regarding both company system/service security and product security.

Reports are subsequently classified and routed to the applicable internal process.

 

Incidents Related to SENECA Systems and Services

Reports concerning SENECA's information systems, digital services, infrastructure, or data are managed by the IT Security Team according to internal Incident Management procedures.

When applicable, SENECA fulfills the notification obligations under the NIS2 regulations toward competent authorities.

 

Vulnerabilities and Incidents Related to SENECA Products

Reports concerning SENECA products with digital elements are managed according to the internal Product Security and Vulnerability Management process.

SENECA evaluates received vulnerabilities, verifies their impact on affected products, and, when necessary, develops mitigation measures, firmware or software updates, and other corrective measures.

In compliance with the Cyber Resilience Act, SENECA maintains a process for coordinated vulnerability management and for assessing actively exploited vulnerabilities and severe incidents impacting product security.

 

Information to Include in the Report

To enable a prompt evaluation, it is recommended to specify, where available:

  • Affected product and model;
  • Product code;
  • Hardware version;
  • Firmware or software version;
  • Detailed description of the vulnerability or incident;
  • Procedure or conditions required to reproduce the issue;
  • Possible impact on security;
  • Any logs or other technical evidence;
  • Any Proof of Concept;
  • Indication of any already observed exploitation of the vulnerability;
  • Contact details of the reporter for further clarifications.

It is recommended not to send passwords, personal credentials, or other information unnecessary for assessing the vulnerability.

 

Coordinated Vulnerability Disclosure

SENECA promotes a Coordinated Vulnerability Disclosure approach.

Received reports are analyzed by competent technical personnel and, when the vulnerability is confirmed, SENECA coordinates the necessary activities to:

  • Evaluate its severity and impact;
  • Identify affected products and versions;
  • Identify temporary mitigation measures;
  • Develop and validate updates or fixes;
  • Inform affected users when necessary;
  • Publish any Security Advisories.

SENECA asks researchers and reporters to refrain from public disclosure of technical details that could facilitate vulnerability exploitation before adequate mitigation or corrective measures have been made available.

SENECA undertakes to maintain, where possible, a communication channel with the reporter during analysis and remediation activities.

 

Notifications Under the Cyber Resilience Act

Starting from September 11, 2026, when conditions under Article 14 of Regulation (EU) 2024/2847 – Cyber Resilience Act are met, SENECA fulfills notification obligations regarding:

  • Actively exploited vulnerabilities contained in products with digital elements;
  • Severe incidents impacting the security of products with digital elements.

Mandatory notifications are submitted via the Single Reporting Platform (SRP) managed by ENISA, according to the terms and timelines specified by applicable law.

The Single Reporting Platform is the channel used by SENECA toward ENISA and competent CSIRTs and does not replace the address security@seneca.it, which remains the public contact point for customers, users, partners, and researchers.

 

Report Management

Received reports are:

  • Logged and analyzed confidentially;
  • Classified based on type and impact;
  • Routed to competent technical personnel;
  • Evaluated for potential applicable legal obligations;
  • Managed according to criteria of timeliness, proportionality, and confidentiality.

SENECA may contact the reporter to request further information necessary for the technical evaluation.

Vulnerability information is shared internally exclusively with functions necessary to manage the event and, when required by law, with competent authorities.

 

Security Activities and Testing

SENECA encourages the responsible disclosure of vulnerabilities.

However, this policy does not constitute authorization to conduct activities that could:

  • Compromise system or service availability;
  • Modify or delete data;
  • Intentionally access unnecessary personal data or confidential information;
  • Compromise third-party systems;
  • Perform DoS or DDoS attacks;
  • Use social engineering techniques;
  • Carry out activities contrary to applicable regulations.

If, during research activities, access to confidential or personal information is accidentally obtained, the activity must be stopped immediately and the event reported promptly to SENECA.

 

Organization and Responsibility

Cybersecurity report management is entrusted to a multidisciplinary organizational structure that may involve, depending on the event:

  • IT Security Team;
  • Product Security / R&D;
  • IT Manager;
  • Quality and Compliance;
  • NIS2 Point of Contact;
  • Legal and Regulatory Functions;
  • Management;
  • Other business functions concerned.

This model allows SENECA to distinguish and properly manage incidents related to corporate infrastructure and those related to product security.