Product Security Incident Response

OMRON Robotics is committed to the security and integrity of our products throughout their lifecycle. Our Product Security Incident Response Team (PSIRT) is responsible for receiving, assessing, and coordinating the resolution of security vulnerabilities affecting our robotics and industrial automation products — including issues in the third-party and open-source components we integrate.

Our vulnerability management program is aligned with IEC 62443-4-1 secure product development lifecycle requirements and follows the coordinated vulnerability disclosure principles set out in ISO/IEC 29147 and ISO/IEC 30111.

Product security commitment: Omron is committed to helping customers maintain secure and reliable operations by reviewing potential cybersecurity issues, coordinating appropriate response activities, and providing guidance when vulnerabilities are identified.

Our Approach

When a potential vulnerability is reported, OMRON evaluates the information, determines potential impact, identifies affected products or versions, and coordinates response activities as appropriate.

PSIRT follows a structured, repeatable process:

  • Acknowledgement – Every report is acknowledged promptly, and a preliminary assessment of validity, scope, and reproducibility follows shortly after.
  • Risk assessment – We score each vulnerability using CVSS v3.1, then layer on context specific to industrial robotics: safety impact, exploitability in operational technology (OT) environments, network accessibility, privilege requirements, and the size of the affected installed base. This combined view determines a priority rating of Critical, High, Medium, or Low.
  • Remediation – Fix development timelines are tied to priority, with Critical issues receiving immediate attention and accelerated development. Every fix goes through engineering development, regression and security testing, and a final PSIRT security review before release.
  • Interim mitigation – When a permanent fix requires more time, we provide interim guidance such as workarounds, configuration recommendations, or network-level controls to reduce exposure while a fix is developed.
  • Third-party components – We maintain a Software Bill of Materials (SBOM) for our products and monitor known vulnerabilities in the open-source and third-party libraries we depend on, prioritizing vendor-supplied fixes and coordinating with upstream maintainers on disclosure timing.
  • Publication or revision of a vulnerability advisory
Coordinated Vulnerability Handling

OMRON follows a coordinated approach to vulnerability handling. Reports are reviewed by the appropriate teams to determine validity, severity, potential customer impact, and recommended next steps.

Where applicable, OMRON may coordinate with external parties, including security researchers, vendors, industry organizations, or vulnerability coordination bodies.

How reports are handled: Vulnerability reports are reviewed to determine affected products, potential impact, severity, and appropriate mitigation or communication steps. Omron may contact the reporter for additional information during the review process.

Customer Guidance

Customers are encouraged to review vulnerability advisories that may apply to their installed OMRON products or software. Each advisory may include information about affected products, affected versions, potential impact, recommended countermeasures, and available updates.

Customers should evaluate recommendations based on their own system architecture, operating environment, and risk profile.

Important note: Cybersecurity risks can vary depending on product configuration, network architecture, connected systems, and operational requirements. Customers should review advisories and security guidelines in the context of their specific environment.

In this topic

Report an incident 

If you find a vulnerability in one of our products or services, please report it to the OMRON Product Security Incident Response Team.

Report incident

50-50