Report suspected cybersecurity issues as soon as possible

If you suspect a cybersecurity incident or have identified a security vulnerability affecting a Newtec product, software, connected service or digital component, please report it immediately.

This channel is specifically for cybersecurity-related issues.
For ordinary machine faults, maintenance, workplace accidents or other non-cybersecurity matters, please use your normal Newtec service or dealer contact.

!
REPORT A SECURITY ISSUE security@newtec.dk

Do not wait until the cause is confirmed or all technical information is available. Report what you know.

Quick Check

Report it if you suspect any of the following:

✓

Unauthorised access to a machine, system or service

✓

A suspected or confirmed cybersecurity vulnerability

✓

Malicious software or unexpected software behaviour

✓

Unauthorised manipulation of software, configuration or machine parameters

✓

Compromised remote access or remote service functionality

✓

Suspicious activity involving Analytics, WebServices or other connected functionality

✓

Unauthorised changes to firmware, software, AI or machine-learning components

✓

Any other cybersecurity issue affecting a Newtec product or connected service

If you are unsure whether an issue is cybersecurity-related, report it. Newtec will assess it.

Detailed Information

The sections below contain the full reporting guidance. Open the sections that are relevant to you.

Please contact Newtec if you identify or suspect a cybersecurity issue involving a Newtec product or related service, including:

  • a suspected or confirmed cybersecurity vulnerability
  • unauthorised access to a machine, system or service
  • exploitation or suspected exploitation of a vulnerability
  • malicious software or unexpected software behaviour
  • unauthorised manipulation of machine configuration, parameters or software
  • compromise of remote access or remote service functionality
  • unauthorised modification of firmware, software or other digital components
  • unexpected or unauthorised modification of AI or machine-learning components
  • unauthorised access to or exposure of data
  • suspicious activity involving Newtec Analytics, WebServices or other connected functionality
  • compromise of user accounts, authentication mechanisms or access credentials
  • any other issue that may affect the cybersecurity of a Newtec product

The reporting channel covers cybersecurity issues relating to:

  • Newtec weighing machines
  • Newtec packing machines and packing solutions
  • Celox optical sorting systems
  • associated software and firmware
  • AI and machine-learning components used in Newtec products
  • Newtec Analytics, WebServices and other relevant connected services
  • other digital components supplied as part of a Newtec product

Please continue to use your normal Newtec service, dealer or other appropriate contact for matters such as:

  • ordinary mechanical faults
  • general machine breakdowns
  • calibration or operational issues with no suspected cybersecurity cause
  • workplace accidents or injuries
  • general occupational health and safety matters
  • ordinary service and maintenance requests
If a physical or operational problem may have been caused by a cybersecurity incident, you should report the suspected cybersecurity issue to security@newtec.dk as well.

Please provide as much of the following information as is reasonably available:

  • product or machine model
  • serial number, if available
  • software, firmware or application version
  • affected component or service
  • description of what you observed
  • date and time of the event or discovery
  • whether the issue is still occurring
  • affected installation or site
  • steps that led to the issue, if known
  • screenshots, log files or other relevant evidence
  • your name and contact details
Do not delay your initial report because some information is missing. Newtec may contact you for additional information as part of the assessment and investigation.

You may report cybersecurity incidents and vulnerabilities directly to Newtec even if the product was purchased, installed or serviced through a Newtec dealer or service partner.

Your normal dealer or service contact may continue to assist with operational service and remediation. However, reporting a suspected cybersecurity issue to Newtec should not wait for the dealer to complete its own investigation.

Newtec may involve the relevant dealer, service organisation or technical specialists where necessary to investigate and resolve the issue.

Cybersecurity issues may also be reported for products that:

  • are not connected to the internet
  • do not use Newtec Analytics or WebServices
  • operate on isolated production networks
  • are older Newtec products
  • are no longer covered by an active service agreement

Whether a product is online, offline or outside an active service agreement should not prevent you from reporting a suspected cybersecurity issue.

Please do not include passwords, private keys, authentication credentials or unnecessarily large amounts of sensitive customer or production data in your initial email.

If additional sensitive information is required for the investigation, Newtec will coordinate an appropriate method for transferring the information.

Where possible, please avoid modifying or deleting relevant logs, files or other evidence before Newtec has had an opportunity to assess the issue.

If you believe you have identified a vulnerability, please provide sufficient technical information for Newtec to understand and reproduce the issue where reasonably possible.

Useful information may include:

  • affected product and version
  • affected digital component
  • technical description of the vulnerability
  • prerequisites for exploitation
  • steps to reproduce the issue
  • observed or potential cybersecurity impact
  • proof-of-concept information, where appropriate

Please avoid activities that could:

  • disrupt production systems
  • create a risk to people or equipment
  • damage or modify customer data
  • access information belonging to other parties without authorisation

Please do not publicly disclose sensitive vulnerability details before Newtec has had a reasonable opportunity to investigate the issue and coordinate appropriate remediation and communication.

Newtec will assess reported cybersecurity issues and involve the relevant technical and operational functions as required.

Depending on the nature of the issue, this may include:

  • confirming the affected product and versions
  • assessing the cybersecurity impact
  • investigating whether exploitation has occurred
  • identifying affected installations
  • developing mitigating or corrective measures
  • coordinating with relevant technical specialists, dealers or service partners
  • providing cybersecurity information to affected users
  • notifying relevant authorities where required

The actions required will depend on the individual case.

If a suspected cybersecurity incident creates an immediate risk to people, equipment or safe production, follow your local safety and emergency procedures first.

You should also report the suspected cybersecurity incident to security@newtec.dk.

The Product Cybersecurity reporting channel does not replace local emergency, workplace safety or machine-safety procedures.

For ordinary maintenance, troubleshooting or operational issues where there is no suspected cybersecurity issue, please continue to use your normal Newtec service or dealer contact.

CONTACT PRODUCT CYBERSECURITY

Report suspected cybersecurity issues as soon as possible.

security@newtec.dk