Skip to Content

PROFESSIONAL SERVICE | MANAGED SERVICE


Managed PSIRT

PROFESSIONAL SERVICE | MANAGED SERVICE


Vulnerability Management

Recognize risks, strengthen security



  Continuous detection and assessment of vulnerabilities


  Risk-based prioritization for targeted remediation in patch management


  Reduzierung der Angriffsfläche durch strukturiertes Managed Vulnerability Management



Do you need more information or would you like to integrate vulnerability management into your Security Operations Center?

Organize product security professionally



  Meet CRA requirements without building and operating an internal PSIRT


  Centralized intake and coordinated processing of vulnerability reports


  Professional communication with researchers, customers, suppliers, and regulatory authorities




Looking to establish an effective vulnerability response process without adding operational burden to your IT team?

With the Cyber Resilience Act (CRA), requirements for manufacturers of products with digital elements are increasing. Vulnerabilities must be received, assessed, processed, and, in certain cases, reported to the relevant authorities in a structured manner.


Building an internal Product Security Incident Response Team (PSIRT) requires specialized expertise, clearly defined processes and responsibilities, and continuous operational resources.


With Managed PSIRT, Possehl Secure takes over key Product Security Incident Response Management tasks as a service. Companies benefit from an established reporting and communication process, clear responsibilities, and support in meeting regulatory requirements.

Manage Product Security efficiently

Possehl Secure supports companies in handling security-related reports in a
structured manner.


  Receiving vulnerability reports as a central single point of contact


  Validating, prioritizing, and verifying reported vulnerabilities


  Structured forwarding of relevant vulnerabilities to the responsible product owners


  Reporting actively exploited vulnerabilities to ENISA


  Coordinated communication with external parties
e.g., researchers,customers, suppliers, and authorities


  Support in preparing security advisories for affected customers



Our solution

Structured onboarding process

The onboarding into Managed PSIRT typically takes 1-2 project days per company. It is based on a standardized onboarding process, where we jointly establish the organizational and process-related prerequisites for an effective PSIRT.



1

Analysis & Planning

GAP analysis to determine the current state and the required target structure.
|

Processes & Responsibilities

Definition of roles, contacts, reporting channels, and escalation processes between the PSIRT, product owners, external parties, and ENISA.

| 3

Standardization of the environment

Introduction or alignment of a Coordinated Vulnerability Disclosure (CVD) policy and security.txt in accordance with RFC 9116.

4 |

Testing & transition to operation

Validation of the defined procedures and transition to regular operations.


Your benefit – our added value

  Meet CRA requirements pragmatically
Professionally operated PSIRT without having to build your own operational resources.

  Fast and structured response
Clear processes for handling vulnerability reports and security incidents.

  Relief for product teams
Development teams can focus on vulnerability remediation and
further product development.

  Professional communication

A central point of contact for researchers, customers, and authorities.



The Managed PSIRT service is designed for companies that develop, distribute, or operate products with digital elements and want to implement CRA requirements efficiently.


Specially suitable for:


  Software vendors


  Mechanical and plant engineering companies


  Manufacturers of connected products and IoT solutions

Who is this service suitable for?


A professionall Security Operations Center (SOC) offers you continuous, efficient security monitoring as well as a rehearsed and proven response. 

You would like to integrate a PSIRT into your Security Operations Center? 
Get in touch with us!

PSIRT in your SOC

Benefits of our managed services

  Reduced workload for IT staff – more focus on the core business

  Professional and cost-efficient support


  Clear assignment of tasks and responsibilities

  Customized state of the art solution

  Up-to-date and stable client infrastructure

  Constant monitoring of security requirements

  Immediate processing of security alarms

  Transparent incident and change process

  Fixed monthly fee

  Operational reliability through continuous monitoring

Interested in more information?

Contact us for a non-binding consultation! 
Our team will contact you shortly.

Ihre Daten wurden übermittelt.

Unser Team wird sich so schnell wie möglich bei Ihnen zurückmelden.




Can we assist you?

Our experts are happy to support. Get in touch with us!