RISO KAGAKU CORPORATION.

Home > Products > Security of Products and Services > EU Cyber Resilience Act

EU Cyber Resilience Act

Coordinated Vulnerability Disclosure (CVD) Policy

1. Introduction

RISO KAGAKU CORPORATION ("RISO" or "we") considers the security of our customers' data and systems to be our highest priority. In accordance with global cybersecurity regulations, including the EU Cyber Resilience Act (CRA), and international standards (ISO/IEC 29147), we operate a Coordinated Vulnerability Disclosure (CVD) process to enhance the security of all our products with digital elements. We highly value the cybersecurity community and welcome vulnerability reports from security researchers, customers, and the general public.

2. Safe Harbor

The Company will not initiate legal action (including civil litigation or criminal prosecution for unauthorized access offences) against any vulnerability research or reporting conducted in good faith and in compliance with the rules of this Policy. Should a third party initiate legal proceedings against a reporter, the Company will explicitly confirm that the good-faith vulnerability research carried out by security researchers or customers was authorized by us, and we will take appropriate measures to safeguard the reporter (including security researchers and customers).

3. Scope

This policy applies to the following products and domains that are currently within their active support period:
- Hardware products manufactured and provided by RISO
- Software and drivers provided by RISO
- *.riso.co.jp and *.riso.com

[Out of Scope] The following are strictly out of scope for this policy:
- Products that have reached their End of Support (EoS)
- Third-party systems, services, or equipment not managed by RISO

4. Rules of Engagement

Security researchers and customers are required to strictly adhere to the following rules when conducting research:
- Data Protection: Do not alter, destroy, or exfiltrate user or corporate data.
- Maintain Availability: Do not engage in activities that degrade or disrupt our services or devices, such as Denial of Service (DoS) attacks.
- Non-Disclosure: Do not disclose or share vulnerability details or exploit code with the public until RISO has provided a security update (patch/firmware) to our customers and both parties have agreed upon a disclosure timeline.

5. How to Report

If you discover a vulnerability, please report it to the contact provided below.
Email: security@riso.co.jp

[IMPORTANT: Emergency Reporting under the CRA]
Under the CRA, RISO is obligated to report severe threats to European authorities. When submitting your report, please ensure you explicitly state whether you are aware of either of the following:
1) Active Exploitation ("In the wild"): Is there evidence that this vulnerability is already being actively exploited in real-world environments?
2) Publicly Available Exploit Code: Is the exploit code for this vulnerability already published and accessible on the internet?

6. Our Response Process and Information Sharing

1) Acknowledgment: We will confirm receipt of your report within 3 business days.
2) Triage and Initial Assessment: We will evaluate the report and notify you of our validation results and remediation plan within 14 days.
3) Reporting to Authorities (CRA Article 14 Compliance): If we determine that the reported vulnerability is being actively exploited or constitutes a severe cyber incident, RISO is legally required to submit an early warning to ENISA and the relevant national CSIRTs within 24 hours of becoming aware of the threat. We will never disclose the reporter's personal information to authorities without explicit consent.
4) Remediation and Patch/Firmware Updates: We will develop a remediation without undue delay and provide it to our customers as a free security update throughout the defined support period of the affected product.