
Cybersecurity, Data Protection and Compliance
Ongoing digitalisation creates new opportunities while simultaneously increasing the demands placed on the protection of information, systems, and connected products. Cybersecurity is therefore a fundamental element of our corporate responsibility and makes a significant contribution to the security, reliability, and trustworthiness of our business processes, products, and services.
We comply with recognised security standards and all applicable legal and regulatory requirements, including the General Data Protection Regulation (GDPR), the NIS2 Directive, and the Cyber Resilience Act (CRA). Our objective is to embed information security and data protection into our processes, products, and services from the earliest stages and to ensure their sustainable implementation throughout the entire lifecycle.
Particular emphasis is placed on the principles of Secure by Design and Secure by Default. Potential risks are identified and assessed early in the development process, enabling appropriate security measures to be incorporated from the outset. This approach is supported by continuous vulnerability management, regular security assessments, timely provision of security updates, and ongoing monitoring of emerging threats.
In addition, we actively promote cybersecurity awareness among our employees through targeted training and awareness programmes. We view cybersecurity not only as a technical and regulatory obligation but also as an integral part of a responsible and sustainable corporate culture.
Our goal is to ensure digital security throughout the entire product lifecycle, identify and mitigate risks at an early stage, and strengthen the long-term trust of our customers, business partners, and employees.
Report a vulnerability
A vulnerability can be reported via the email address product-security@thermokon.de.