Certifications
- Sustainability
- Certifications
ISO 27001:2022 Information Security Management System
The International Organization for Standardization (ISO) is an international organization whose mission is to promote international trade through the standardization of facilities and activities associated with service goods, and to enhance cooperation in the fields of technology, science, and economic activities..
ISO 27001 certification is an international standard that specifies the requirements for an information security management system, which companies must systematically manage to protect the information of stakeholders such as employees and customers.
In 2024, Hyosung Heavy Industries newly obtained ISO 27001:2022 certification for its headquarters and Changwon plant.
IEC 62443 4-1:2018 (Secure Development Lifecycle)
The International Electrotechnical Commission (IEC) is an international organization that develops and publishes international standards for electrical, electronic, and related technologies. IEC 62443 is a series of international standards for the security of industrial automation and control systems (IACS), and IEC 62443 4-1 specifically sets out the requirements for a secure product development lifecycle.
Hyosung Heavy Industries established a systematic secure development framework for a wide range of power equipment products incorporating communication and control functions, including STATCOM, HVDC, and ESS, and obtained IEC 62443 4-1 certification in February 2026.
Cybersecurity Vulnerability Management Policy
In accordance with the aforementioned security certification recommendations, Hyosung Heavy Industries establishes appropriate procedures for handling security vulnerabilities in its products and services. In addition, we periodically monitor public vulnerability databases and conduct penetration testing.
This page summarizes our vulnerability disclosure policy.
Report Vulnerability
Hyosung Heavy Industries welcomes reports from all individuals who help strengthen the security of our services. To ensure a safe reporting process, please submit your reports in accordance with the guidelines below.
As a good-faith reporter, we kindly ask that you comply with the following guidelines:
- Please conduct only the minimum verification necessary to demonstrate the vulnerability.
  Any modification, deletion, or downloading of actual user data is strictly prohibited
- Avoid any testing that could cause system downtime, service degradation, or otherwise impact regular users.
- Please keep the reported vulnerability confidential and do not disclose it to third parties or the public
  until Hyosung Heavy Industries has completed its analysis and official patch.
For reporters who submit vulnerabilities in good faith and follow the guidelines above, we guarantee that no civil or criminal legal actions will be pursued. Hyosung Heavy Industries respects and protects your valuable efforts.
Please submit your report via the Customer Inquiry link below. We recommend including the following details:
- Contact details of the reporter
- System specs (e.g., product name, firmware version)
- Error symptoms or associated logs
- Technical details (e.g., steps to trigger the vulnerability, sample packet captures)
Response Process
Hyosung Heavy Industries handles received vulnerabilities promptly and transparently according to the following steps.
Step 1. Receipt & Acknowledgment [Within 5 business days of receipt]
- Once the report is successfully received, the coordinator will send an acknowledgment email to the reporter.
Step 2. Analysis & Verification [Within 10 business days of receipt]
- The internal department verifies whether the vulnerability can be reproduced,
  assesses the risk level (based on CVSS metrics, etc.), and determines if it is a valid vulnerability.
Step 3. Remediation & Patching [Timeline varies based on severity]
- The product development department and the product security team collaborate to develop and apply the vulnerability patch.
- However, because each security vulnerability is unique, we cannot guarantee a specific resolution timeline.
  Remediation actions may include software modifications, new product version releases, and/or updates to security guidelines.
  Throughout the entire process, we will continuously coordinate with the vulnerability discoverer and
  affected vendors to ensure all concerns are resolved before the patch is finalized.
Step 4. Result Sharing & Completion
- Upon successful remediation, the results will be shared with the reporter and published on our official website.