EN

IT Security & Data Privacy PolicyWhat makes Voith trustworthyOur Cyber Security Approach

Voith follows a risk‑based, defense‑in‑depth security strategy that covers enterprise IT systems, digital platforms, and industrial control systems throughout their lifecycle.

Key principles include:

  • Secure‑by‑design engineering for digital and industrial solutions
  • Risk‑based information security management applying the zero-trust principle
  • Secure development lifecycle (SDLC) for products and services.
  • Continuous improvement and monitoring according to international standards

This approach reflects Voith’s long‑standing focus on Industrial Security, addressing increasing connectivity in critical infrastructures such as energy, paper, transport, and automation.

Information Security & Governance

  • Information Security Management System (ISMS): Voith has implemented an Information Security Management System (ISMS) aligned with ISO/IEC 27001, covering defined business areas and digital services.
  • Key elements of the ISMS include:
  • Our Voith Information Security Policy
  • A comprehensive awareness program to strengthen human factors
  • Information security risk assessment and treatment
  • State-of-the-art Technical and organizational protection measures
  • Regular internal audits and continuous improvement
  • ISO/IEC 27001:2022 certification, demonstrating internationally recognized information security practices

Product & Services

  • Compliant with international and industry-specific standards
  • Secure Development Lifecycle (SDL) based on IEC 62443-4-1 certified practices
  • Defense in depth principle-based products and services
  • Vulnerability management as a Service through the lifecycle
  • Applying strict cybersecurity requirements throughout our supply chain
  • Customer Support & Assurance through enhanced cybersecurity service offerings.

Detect & Respond

  • Monitor information systems and networks for cyber threats
  • Detect, analyze, and respond to security incidents
  • Contain and mitigate cyber-attacks to minimize impact
  • Provide transparency on cyber exposure
  • Security vulnerability management
  • Coordinated disclosure program available

Applied Cybersecurity at Voith

Compliance & Certification

ISO 27001: 2022, Auditor TÜVNORD

IEC 62443-4-1: 2018, Auditor TÜVNORD

MPLs 2.0 Regulation Certified China Region

Align our security measures with regulatory requirements such as GDPR and NIS2

JOSCAR‑ Voith is registered supplier, listed on the Joint Supply Chain Accreditation Register (JOSCAR)

Cyber Essential Plus (UK)

Data Privacy

  • Protection of personal data in services & products
  • Global Policy & Data Protection Framework
  • Sub-processer management

Identity & Access Management (IAM)

  • Identity Management and Protection
  • Role-based access control (RBAC),
  • Secure user authentication and access controls

Network Segmentation

  • Network zoning.
  • Controlled through firewalls and security gateways.
  • Secure Separation of Business and Production Environments

Security Awareness

  • Mandatory employee awareness training
  • Security guidelines and policies
  • Continuous communication on emerging threats

Education & Expertise

  • Global cross-divisional cybersecurity organization
  • Certified cybersecurity experts
  • A network of partners inc. ditis as a member of the Voith Group

Data Protection & Endpoint Security

  • Protected against unauthorized access.
  • Data Classification & Data Loss Prevention.
  • Protection of sensitive data

Monitoring, Logging & Threat Detection

  • Threat Detection & Response
  • 24x7 Incident Response
  • Advanced Threat Analytics

Vulnerability Management

  • Vulnerability Assessment Program inc. Detection & Remediation
  • Customer portal for product vulnerabilities
  • Lifecycle vulnerability management as a Service

Business Continuity & Resilience

  • Business Continuity Planning
  • Verified Backup & Recovery procedures
  • Regular exercises

Supplier & Third-Party Security

  • Supplier cybersecurity assessments
  • Certification and compliance verification
  • Risk-based control requirements

Security Testing & Auditing

  • Security Testing & Assurance in Development
  • Penetration Testing Program
  • Audit Management

Incident Detection & Response

  • 24x7 Incident Response
  • Security Incident Response & Recovery
  • Cyber Defense Operations


Product Vulnerabilities and Security Updates

Registered customers can access MyVoith to review published cybersecurity vulnerabilities relevant to their Voith products, including available mitigation guidance and security update information. Vulnerabilities can be identified by product or serial number.

Security Contact

For security‑related inquiries or responsible disclosure, please contact:
security@voiths.sbs

Please Note:
The information presented on this Trust Center is provided for general informational purposes only and represents high‑level summaries of the Company’s internal policies, standards, and guidelines. These summaries are not intended to be exhaustive and do not replace or supersede the official policy documentation approved and maintained by the Company.
In the event of any inconsistency, discrepancy, or conflict between the content published on this website and the applicable internal policy documents, the internal policy documentation shall govern and be considered the authoritative source.

RIGHT OFFCANVAS AREA