Trust

Security

A security arrangement added after commissioning protects less and costs more. The decisions that matter are taken during design: segmentation, privileges, logging, and what the system must keep doing when part of it is compromised.

What we apply

The principles below apply to every engagement, whatever the division involved. They depend on no product and assume no particular tool.

  • Segmentation between functional domains and least privilege on every exchange.
  • Strong authentication and traceability of privileged access.
  • Encryption in transit and at rest.
  • Vulnerability management with committed timeframes by severity.
  • Documented hardening of delivered systems, verified at acceptance.
  • Control of the software supply chain for integrated components.

What is measured

A security commitment that translates into no observable quantity commits no one. The following are contractual, and they are what we accept to be judged on.

  • Time between an event occurring and the organisation detecting it.
  • Time to qualify, between detection and the decision to act.
  • Time to remediate, by severity, observed rather than estimated.

Reporting

Konect Groupe welcomes vulnerability reports concerning its publicly exposed systems. The procedure, the scope and the commitments made to those who report are published on the responsible disclosure page.

Shared at pre-qualification

This material is provided to an identified organisation once the request has been qualified.

  • Detailed security statement by domain.
  • Vulnerability management policy and committed timeframes.
  • Incident response procedure and client notification terms.

Request the documentation

Consultations · Pre-qualifications · Partnerships

Let’s discuss your project.

Describe your priority, its operating context and the intended outcome. We will route the enquiry to the right person.