Our Commitment to Product Security
Advantest takes all possible threats to our products very seriously and recognizes the importance of information received from customers and clients, in addition to our company's technology and sales information. Thus, a Product Security Incident Response Team (PSIRT) and a reporting process have been established that ensure any product security issues are immediately dealt with.
Policies and Rules Related to Product Security
Advantest has established a Product Cyber Security Policy setting out our approach to identifying, assessing and remediating any potential vulnerabilities in our products.
This policy aims to integrate cybersecurity to every phase of the lifecycle of an Advantest product. It establishes fundamental cybersecurity principles like Secure-by-Design and Secure-by-Default, which are followed from product planning and enable security features to be enabled by default. It also defines clear roles and responsibilities if a security issue is ever discovered.
Organization of the Product Security Management System
In FY2026, Advantest formed the Advantest PSIRT to reinforce initial response systems for product security incidents. PSIRT is the single point of contact for the users of our products to enable them to communicate directly and rapidly with us, in order to facilitate reporting on vulnerabilities. Furthermore, a reporting process that is available 24 hours a day, 365 days a year, has also been incorporated to facilitate early detection and swift response to global cybersecurity issues.
Advantest's PSIRT is composed of experts from different departments who work together across organizational boundaries to respond to potential product security issues as quickly as possible. PSIRT members fulfill specific roles and responsibilities.
Advantest’s PSIRT is dedicated to identifying possible cyber threats related to product security and designing solutions for any possible product security issues. If applicable, PSIRT will analyze the issue and coordinate all related processes, while Advantest’s defect management and R&D teams are responsible for developing patches and corrective actions to restore cybersecurity to the affected product.
System for Responding to Product Security Incidents
Advantest created a form through which any product security related issues can be reported to PSIRT. Said form can be found below and can be accessed without log-in requirements.
After a report is submitted, Advantest’s PSIRT will follow a pre-defined process to deal with the issue as quickly as possible, in order to restore full security to our products, as the safety of our customers’ data is of the highest priority to us.
Upon receipt of an issue, Advantest's PSIRT performs an initial triage and determines whether the reported item qualifies as a vulnerability, an exploited vulnerability, an incident, a severe incident, or a non-security issue. If the reported issue is not related to product security, the report is forwarded to the appropriate support team. For issues classified as security-related, PSIRT performs the detailed analysis and classification. Only exploited vulnerabilities and severe incidents are considered reportable under the Cyber Resilience Act (CRA). For reportable cases, the PSIRT prepares the report to ENISA, the European Union Agency for Cybersecurity. The report is reviewed by the Legal team and submitted by the Compliance team.
Reporting a Security Issue
The Advantest Group encourages users of our products to report any possible security vulnerabilities and incidents to us. After a report Advantest allocates appropriate resources to analyze, validate and provide actions to address the issue and restore proper security to the affected product.
To help ensure a smooth and efficient review process, please verify that you have all relevant information available before submitting your report.
For your convenience, we have outlined all required information below.
What product information do you have to submit?
-
Your name and contact information (e.g. email address, phone number)
-
Name of the affected product and further detail information (e.g. serial number, firmware version, ...)
-
Source of cybersecurity information
-
Description of the vulnerability
-
If applicable: exploit description
-
If applicable: incident description
-
If applicable: impact description
Important information before you submit
Please make sure you comply with the following points before you submit your report:
-
We kindly ask that forms be filled out in English, if possible, to help ensure a smooth and efficient review process.
-
We kindly ask you to submit any reports to us only through the form above to allow us to deal with any potential vulnerability as quickly as possible. Alternatively, you can also contact us at:
-
Postal address:
Advantest Europe GmbH
Compliance Unit
Herrenberger Str. 130
71034 Boeblingen
Germany
-
-
Only new reports will be considered. Reports about vulnerabilities that have been publicly addressed by Advantest will not be considered.
-
Only share information that is relevant and do not share any information that you are not allowed to share with us, such as, for example, business secrets.