IT Security & Data Privacy PolicyWhat makes Voith trustworthyOur Cyber Security Approach
Voith follows a risk‑based, defense‑in‑depth security strategy that covers enterprise IT systems, digital platforms, and industrial control systems throughout their lifecycle.
Key principles include:
- Secure‑by‑design engineering for digital and industrial solutions
- Risk‑based information security management applying the zero-trust principle
- Secure development lifecycle (SDLC) for products and services.
- Continuous improvement and monitoring according to international standards
This approach reflects Voith’s long‑standing focus on Industrial Security, addressing increasing connectivity in critical infrastructures such as energy, paper, transport, and automation.
Information Security & Governance
- Information Security Management System (ISMS): Voith has implemented an Information Security Management System (ISMS) aligned with ISO/IEC 27001, covering defined business areas and digital services.
- Key elements of the ISMS include:
- Our Voith Information Security Policy
- A comprehensive awareness program to strengthen human factors
- Information security risk assessment and treatment
- State-of-the-art Technical and organizational protection measures
- Regular internal audits and continuous improvement
- ISO/IEC 27001:2022 certification, demonstrating internationally recognized information security practices
Product & Services
- Compliant with international and industry-specific standards
- Secure Development Lifecycle (SDL) based on IEC 62443-4-1 certified practices
- Defense in depth principle-based products and services
- Vulnerability management as a Service through the lifecycle
- Applying strict cybersecurity requirements throughout our supply chain
- Customer Support & Assurance through enhanced cybersecurity service offerings.
Detect & Respond
- Monitor information systems and networks for cyber threats
- Detect, analyze, and respond to security incidents
- Contain and mitigate cyber-attacks to minimize impact
- Provide transparency on cyber exposure
- Security vulnerability management
- Coordinated disclosure program available
Applied Cybersecurity at Voith
Compliance & Certification
ISO 27001: 2022, Auditor TÜVNORD
IEC 62443-4-1: 2018, Auditor TÜVNORD
MPLs 2.0 Regulation Certified China Region
Align our security measures with regulatory requirements such as GDPR and NIS2
JOSCAR‑ Voith is registered supplier, listed on the Joint Supply Chain Accreditation Register (JOSCAR)
Cyber Essential Plus (UK)
Data Privacy
- Protection of personal data in services & products
- Global Policy & Data Protection Framework
- Sub-processer management
Identity & Access Management (IAM)
- Identity Management and Protection
- Role-based access control (RBAC),
- Secure user authentication and access controls
Network Segmentation
- Network zoning.
- Controlled through firewalls and security gateways.
- Secure Separation of Business and Production Environments
Security Awareness
- Mandatory employee awareness training
- Security guidelines and policies
- Continuous communication on emerging threats
Education & Expertise
- Global cross-divisional cybersecurity organization
- Certified cybersecurity experts
- A network of partners inc. ditis as a member of the Voith Group
Data Protection & Endpoint Security
- Protected against unauthorized access.
- Data Classification & Data Loss Prevention.
- Protection of sensitive data
Monitoring, Logging & Threat Detection
- Threat Detection & Response
- 24x7 Incident Response
- Advanced Threat Analytics
Vulnerability Management
- Vulnerability Assessment Program inc. Detection & Remediation
- Customer portal for product vulnerabilities
- Lifecycle vulnerability management as a Service
Business Continuity & Resilience
- Business Continuity Planning
- Verified Backup & Recovery procedures
- Regular exercises
Supplier & Third-Party Security
- Supplier cybersecurity assessments
- Certification and compliance verification
- Risk-based control requirements
Security Testing & Auditing
- Security Testing & Assurance in Development
- Penetration Testing Program
- Audit Management
Incident Detection & Response
- 24x7 Incident Response
- Security Incident Response & Recovery
- Cyber Defense Operations
Product Vulnerabilities and Security Updates
Registered customers can access MyVoith to review published cybersecurity vulnerabilities relevant to their Voith products, including available mitigation guidance and security update information. Vulnerabilities can be identified by product or serial number.
Security Contact
For security‑related inquiries or responsible disclosure, please contact:
security@voith.com
Please Note:
The information presented on this Trust Center is provided for general informational purposes only and represents high‑level summaries of the Company’s internal policies, standards, and guidelines. These summaries are not intended to be exhaustive and do not replace or supersede the official policy documentation approved and maintained by the Company.
In the event of any inconsistency, discrepancy, or conflict between the content published on this website and the applicable internal policy documents, the internal policy documentation shall govern and be considered the authoritative source.