Vulnerability Management Policy
1. Introduction
WEG is committed to identifying, evaluating, addressing and monitoring security vulnerabilities in a continuous and risk-based manner, protecting its systems, products, digital solutions and operations.
Vulnerability Management is part of WEG's corporate cybersecurity strategy and aims to reduce exposure to threats, strengthen asset resilience and contribute to business continuity, customer protection and compliance with legal, regulatory and normative requirements.
2. Scope
This Policy applies to technological assets, information systems, Information Technology (IT), Operational Technology (OT), Industrial Control Systems (ICS) environments, products with digital elements, cloud solutions, software, firmware, third-party components and other technologies developed, operated or supported by WEG during their supported life cycle, as defined by WEG or required by applicable laws and regulations.
Vulnerability management may also include components, libraries, software, firmware, and other elements developed by third parties and incorporated into WEG's products or solutions, subject to applicable technical, legal, regulatory, and contractual limitations.
All employees, suppliers, partners and third parties involved in the management of these assets must comply with the guidelines established in this Policy.
3. Principles
Vulnerability Management at WEG is conducted based on the following principles:
- continuous and risk-based management;
- proactive identification of vulnerabilities;
- prioritization according to business impact and criticality of assets;
- protection of the confidentiality, integrity, availability and authenticity of information;
- integration between information security, secure development, risk management, change management, and incident response processes;
- traceability of activities and decisions;
- continuous improvement of processes;
- compliance with applicable legal, regulatory and normative requirements;
- integration of the principles of Security by Design, Security by Default, and Privacy by Design into the product and solution lifecycle.
4. Vulnerability Management
WEG maintains a structured process for vulnerability management throughout the life cycle of its assets, products and solutions.
This process includes, among other activities:
- identification of vulnerabilities;
- assessment of severity and potential impact;
- risk-based prioritization;
- definition and implementation of remediation or mitigation actions;
- validation of the effectiveness of the measures adopted;
- continuous monitoring of exposure to vulnerabilities;
- periodic reassessment of risks.
Vulnerabilities are addressed considering their criticality, the operational context and the potential impacts on WEG's customers, operations and business. Decisions related to the assessment, prioritization, treatment, mitigation, correction and disclosure of vulnerabilities will be defined by WEG in accordance with technical, operational, legal, regulatory and risk management criteria applicable to each case.
When immediate remediation is not technically feasible or operationally adequate, WEG may adopt mitigating measures, compensatory controls or formal risk management procedures to reduce the exposure associated with the vulnerability.
Where applicable, the vulnerability assessment will consider not only the technical and operational impacts, but also the potential effects on data subjects.
WEG will make reasonable efforts to analyze the reports received and define the measures it deems appropriate, in accordance with applicable technical, operational, legal and regulatory criteria. Nothing in this Policy shall be construed as guaranteeing remediation, mitigation, public disclosure or taking any specific action with respect to reported vulnerabilities. Decisions related to the assessment, prioritization, treatment, mitigation, remediation and disclosure of vulnerabilities will be defined by WEG in accordance with technical, operational, legal, regulatory and risk management criteria applicable to each case.
5. Security Updates
WEG seeks to provide security updates, patches, remediations, or mitigation measures to reduce the risks associated with the vulnerabilities identified in its products.
The prioritization of these updates considers factors such as:
- severity of the vulnerability;
- possibility of exploitation;
- operational impact;
- criticality of affected assets;
- regulatory and business requirements.
For industrial environments and products used in critical systems, the deployment of the updates considers additional requirements for availability, reliability, and operational continuity.
The corrections and mitigating measures implemented are submitted to validation activities to verify their effectiveness and ensure the adequate reduction of the identified risks.
6. Continuous Monitoring
WEG continuously monitors reliable sources of threat intelligence, manufacturer advisories, known vulnerabilities, third-party components, and cybersecurity trends to identify new risks that may affect its assets, products, and services. Special attention is given to actively exploited vulnerabilities and emerging threats that may increase the level of risk to the organization and its customers.
The information obtained is used to support risk assessment, priority definition and continuous improvement of the Vulnerability Management process.
7. Roles and Responsibilities
Vulnerability Management is a shared responsibility between the areas of Information Security, Information Technology, Engineering, Product Development, Operations, asset owners and other areas involved.
The Information Security area establishes corporate guidelines, coordinates the governance of the process, monitors indicators, supports the management of risks related to vulnerabilities and promotes their continuous improvement.
The areas responsible for the assets must ensure implementation within a time frame compatible with the identified risk.
8. Compliance
This Policy is part of WEG's corporate cybersecurity program and is aligned with the main applicable international standards and best practices. The application of these requirements may
vary according to the type of asset, product, solution, service, market of operation, and the corresponding regulatory context, including:
- ISO/IEC 27001: information security management system and protection of information assets;
- IEC 62443: Cybersecurity requirements for industrial automation and control systems, products, and related processes;
- Cyber Resilience Act (CRA): cybersecurity requirements applicable to products with digital elements marketed in the European Union;
- Network and Information Security Directive 2 (NIS2): requirements for cybersecurity risk management and incident reporting in essential and important entities in the European Union;
- Radio Equipment Directive (RED): cybersecurity requirements applicable to certain radio equipment marketed in the European Union;
- General Data Protection Regulation (GDPR): requirements for the protection of personal data, adoption of security measures, and handling of incidents involving personal data;
- General Law for the Protection of Personal Data (LGPD – Law No. 13,709/2018): requirements applicable to the protection of personal data, the adoption of security measures, and the assessment of incidents and vulnerabilities that may impact personal data, when applicable;
- Other applicable legal, regulatory and contractual requirements.
9. Vulnerability Communication
Vulnerabilities related to WEG products, digital solutions and services can be reported through the channels defined in the Coordinated Vulnerability Disclosure Policy (CVD). Additional information may be obtained through WEG's official channels.
When required by applicable law or regulation, WEG may share information related to vulnerabilities or incidents with competent authorities, regulatory bodies or other legally authorized entities.
10. Updates to this Policy
This Policy may be revised from time to time to reflect changes in legal, regulatory, technological and cybersecurity best practices.
11. Revision History
| Version | Date | Description |
|---|---|---|
| 1.0 | 19/08/2026 | Initial issuance of the Vulnerability Management Policy. |