Silicon Motion is strongly committed to product cybersecurity and takes it as our high priority. A task force was formed to handle the related concerns, and we provide a transparency of responsible vulnerability management, ensuring proper resources to take care of security vulnerabilities and aligned with Cyber Resilience Act (CRA) and ISO/SAE 21434.
The structured approach to identify, assess, and address vulnerabilities helps Silicon Motion timely coordinate internally to handle any security threats.
We continuously monitor vulnerability information from multiple resources and aspects.
We analyze the reported vulnerabilities and prioritize the risk level with appropriate ways, each finding will be evaluated based on exposure and potential impact.
We develop and implement suitable remediations or mitigations controls.
We keep communication open with affected customers and stakeholders.
We review and improve our process continuously to consistently deliver high-quality services.
Our pledge to enhance product cybersecurity, conformance and continuous improvement.
We proactively manage vulnerabilities to protect our customers, products and data with risk-based prioritization and compensating controls.
Our process aligns with CRA and ISO/SAE 21434 to meet regulatory requirements.
We learn, improve and evolve our PSIRT process to address threats effectively, and continuously monitor emerging security risks.
Silicon Motion appreciates reports from multiple resources to guarantee less risk of product cybersecurity. Any potential vulnerabilities you are willing to share with us, please click here to find out more information on how to report a security risk and leave your information regarding contact information, product name with version, description of the potential vulnerability and exploit, CVE or related impact.