Deutschland

Cybersecurity

Since 1987, CompuGroup Medical has pursued its vision of a digitalized healthcare system. Ever since, we have continuously driven the development of innovative technologies to support and improve both the work of healthcare professionals and the lives of citizens.

In the age of digitalization, cybersecurity is a critical success factor. CGM is committed to upholding the highest security standards to comprehensively protect the data of our customers, employees, and the company itself.

Certifications

CGM operates a comprehensive information security management system based on the ISO 2700x series of standards and is certified according to ISO 27001. In addition, we have implemented the C5 standard to address the specific security requirements for cloud services; this certification has also been successfully renewed. Certified data centers as well as clearly defined objectives, processes, and policies support our Group Information Security Policy and ensure a consistently high level of security.

Always vigilant

Our Security Operations Center (SOC) monitors our global networks around the clock using a follow-the-sun model, enabling a rapid response to security-relevant incidents.

Tested Security

Servers, web applications, and endpoint devices are routinely scanned for vulnerabilities. An internal audit team regularly verifies that the required processes are in place and being followed. Top management is continuously and transparently informed about the current security status.

Standardization

Consistent server standards ensure that our systems are uniformly hardened, kept up to date at the software level, and seamlessly integrated into existing maintenance processes. This rigorous cyber hygiene forms the foundation of our security posture.

Comprehensive Training and Awareness

Our employees are the most important line of defense against cyber risks. Mandatory security training across the entire group, along with regular phishing simulations, continuously sharpens security awareness. In addition, we use internal communication channels to provide ongoing updates on current threats and attack vectors, and share relevant knowledge through concise, practical microlearnings.

Vulnerability Management Policy (Bug Bounty)

The security of our solutions is our top priority. We ask that any security vulnerabilities be reported responsibly and in accordance with our Vulnerability Management Policy. Upon receiving a report, we review and remediate the affected vulnerabilities with the highest priority. In addition, we periodically run time-limited bug bounty challenges, specifically inviting security researchers to report vulnerabilities.