Deutschland

Cybersecurity

CompuGroup Medical has been pursuing the vision of a digitalised healthcare system since 1987. Since then, we have been continuously driving the development of innovative technologies to support and improve both the work of healthcare professionals and the lives of citizens. 

In the age of digitalisation, cyber security plays a crucial role. At CGM, we are committed to maintaining the highest security standards in order to protect the data of our customers, employees and our company in the best possible way.

Certifications

CGM operates a comprehensive information security management system based on the ISO 2700x standards. In addition, we have implemented the C5 standard to specifically fulfil the security requirements for cloud services. Our certified data centres and a large number of defined objectives, processes and guidelines support the Group Information Security Policy and ensure robust information security.

Always vigilant

Our Security Operations Centre (SOC) operates around the clock and uses a follow-the-sun model to continuously monitor our global networks and respond quickly to incidents.

Proven safety

Our servers, web applications and end devices are routinely scanned for vulnerabilities. Our internal audit team regularly checks whether the necessary processes are in place and are being adhered to. Top management is regularly and transparently informed about the status of security. 

Standardisation

We consistently use uniform server standards to ensure that all our servers have hardened configurations, are always up to date with the latest software and can be seamlessly integrated into all maintenance processes. This cyber hygiene forms the basis for maximum security. 

Comprehensive training and awareness-raising

Our employees are our best defense. We organise mandatory security training for all Group employees. Frequent training sessions, including regular phishing simulations, also raise employee awareness. 

Vulnerability Management Policy (Bug Bounty)

The security of our solutions and products is our top priority. We therefore ask you to report any vulnerabilities responsibly and in accordance with our Vulnerability Management Policy. Upon receipt, we will review and fix the reported vulnerabilities as quickly as possible.