Report and respond
Report a security issue
Tell us about a vulnerability or security incident affecting a Moorfield system, its control software or firmware, or a PC connected to it. Security reports go to our security contact, not to sales.
How to report
Use the form at the bottom of this page. It prepares an email to for you to check and send from your own email program, so you can attach screenshots, logs or scanner output. If you’d rather not use the form, email that address directly.
Never send passwords, keys or other credentials, even if they’re part of the problem. Tell us they’re affected, and we’ll arrange a safe way to deal with them.
What to include
- The system model and, if you know it, the SO number from the identification plate or your order paperwork
- The software or firmware version, if you know it: from the touchscreen control panel, IntelliDep, or the PC software supplied with the system
- How the system is connected: standalone, on a site network, with internet access, or with a remote access tool installed
- What you saw or found, which part is affected, and for a vulnerability, the steps to reproduce it
- Any effect on the system, the process or your data
- What you have done so far
If a system is being attacked now
Tell us straight away, and answer Yes to “Is anyone actively exploiting this?” so your report is handled first. If it’s safe to do so, disconnect the system, and any PC connected to it, from the network. Follow your local safety procedures before you stop a system mid-process. Include a phone number so we can call you.
What we will do
- Acknowledge your report within one working day.
- Investigate, and tell you whether we can reproduce the issue.
- Keep you updated until the issue is resolved.
- Agree the timing of any public disclosure with you.
- Publish a security advisory once a fix or workaround is available.
- Where the law requires it, report the issue to the relevant cybersecurity authorities.
Scope
In scope: the software and firmware we supply with our systems: touchscreen control panel (HMI) software and the controller firmware behind it, IntelliDep control software, the PC software we supply for data logging and recipe editing, and any control PC as we configure and supply it.
Out of scope:
- Third-party instruments we resell or integrate, such as gauges, power supplies and mass flow controllers. Report those to their manufacturer. If you’re not sure who that is, tell us and we’ll help.
- Findings with no security impact.
- Our website, moorfield.co.uk, and our corporate IT systems.
Recognition
We don’t run a paid bug bounty. If you’d like, we’ll credit you by name in the advisory for the issue you reported.
If you’re not happy with our response
Reply to our acknowledgement email and write “For the attention of the Managing Director” at the top of your message. Please reply rather than starting a new email, so your report stays together. You can also contact your national Computer Security Incident Response Team (CSIRT).
About this policy
This policy describes how we handle security reports. It isn’t a contract, and we may update it. Last updated 29 September 2026.
Report form
Send us a report
When you finish, this page opens a pre-filled email to in your email program. Check it, attach any screenshots or log files, and press send. We acknowledge security reports within one working day.
Your report is ready to send
If your email program didn’t open, copy the subject and report below into a new email to .
- Check the email that has opened.
- Attach any screenshots, log files or scanner output.
- Press Send. We’ll acknowledge it within one working day.
Subject
Report
