--- title: "IT Security" slug: "it-security-en" updated: 2026-08-27T07:28:03Z published: 2026-08-27T07:28:10Z canonical: "docs.insys-icom.com/it-security-en" --- > ## Documentation Index > Fetch the complete documentation index at: https://docs.insys-icom.com/llms.txt > Use this file to discover all available pages before exploring further. # IT Security Use this overview as support when creating an IT security concept for a planned application. It does not replace the other publications that are available for the selected router. > [!WARNING] > You are responsible for your security! > > Verify all information regarding IT security of the own application due to the individual nature of each single application. Consult our [INSYS Product Security Whitepaper](https://public.centerdevice.de/921ae656-058b-486b-b46b-33520a4930c5) to find out which technical and organisational measures (TOM) we take to maintain IT security in the company and in the products of INSYS icom. You can also see the deadlines for providing our products and services with security-critical updates. Another important publications are: - [IT security at INSYS icom](https://www.insys-icom.com/en/products/it-security/) (company website) - [Quick Installation Guide](/kb/docs/en/quick-installation-guide-en) - [Installation and User Manual](/kb/docs/en/routers-and-gateways) - Inline and Online Help in the web interface of the router - [Configuration Guides](/kb/docs/en/configuration-guides-icom-os) ## 1. Application concept designed to IT security Consider already during conceptual design of the application [these questions regarding IT security](/kb/docs/en/it-security-hardening-the-most-important-issues-regarding-it-security-en), which have been identified by the [BSI](https://www.allianz-fuer-cybersicherheit.de/SharedDocs/Downloads/Webs/ACS/DE/BSI-CS/BSI-CS_005.html) as the top ten of dangerous threads. ## 2. IT security functions of the router and default settings Overview of different [security functions of the router and its default settings](/kb/docs/en/it-security-security-functions-of-the-routers-en) ## 3. Guide for securing the router Use this [guide for securing the router](/kb/docs/en/it-security-hardening-the-router-en) to increase the IT security of your router. Depending on the nature of the application, other measures might be necessary. The concept phase of the application should be finished at this time already. These measures make no claim to be complete. If your application has **particularly high requirements to IT security**, e.g. for the use in critical infrastructure, use the [Secure Configuration Guide](/kb/docs/en/it-security-secure-configuration-guide-en). This demonstrates you how to configure the device **in compliance with the accelerated security certification of the German Federal Office for Information Security (BSI)**. ## 4. IT security checklist Use this [checklist](/kb/docs/en/it-security-checklist-en) to protect the application. ## 5. KRITIS requirements Critical infrastructures (as per BSI KritisV) are organizational and physical structures and facilities of such vital importance to a nation’s society and economy that their failure or degradation would result in sustained supply shortages, significant disruption of public safety and security, or other dramatic consequences. INSYS icom has many years of experience in CI (KRITIS) applications and thousands of devices in use in critical infrastructures, such as energy, health, information technology/telecommunications, media/culture, water and food. Do you need helpful material for an audit by the BSI or other IT security authority? Refer to our information regarding [IT Security](/kb/docs/en/it-security-en). The [Secure Configuration Guide](/kb/docs/en/it-security-secure-configuration-guide-en) demonstrates you how to configure the device in compliance with the accelerated security certification of the German Federal Office for Information Security (BSI). ## 6. Interfaces The INSYS routers provide different types of interfaces, physical interfaces, communication interfaces, user interfaces and service interfaces. The existing interfaces differ depending on type and variant of the router. The physical interfaces contain the digital and analogue inputs and outputs of the router. The communication interfaces contain the Ethernet switch, the modems for LTE, DSL and glass fiber as well as the serial interfaces. The web interface and access to the command line (CLI) or the REST interface are available as user interfaces. Moreover, it is possible to dispatch messages via SMS, e-mail, SNMP or MCIP as well as receive and evaluate them ## 7. Maintaining the security A secure configured router requires regular actions for maintaining the security. These include: - Regular certificate updates and maintaining certificate revocation lists (CRLs) - manually or via EST - Regular update of the router with the latest firmware - using the [icom Router Management](https://www.insys-icom.com/en/products/managed-services/device-management/) - by manual updates (proceed as described in this [Configuration Guide](/kb/docs/en/updating-a-router-manually-en) and verify the integrity of the firmware) - Subscribe to our [Release Note Newsletter](https://icom-os.releasenotes.io/) to be informed about the release of new firmware - Regular review of our [Security Advisories](https://www.insys-icom.com/en/support/security-advisories/), subscribe to our [Security Newsletter](https://www.insys-icom.com/en/support/security-advisories/registration-security-notifications/) for this - Regular review of the used cryptographic methods for up-to-dateness and use of more up-to-date methods in case of weakening security; recommended reference of the BSI for this: [TR-02102](https://www.bsi.bund.de/EN/Themen/Unternehmen-und-Organisationen/Standards-und-Zertifizierung/Technische-Richtlinien/TR-nach-Thema-sortiert/tr02102/tr02102_node.html) - Regular review of the relevant log files for irregularities in order to detect them at an early stage - Setting up messages (via SMS, E-Mail, SNMP trap or MCIP) upon IT security-relevant events such as login attempts, configuration changes, changes at the switch, etc. to alert users in due time ## 8. Safe decommissioning After using the router in a safety-critical application, delete all data on it. If you only [reset the device to default settings](/kb/docs/en/resetting-to-defaults-en), the data will not be completely deleted, but only the allocation table, so that the data could be recovered with appropriate effort and tools if there is physical access to the router. Therefore, a router reset to default settings, must not be sold or passed on. For this reason, use the function for **Safe decommissioning** of the router (available from icom OS version 6.1). This will also delete the complete firmware from the router. Only a rudimentary rescue system will remain on the router, which can be accessed via the address [**http://192.168.1.1**](http://192.168.1.1) and enables the router to be restored. 1. Open for this the user interface of the router: [https://insys.icom](https://insys.icom) and click for this in the *Administration* → *Reset / Restart* menu on the *Decommissioning* slider and then on the NOW SAFELY TAKE DECOMMISSIONING button ## 9. Secure disposal Please note the following points before disposing of a router: - Safely remove the router from its operating environment and do not leave it unattended while it still contains secrets. To remove all secrets and potentially confidential information, first use the function for **Safe decommissioning** of the router (see previous section). - Never sell a router for which a **Safe decommissioning** has not been completed. - Pass the router on to a certified disposal company that also meets the requirements for data protection and data security. ## 10. FAQ The [FAQ](/kb/docs/en/it-security-faqs-en) contain frequently asked questions and their answers. ## 11. Reporting security vulnerabilities If you suspect that one of our products has a security vulnerability, please report your suspicion to us using the form provided on our page [Security Advisories](https://www.insys-icom.com/en/support/security-advisories/) page. Standard IP address: https://192.168.1.1; login depending on configuration; default for earlier firmware versions: *User name*: **insys**, *Password*: **icom**