HB-Therm AG

New standards in cybersecurity: HB-Therm integrates security by design in product development

In close collaboration with bbv, HB-Therm has implemented a pioneering product development. The consistent use of security by design in the new device generation ensures the highest security standards, setting a new benchmark in the industry.

06.01.2025Text: tnt-graphics0 Comments
HB-Therm bbv

“Security by design was a key part of our development strategy from the outset. Thanks to the support of bbv in developing the Thermo-6 series, we were able to expand our market leadership and offer our customers a state-of-the-art product experience.”

Andreas Steiner, Team Leader Software Engineering, HB-Therm AG

HB-Therm AG, based in St. Gallen, Switzerland, is one of the world’s leading manufacturers of temperature control units for the injection moulding process, which is used primarily in plastics processing. HB-Therm has been the epitome of innovative temperature control technology for the highest quality standards since 1967.

The company wanted to set new standards with the new “Thermo-6” generation of temperature control units and faced the challenge of completely overhauling not only the hardware but also the software.

One thing was clear to HB-Therm from the outset: it wanted to not only set the technical standard in the industry but also integrate the highest security standards in order to be armed against potential cyber attacks.

The time-to-market had to be met, while at the same time consistently implementing security by design.

Die Welt der HB-Therm Thermo-6 mit Gate-6
© HB-Therm AG | hb-therm.com

Robust software architecture and security concept with bbv

HB-Therm needed a robust software architecture that integrates state-of-the-art industry communication standards such as OPC UA and guarantees secure processing and storage of data.

bbv supported HB-Therm from the outset in developing the software for the entire Series 6 ecosystem. The focus was on creating a clean system architecture and integrating security by design right from the first architectural diagram. That included:

  • Laying the groundwork: Developing a cloud solution, a gateway and mobile applications (Android and iOS) to control and monitor the temperature control units.
  • Developing a security concept: Documenting the software architecture and creating a detailed data flowchart. Holding workshops lasting several days on risk analysis (STRIDE) and assessment (DREAD) of the identified risks.
  • External review: Commissioning an external penetration test to review security measures before the final release and identify and resolve vulnerabilities.

DREAD and STRIDE

DREAD and STRIDE are methods used to analyse risks in software development. They help to systematically identify, assess and fix security vulnerabilities in order to guarantee a high level of security.

DREAD assesses risks based on:

  • Damage potential
  • Reproducibility
  • Exploitability
  • Affected users
  • Discoverability

STRIDE identifies threats through:

  • Spoofing
  • Tampering
  • Repudiation
  • Information disclosure
  • Denial of service
  • Elevation of privilege

Added value for HB-Therm AG

Long-term security and market leadership: Through the close collaboration and holistic approach of bbv, HB-Therm was able to not only launch the new temperature control units on schedule and securely but to also implement long-term security strategies.

HB-Therm benefits from:

  • Security guarantee: By integrating security by design and carrying out an external penetration test, HB-Therm was able to ensure that the new devices meet the highest security requirements.
  • Improved planning and transparency: The detailed documentation and the risk analyses led to an improved planning and a deeper understanding of the interdependencies within the development infrastructure.
  • Gain in reputation: With a secure product group, HB-Therm was able to strengthen its position as an industry leader and further develop its customers’ confidence. The security measures are advertised as an outstanding feature, which has a positive impact on the brand image.

The collaboration with bbv enabled HB-Therm to successfully meet the challenges of time-to-market and security by design. Through a carefully planned and implemented security strategy, HB-Therm was able to launch Series 6 on schedule and securely, while at the same time creating sustainable added value for its customers.

Our services in the project

Your contact

Roland Achermann

As Head of Business Area at bbv, Roland Achermann is responsible for the field of industry and energy. He has many years of extensive experience in software development. Roland contributes his expertise in the fields of digitalisation and individual software to specific solution portfolios.

Attention!

Sorry, so far we got only content in German for this section.