Risk Context
Overview
This reference consolidates the Risk Context and Product Security Information for the hi human interface software product and supported hi Hardware Panels. It states the intended purpose, reasonably foreseeable use, foreseeable misuse, security environment, residual risks, lifetime measures, and vulnerability-reporting process.
This page is not a certification claim, a site threat model, or a substitute for the approved project network design.
Manufacturer: Riedel Communications GmbH, Uellendahler Straße 353, 42109 Wuppertal, Germany.
Intended Purpose
The hi system is a client-server control layer for supported media, production, and facility systems. Trained operators use the hi web interface or supported Hardware Panels to:
-
Route signals between configured Sources and Destinations.
-
Control supported device parameters.
-
Monitor device and system state.
-
Propagate Tally and labels through configured Signal Paths.
-
Recall Snapshots and Presets.
-
Run configured Rules and operational workflows.
-
Integrate supported third-party broadcast, media, production, and facility systems.
Authorized technical personnel configure, administer, maintain, back up, restore, and upgrade the hi installation. The hi system does not replace the controlled equipment or its safety functions.
Supported hi Hardware Panels extend the configured hi workflows:
-
hiPush provides labeled LCD buttons and rotary controls for configured operator workflows.
-
hiContact connects 16 opto-isolated inputs and 16 relay contact outputs to configured Rules and workflows.
-
hiDot provides one multifunctional touchscreen-rotary control for Snapshot recall, Parameter Control, Rule triggers, and cue-light style indication.
Reasonably Foreseeable Use
Reasonably foreseeable use includes:
-
Deploying the hi system in broadcast studios, outside-broadcast vehicles, event venues, theaters, arenas, control rooms, and comparable commercial production environments.
-
Installing the hi server on a customer-provided and customer-managed Linux host.
-
Operating the hi system on a customer-controlled production or facility network.
-
Using a firewalled private LAN or an air-gapped site where required by the project design.
-
Allowing trained operators, engineers, production personnel, and administrators to use the permissions assigned to their roles.
-
Connecting supported Hardware Panels to the approved production or management network.
-
Adding supported third-party integrations and configuring Nodes through authorized administrators.
-
Using approved secure remote-access methods when the site design permits remote administration.
-
Allowing multiple authorized users and connected Hardware Panels to operate configured workflows concurrently.
-
Installing supported software and firmware updates through the procedure supplied for the installation.
These uses remain consistent with the product's functionality and expected operation.
Intended Security Environment
Deploy the hi system on a trusted and managed customer network. Do not treat the hi web interface, identity services, Hardware Panel commissioning interfaces, or control-plane services as public-internet services.
The customer is responsible for the host operating system, network design, firewall policy, certificates, identity policy, physical access, patching, monitoring, backups, and lifecycle. Supported operating systems depend on the installed hi release.
Warning
Cluster maintenance and infrastructure recovery require specialist support. Contact Riedel Customer Success before intervention. A cluster malfunction can cause critical service impacts, database-integrity failures, and data loss. Follow A Multi-Server Installation Reports a Server or Service Fault for safe checks and support guidance.
For more information, see: System Requirements.
For more information, see: Security Posture.
For more information, see: Network and Firewall Ports.
Foreseeable Misuse
Warning
The hi system and its Hardware Panels are not safety-rated controls. Do not use them for life-preserving functions, emergency shutdowns, safety interlocks, or other functions where failure could cause injury, loss of life, or significant environmental or industrial damage.
The following uses fall outside the intended purpose and can increase cybersecurity, operational, safety, environmental, or industrial risk:
-
Deploying the hi system or a Hardware Panel as a safety-critical, life-preserving, emergency, or other high-risk control.
-
Using hiContact relay outputs as a safety interlock.
-
Exposing the hi web interface, identity services, media interfaces, management interfaces, or commissioning interfaces directly to the public internet.
-
Connecting the hi system to untrusted, public, unmanaged, compromised, or inadequately secured networks.
-
Using administration workstations or engineering tools that are not protected against unauthorized access or malware.
-
Leaving supplied administrator credentials unchanged before routine operation.
-
Using shared, weak, or improperly managed credentials.
-
Granting administrative privileges, access rights, or control rights without an authorization process.
-
Disabling or bypassing available security controls.
-
Installing unsupported, modified, or unauthorized software or firmware.
-
Connecting unsupported, unapproved, insecure, or improperly maintained third-party systems or peripherals.
-
Using online license activation from a network that must remain air-gapped.
-
Leaving a factory default Hardware Panel address in service after commissioning.
-
Allowing unauthorized physical access to the server, Hardware Panels, their interfaces, or associated network infrastructure.
-
Operating the installation outside the documented configuration, environmental limits, or project guidance.
Caution
Such use falls outside the intended purpose of the product and may increase cybersecurity risks, operational disruption, and unauthorized access to control services.
Third-Party Integrations
Device integrations are opt-in. An administrator adds a Node, and some integrations require a license. Riedel does not define the security properties of a third-party control protocol.
Where a protocol provides authentication or encryption, the hi system uses that option when the integration supports it and the Node is configured for it. Where a protocol does not provide authentication or encryption, use of that device is a site decision. Isolate those links according to the approved network design.
For more information, see: Getting Started with Integrations.
Hardware-Specific Boundaries
hiPush
Commission hiPush on the approved production or management network and point it at the hi server. A connected panel requires hiGlue and one hiUser session. Do not expose the commissioning interface to untrusted hosts or use the panel as a public-internet appliance.
For more information, see: hiPush Series.
hiContact
Connect contact closures and relays within their published electrical ratings. hiContact requires hiGlue and does not consume a hiUser session. It is not a safety-rated programmable logic controller or safety interlock.
For more information, see: hiContact Series.
hiDot
Install hiDot on the approved production or management network and power it through the documented PoE connection. A connected panel requires hiGlue and one hiUser session. Do not use USB from an untrusted computer or treat the control as a safety function.
For more information, see: hiDot Series.
Residual Risks to Plan For
Treat the following as residual risks for a commissioned installation, not as secure defaults:
-
Transport security depends on the approved project design. Do not assume that every connection uses HTTPS or an encrypted southbound protocol.
-
Host operating-system security, hardening, patching, and lifecycle remain customer responsibilities.
-
Third-party protocol security remains subject to the connected device and protocol.
-
Configuration Backups can contain users, Topology, and other operational information.
-
A restore, restart, shutdown, or power operation can interrupt routing control, Parameter Control, Tally, and Hardware Panel connections.
-
Hardware Panel traffic and commissioning interfaces require network isolation from untrusted hosts.
Commissioning and Lifetime Measures
-
Deploy only on the approved production or management network.
-
Change supplied administrator credentials before routine operation.
-
Apply least-privilege user and administrator access.
-
Prefer deny-by-default outbound connectivity when manufacturer licensing or update services must not be used.
-
Install a trusted certificate chain when HTTPS is enabled.
-
Back up the installation according to the site procedure and protect the backup files.
-
Install the hi system and Hardware Panel firmware only through approved procedures.
-
Remove users and configuration before decommissioning, then retire the host and hardware according to site policy.
-
Dispose of Hardware Panels according to applicable WEEE requirements.
Riedel provides technical security support for each covered hi system release and hi hardware product for 5 years from its placing on the Union market. The calendar end date follows the applicable placing date.
For more information, see: Commissioning.
For more information, see: Backups.
For more information, see: Release Notes.
Reporting a Security Vulnerability
Riedel Communications is committed to the security of its products. If you believe that you have identified a security vulnerability in this product, report it through the Riedel technical support portal.
The portal explains how to submit a report, which details to include, and what to expect after a report is received. Report suspected vulnerabilities in good faith and allow Riedel a reasonable opportunity to assess and address the issue before public disclosure.
The same portal lists known and publicly disclosed vulnerabilities affecting Riedel products, together with available guidance, workarounds, and security updates. Check the portal periodically and subscribe to available notifications for relevant equipment.
Constraints
-
This page makes no claim of certification against a named framework.
-
A Declaration of Conformity is a company legal publication and applies only to the identified product.
-
Site identity policy, firewall rules, retention values, and threat acceptance are not public defaults.
-
Firmware package numbers and update channels are defined by the approved project procedure and Firmware History.