GlossarySOC and monitoring

CSIRT

Short answer

A CSIRT (Computer Security Incident Response Team) is a team that receives, analyses and coordinates the response to cybersecurity incidents. It can serve a single organisation, a sector or a whole country. National CSIRTs also share alerts and support organisations during serious incidents.

Types of CSIRT

Internal CSIRTs handle incidents within one organisation. Sector CSIRTs serve a specific industry, such as finance or health. National CSIRTs coordinate at country level, publish alerts and receive incident notifications. Vendor CSIRTs, often called PSIRTs, handle vulnerabilities in a company's own products. The term CERT is also widely used for the same kind of team.

CSIRTs in Spain

Spain has three national reference CSIRTs. INCIBE-CERT, part of INCIBE, serves citizens and private companies. CCN-CERT, part of the CCN, serves the public sector and is the reference for the ENS. ESPDEF-CERT serves the defence sector. Some autonomous communities, such as Catalonia and Valencia, have their own as well.

CSIRTs and regulation

NIS2 requires each member state to designate CSIRTs, which receive notifications of significant incidents from entities in scope and work together through the European CSIRTs network. Under the Cyber Resilience Act, manufacturers notify actively exploited vulnerabilities to the CSIRT designated as coordinator and to ENISA.

CSIRT and SOC

A SOC monitors and detects incidents; a CSIRT leads the incident response once an incident is confirmed. In smaller organisations the same people often do both, supported by external providers, and the incident response plan should state who plays the CSIRT role and how to contact the national CSIRT.

Related terms

Keep reading on this topic

Continuous monitoring and response: EDR, SIEM, SOC operations, detection engineering and incident handling.

Go to the topic hub