Skip to content

CSIRT (Computer Security Incident Response Team)

Definition

A dedicated team responsible for coordinating the response to confirmed security incidents. The CSIRT manages containment, forensic investigation, communication to stakeholders, and recovery. It may be internal to an organisation or contracted externally. National CSIRTs (such as CERT-In in India or CISA in the US) also provide coordination across sectors.

Full name
Computer Security Incident Response Team
Core functions
Containment, forensic investigation, communication, recovery
Structure
Internal team or external contracted provider
National examples
CERT-In in India, CISA in the US

Common questions

What is the difference between an organisation's own CSIRT and a national CSIRT like CERT-In?+

An organisational CSIRT handles incidents within that single organisation's systems, while a national CSIRT coordinates across sectors, issues advisories, and often serves as a point of contact between affected organisations, law enforcement, and international counterparts during large-scale incidents.

Why does communication to stakeholders count as a core CSIRT function alongside technical response?+

A poorly managed disclosure can cause as much harm as the incident itself, through regulatory penalties, lost trust, or panic, so the CSIRT is typically responsible for coordinating timely, accurate notifications to affected parties, regulators, and leadership alongside the technical containment work.

Related terms

Escalation Path
The predefined chain of notification and decision-making authority that an incident follows as its severity increases. Documented in the IR plan before...
Indicator of Compromise (IoC)
An observable artefact that suggests a system has been involved in a malicious event. Static analysis produces file-based IoCs: cryptographic hashes, embedded...
SOC (Security Operations Centre)
A function providing continuous monitoring, alert triage, and early detection of security events. The SOC is the first tier of response: it...
Tactics, Techniques, and Procedures (TTPs)
A three-level description of adversary behaviour. Tactics are the high-level goals (initial access, persistence, exfiltration). Techniques are the specific methods (spear-phishing, pass-the-hash)....
Threat Actor
An individual or group responsible for a security incident or malicious campaign. Threat actors are categorised by motivation (financial, espionage, hacktivism, destruction)...

Explained in

Your journey to becoming a forensic professional starts here.

Practice with mock tests, learn from structured notes, and get your questions answered by a global forensic community, all in one place.