Skip to main content
Guidance

Incident management

How to effectively detect, respond to and resolve cyber incidents.

Page 4 of 7

Build: A cyber security incident response team (CSIRT)

iStock.com/lohjinawi
A cyber security incident response team (CSIRT) consists of the people who will handle the response to an incident. It may include both internal and external teams and may differ based on the nature of the incident.

The core team will usually be IT or Cyber Security staff. The extended team may include other capabilities, such as PR, HR and legal. A full list is described in the sub-sections below.

The team does not have to be dedicated to IR full time. It is more cost effective to have a 'virtual' CSIRT, pulled together when needed, from people who have other day jobs. 

Ad-hoc CSIRT teams

If this approach is to be adopted, it is vitally important that the people critical to the CSIRT are able to prioritise an incident over their day-to-day work, when necessary.


Assuring availability

Always provide for 'deputies' - people who will cover if a critical person or persons are unavailable.

This applies to all aspects of the response team and any suppliers if they only have one key individual who can carry out certain tasks.


Note on suppliers

You should review all suppliers to determine who you may require support from during an incident.

This could be anything from infrastructure and cloud hosting to external PR firms. Work with suppliers to ensure they will be able to support when needed. Even in-hours support may be limited from a supplier, depending on your contract.



Reviewed

Version

1.0