About CSIRT

COMPUTER SECURITY AND INCIDENT RESPONSE TEAM

CSIRT - is a computer emergency response team of the State Research Institute of Cyber Protection Technologies, which functions as part of the State Service for Special Communications and Information Protection of Ukraine. The main functional direction of the CSIRT is to counter cyber threats in automated systems and information and communication systems of the State Research and Development Institute of Cyber Security Technologies and energy industry enterprises.

CSIRT is a non-staff structural unit of the State Research and Development Institute of Cyber Security Technologies that interacts with CERT-UA teams, the System for identifying vulnerabilities and responding to cyber incidents and cyber attacks, external organizations and other subjects of the national cyber security system.

The organizational structure of the CSIRT consists of the following subdivisions:

  • Group of analysts;
  • Computer Incident Response Team targeting system resources and switching equipment;
  • Computer incident response team targeting technological equipment (programmable logic controllers (PLCs), automated process control systems (ACS TP)).

The territorial zone of responsibility consists of the western regions of Ukraine, namely: Khmelnytskyi, Rivne, Volyn, Ternopil, Chernivtsi, Ivano-Frankivsk, Lviv and Zakarpattia regions.

 

Tasks of the CSIRT:

  • accumulation and analysis of data on cyber incidents, maintenance of the state registry of cyber incidents;
  • providing owners of cyber protection facilities with practical assistance in preventing, identifying and eliminating the consequences of cyber incidents in relation to these facilities;
  • organization and holding of practical seminars on cyber protection issues for subjects of the national cyber security system and owners of cyber protection objects;
  • preparation and placement on its official website of recommendations on countering modern types of cyber-attacks and cyber-threats;
  • interaction with law enforcement agencies, providing them with timely information about cyber attacks;
  • interaction with foreign and international organizations on cyber incident response issues, in particular within the framework of participation in the FIRST Security Incident Response Teams Forum with payment of annual membership fees;
  • interaction with Ukrainian computer emergency response teams, as well as other enterprises, institutions and organizations, regardless of the form of ownership, that conduct activities related to ensuring the security of cyberspace;
  • processing information received from citizens about cyber incidents regarding cyber protection objects;
  • assistance to state bodies, local self-government bodies, military formations formed in accordance with the law, enterprises, institutions and organizations regardless of the form of ownership, as well as citizens of Ukraine in solving issues of cyber protection and countering cyber threats.