Incident Triage
Initial assessment, classification and prioritization of reported security incidents.
BlackDogs Security · Spain · BD-CSIRT
Computer Security Incident Response Team
BlackDogs CSIRT is the incident response and coordination team operated by BlackDogs Security. The team supports the detection, analysis, containment, coordination and response of cybersecurity incidents affecting its constituency.
Mission
The mission of the BlackDogs CSIRT teams is to support the prevention, detection, analysis, containment and coordination of cybersecurity incidents affecting the BlackDogs group companies and their constituencies.
The team facilitates communication between affected parties, security providers, researchers and other CSIRTs when coordination is required.
Constituency
Response capabilities, authority and service levels may differ depending on the applicable agreement with each constituent. Organizations purchasing other BlackDogs Security services are not automatically considered constituents of BlackDogs CSIRT unless incident response or coordination capabilities are included within the applicable agreement.
Authority
BlackDogs CSIRT operates under the authority granted by BlackDogs Security and, where applicable, by contractual agreements established with its constituents.
Depending on the agreed service model, BlackDogs CSIRT may perform investigation, containment or remediation actions directly, or provide recommendations requiring approval from the affected organization.
The specific authority applicable to each constituent is defined contractually and may range from advisory and coordination-only functions to pre-authorized containment and remediation actions.
BlackDogs CSIRT does not perform intrusive actions against third-party systems without appropriate authorization.
Scope of work
Initial assessment, classification and prioritization of reported security incidents.
Technical investigation of indicators, logs, endpoint activity, network events and suspicious artifacts.
Support for containment, eradication, remediation and recovery activities.
Coordination between affected organizations, service providers, security vendors and external CSIRTs.
Analysis of significant incidents to identify root causes, lessons learned, control improvements and opportunities to improve detection and response capabilities.
Forensic acquisition and analysis when required as part of incident response.
Static and dynamic analysis of malicious or suspicious software.
Enrichment and contextualization of indicators, campaigns and adversary activity.
Coordination of vulnerabilities affecting BlackDogs infrastructure, services or constituency.
Proactive investigation based on indicators, hypotheses and adversary techniques.
Incident reporting
Contact BlackDogs CSIRT regarding:
05D9 A242 CE24 E6D0 13F2 A060 881C 5CE5 806E E9B3
Do not send sensitive evidence, credentials or confidential material through unencrypted email.
Report content
When reporting an incident, include when possible:
Please avoid sending passwords, private keys or unnecessary personal data.
Triage
Incidents are prioritized according to business impact, affected assets, scope, active exploitation, potential lateral movement, data exposure, operational disruption and regulatory implications.
Active exploitation, widespread operational disruption or confirmed exposure of sensitive data.
Target initial response4 hours
Confirmed compromise with contained scope, or significant risk of escalation or lateral movement.
Target initial response1 business day
Suspicious activity requiring investigation, with limited impact on operations or data.
Target initial response2 business days
Isolated events, informational reports or activity without observable impact.
Target initial response5 business days
These are target times to acknowledge a report and begin triage, not resolution times. Critical incidents are handled 24x7 for constituents whose agreement provides for it; the remaining targets apply during the operating hours stated above. Where a specific agreement sets different service levels, that agreement prevails.
Confidentiality
BlackDogs CSIRT handles incident information on a need-to-know basis and applies appropriate technical and organizational safeguards to protect sensitive information.
Information received and shared is classified using the Traffic Light Protocol (TLP) 2.0. Reporters are encouraged to apply an appropriate designation when sharing information. Where none is provided, BlackDogs CSIRT determines the appropriate handling and disclosure restrictions based on the sensitivity and context of the information received.
Researchers
Security researchers who identify a vulnerability affecting BlackDogs Security infrastructure or services may report it to BlackDogs CSIRT at [email protected]
We encourage responsible and coordinated disclosure and request that researchers provide sufficient time for investigation and remediation before public disclosure.
Machine-readable contact information is published at /.well-known/security.txt in accordance with RFC 9116.
Cooperation
BlackDogs CSIRT supports cooperation and information exchange with other CSIRTs, CERTs, security vendors, researchers, service providers and relevant authorities when required for effective incident coordination.
Information sharing is performed according to applicable confidentiality requirements, contractual obligations and information classification.
Operating model
BlackDogs CSIRT operates as a distributed security response team supported by centralized security platforms and controlled remote access mechanisms.
Team members use managed systems and secure access controls to operate the incident response environment.
Separation of functions
BlackDogs CSIRT may use the capabilities of the BlackDogs vSOC, DFIR and Threat Intelligence practices, but operates as a distinct function.
Continuous security monitoring, detection and operational security services.
Incident response, coordination, investigation and crisis management.
Team record
BlackDogs operates two separate incident response teams, one per group company. Each holds its own mandate, constituency and line of authority, and each publishes its own team description following the RFC 2350 structure.
BlackDogs CSIRT (BD-CSIRT) is operated by BlackDogs Security, S.L. from Barcelona and serves constituents in Spain and the rest of Europe.
BlackDogs CSIRT Andorra (BD-CSIRT-AD) is operated by BlackDogs Security Andorra, S.L. from Andorra la Vella and serves constituents established in the Principality of Andorra, coordinating with CSIRT-AD, the national reference team, where the nature of the incident makes that appropriate.
Both teams share the contact address and the PGP key published on this page.