BlackDogs Security · Spain · BD-CSIRT

BlackDogs CSIRT

Computer Security Incident Response Team

BlackDogs CSIRT is the incident response and coordination team operated by BlackDogs Security. The team supports the detection, analysis, containment, coordination and response of cybersecurity incidents affecting its constituency.

Mission

Prevention, analysis, containment and coordination.

The mission of the BlackDogs CSIRT teams is to support the prevention, detection, analysis, containment and coordination of cybersecurity incidents affecting the BlackDogs group companies and their constituencies.

The team facilitates communication between affected parties, security providers, researchers and other CSIRTs when coordination is required.

Constituency

Who the team serves.

  • BlackDogs Security's own infrastructure, systems and services.
  • Organizations with active agreements that explicitly include incident response, security monitoring, MDR, vSOC, DFIR or CSIRT-related capabilities within the agreed scope.
  • Other organizations may contact BlackDogs CSIRT regarding incidents or vulnerabilities involving BlackDogs infrastructure or customers.

Response capabilities, authority and service levels may differ depending on the applicable agreement with each constituent. Organizations purchasing other BlackDogs Security services are not automatically considered constituents of BlackDogs CSIRT unless incident response or coordination capabilities are included within the applicable agreement.

Authority

Mandate and limits of action.

BlackDogs CSIRT operates under the authority granted by BlackDogs Security and, where applicable, by contractual agreements established with its constituents.

Depending on the agreed service model, BlackDogs CSIRT may perform investigation, containment or remediation actions directly, or provide recommendations requiring approval from the affected organization.

The specific authority applicable to each constituent is defined contractually and may range from advisory and coordination-only functions to pre-authorized containment and remediation actions.

BlackDogs CSIRT does not perform intrusive actions against third-party systems without appropriate authorization.

Scope of work

CSIRT Services

01

Incident Triage

Initial assessment, classification and prioritization of reported security incidents.

02

Incident Analysis

Technical investigation of indicators, logs, endpoint activity, network events and suspicious artifacts.

03

Incident Response

Support for containment, eradication, remediation and recovery activities.

04

Incident Coordination

Coordination between affected organizations, service providers, security vendors and external CSIRTs.

05

Post-Incident Review

Analysis of significant incidents to identify root causes, lessons learned, control improvements and opportunities to improve detection and response capabilities.

06

Digital Forensics

Forensic acquisition and analysis when required as part of incident response.

07

Malware Analysis

Static and dynamic analysis of malicious or suspicious software.

08

Threat Intelligence

Enrichment and contextualization of indicators, campaigns and adversary activity.

09

Vulnerability Coordination

Coordination of vulnerabilities affecting BlackDogs infrastructure, services or constituency.

10

Threat Hunting

Proactive investigation based on indicators, hypotheses and adversary techniques.

Incident reporting

Report a Security Incident

Contact BlackDogs CSIRT regarding:

  • Security incidents
  • Suspected compromises
  • Malware
  • Phishing campaigns
  • Credential compromise
  • Unauthorized access
  • Vulnerabilities involving BlackDogs infrastructure
  • Incidents involving BlackDogs-managed environments
  • Requests for incident coordination
Telephone +34 930 18 66 17
PGP fingerprint 05D9 A242 CE24 E6D0 13F2  A060 881C 5CE5 806E E9B3
PGP public key csirt-blackdogs.asc
Operating hours Mon–Fri, 09:00–18:00 Europe/Madrid
Out of hours On-call escalation by agreement
Languages English · Spanish · Catalan

Do not send sensitive evidence, credentials or confidential material through unencrypted email.

Report content

Information to include in a report

When reporting an incident, include when possible:

  • Organization and contact details
  • Date and time of detection
  • Affected systems
  • Description of observed activity
  • Indicators of compromise
  • Relevant logs or evidence
  • Actions already performed
  • Impact or suspected impact
  • Preferred secure communication channel

Please avoid sending passwords, private keys or unnecessary personal data.

Triage

Incident Prioritization

Incidents are prioritized according to business impact, affected assets, scope, active exploitation, potential lateral movement, data exposure, operational disruption and regulatory implications.

Critical

Active exploitation, widespread operational disruption or confirmed exposure of sensitive data.

Target initial response4 hours

High

Confirmed compromise with contained scope, or significant risk of escalation or lateral movement.

Target initial response1 business day

Medium

Suspicious activity requiring investigation, with limited impact on operations or data.

Target initial response2 business days

Low

Isolated events, informational reports or activity without observable impact.

Target initial response5 business days

These are target times to acknowledge a report and begin triage, not resolution times. Critical incidents are handled 24x7 for constituents whose agreement provides for it; the remaining targets apply during the operating hours stated above. Where a specific agreement sets different service levels, that agreement prevails.

Confidentiality

Information Handling

BlackDogs CSIRT handles incident information on a need-to-know basis and applies appropriate technical and organizational safeguards to protect sensitive information.

Information received and shared is classified using the Traffic Light Protocol (TLP) 2.0. Reporters are encouraged to apply an appropriate designation when sharing information. Where none is provided, BlackDogs CSIRT determines the appropriate handling and disclosure restrictions based on the sensitivity and context of the information received.

  • TLP:CLEAR
  • TLP:GREEN
  • TLP:AMBER
  • TLP:AMBER+STRICT
  • TLP:RED

Researchers

Vulnerability Disclosure

Security researchers who identify a vulnerability affecting BlackDogs Security infrastructure or services may report it to BlackDogs CSIRT at [email protected]

We encourage responsible and coordinated disclosure and request that researchers provide sufficient time for investigation and remediation before public disclosure.

Machine-readable contact information is published at /.well-known/security.txt in accordance with RFC 9116.

Read the Coordinated Vulnerability Disclosure Policy

Cooperation

Working with other teams.

BlackDogs CSIRT supports cooperation and information exchange with other CSIRTs, CERTs, security vendors, researchers, service providers and relevant authorities when required for effective incident coordination.

Information sharing is performed according to applicable confidentiality requirements, contractual obligations and information classification.

Operating model

Distributed / Virtual CSIRT

BlackDogs CSIRT operates as a distributed security response team supported by centralized security platforms and controlled remote access mechanisms.

Team members use managed systems and secure access controls to operate the incident response environment.

Separation of functions

CSIRT and vSOC

BlackDogs CSIRT may use the capabilities of the BlackDogs vSOC, DFIR and Threat Intelligence practices, but operates as a distinct function.

BlackDogs vSOC

Continuous security monitoring, detection and operational security services.

BlackDogs CSIRT

Incident response, coordination, investigation and crisis management.

  1. vSOCContinuous monitoring and detection engineering
  2. Detection / AlertQualified signal requiring handling
  3. BlackDogs CSIRTTriage, ownership and incident coordination
  4. InvestigationScoping, timeline and root cause analysis
  5. Containment / CoordinationIsolation, eradication and stakeholder communication
  6. DFIR / Threat IntelligenceForensic acquisition, malware and adversary analysis
  7. Recovery / Lessons LearnedRestoration, reporting and preventive improvements

Team record

CSIRT Information

BlackDogs operates two separate incident response teams, one per group company. Each holds its own mandate, constituency and line of authority, and each publishes its own team description following the RFC 2350 structure.

BlackDogs CSIRT (BD-CSIRT) is operated by BlackDogs Security, S.L. from Barcelona and serves constituents in Spain and the rest of Europe.

BlackDogs CSIRT Andorra (BD-CSIRT-AD) is operated by BlackDogs Security Andorra, S.L. from Andorra la Vella and serves constituents established in the Principality of Andorra, coordinating with CSIRT-AD, the national reference team, where the nature of the incident makes that appropriate.

Both teams share the contact address and the PGP key published on this page.

RFC 2350 — BlackDogs CSIRT

RFC 2350 — BlackDogs CSIRT Andorra

Team names
BlackDogs CSIRT · BlackDogs CSIRT Andorra
Short names
BD-CSIRT · BD-CSIRT-AD
Host organizations
BlackDogs Security, S.L. · BlackDogs Security Andorra, S.L.
Team countries
Spain · Andorra
Operational coverage
Spain and Europe · Principality of Andorra
Team type
Commercial / Service Provider CSIRT
Operating model
Distributed / Virtual
Primary contact
[email protected]
Telephone
+34 930 18 66 17
Website
https://blackdogs.io/csirt
PGP key ID
0x881C5CE5806EE9B3
External recognitions
None currently claimed