A Mission to Save and Improve Lives

Defending the
defenders

The CSIRTs answering the call when ransomware hits a hospital, when a power grid is targeted, when an election system is attacked. They don’t get to choose when the call comes in. Team Cymru’s CSIRT Assistance Program is our standing partnership with the national, regional, and sector incident response teams holding that line. We share PureSignal™ threat intelligence with them, region-tuned, so when the alert fires they’re already responding.

By the Numbers

25

YRS

Threat Intelligence Operations

PURE

Signal™ Intelligence Shared

10

Threat Intelligence Categories

STANDING

Partnership Commitment to Every CSIRT

What's at Stake

When a CSIRT loses an hour, somebody else loses a lot more.

CSIRT work is the closest cybersecurity ever gets to first responders. The teams on the receiving end of nation-state activity, ransomware against hospitals, attacks on water systems, election interference, and supply chain compromises. The CSIRTs Team Cymru partners with don’t defend abstract networks. They defend the systems people depend on to live their lives.That’s the work we’ve committed to support, with no invoice attached and no expiration on the partnership, because the consequences of getting it wrong are not measured in downtime.

When the alert fires

Hospitals stay open.

Ransomware on a healthcare network is the difference between scheduled surgery and a postponed surgery, sometimes worse. CSIRTs that respond fast keep patients in care.

When the grid is targeted

Power stays on.

Critical infrastructure attacks aren’t hypothetical. CSIRTs coordinating across sectors are why outages get measured in minutes instead of weeks.

When elections are attacked

Trust holds.

Information operations and infrastructure intrusion against election systems happen every cycle. National CSIRTs are the people on the wall who don’t get to call in sick.

When a supply chain breaks

Cascades get contained.

One compromised vendor can ripple into thousands of downstream systems. CSIRTs sharing intelligence early are why the ripple becomes a contained incident, not a crisis.

WHAT IS CSIRT AP

A standing partnership with the CSIRTs holding the line.

The CSIRT Assistance Program (CAP) is Team Cymru’s standing partnership with the world’s national, regional, and sector incident response teams. Underwritten by us. Ongoing. Region-tuned to what’s hitting the ground where you defend. Every CSIRT we partner with gets the same intelligence we use ourselves, so they can act on it before  incident lands.

01

Pure Signal™ Intelligence Shared

The same threat intelligence Team Cymruuses internally. CSIRTs in our programreceive feeds across bots, controllers, brute-force, darknet, honeypot, open resolvers, phishing, proxies, scanners, and spam, , tuned to what we’re seeing in their region.

02

All CSIRTs Eligible

National, regional, and sector-specific CSIRTs. Newly formed CSIRTs especially, where the program often delivers immediate operational benefit. Eligibility starts with ashort Memorandum of Understanding outlining program terms.

03

A standing commitment.

No invoice. No premium tier. No usage caps. The CSIRT Assistance Program is operated by Team Cymru as part of our mission to save and improve lives. Our position is that access to threat intelligence should never be the thing slowing a CSIRT down, so we carry that cost ourselves.

Program Detail

CSIRT Assistance Program. The standing partnership.

01

Threat Intelligence Partnership

CSIRT AP · The Program

A direct partnership between Team Cymru and your CSIRT. We share Pure Signal™ threat intelligence underwritten by us, tuned to what we’re observing in your region, across the threat categories that matter most for incident response. Partnership begins with a short Memorandum of Understanding and continues for as long as the program serves your team. No subscription. No quotas. No commercial relationship behind the data. The exchange is partnership, and we carry it.

Program OUTCOMES

  • Receive Pure Signal™ intelligence across 10 threat categories, region-tuned
  • See what Team Cymru sees in your region, before the next incident lands
  • Access ongoing partnership support, not one-time data drops
  • Coordinate with Team Cymru’s analyst team during active incidents
  • Strengthen national and regional incident response capability through a standing Team Cymru partnership

ELIGIBLE CSIRT TYPES

National CSIRTs
Regional CSIRTs
Sector-Specific CSIRTs
Newly Formed CSIRTs
Government CSIRTs

Why CSIRT AP

We don’t sell intelligence to CSIRTs.
We partner with them.

Team Cymru’s mission is to save and improve lives. That’s not a marketing line, it’s the work. The CSIRTs we partner with are the people standing between attackers and the systems we all rely on. So we share what we see with them, underwritten by us, and we’ve been doing it for over a decade. Because when a national CSIRT moves faster, the consequences ripple outward in the right direction.

Our Promise

The CSIRTs we partner with don’t defend abstract networks. They defend the systems people live their lives on. Sharing our intelligence with them is the most important work we do.”

Team Cymru
STEWARDS OF THE BOGON REFERENCE SINCE 2002

Shared with CSIRTs, never sold to them.

The CSIRT Assistance Program is underwritten by Team Cymru for qualifying national, regional, and sector CSIRTs. No license fee. No commercial relationship behind the data. The exchange is partnership and trust, period. We share what we see, you protect what you cover.

Region-tuned intelligence, because the threats are.

What an Asian national CSIRT needs to see is not what a European regional CSIRT needs to see. We tune the intelligence we share to the threats you’re facing, in the region you’re defending. The work means more when it actually matches the ground.

Especially for the newly formed teams.

Standing up a new national CSIRT is one of the hardest jobs in cybersecurity. We work with newly formed CSIRTs especially, because that’s where shared intelligence has the biggest immediate impact. The first year of a CSIRT is the year the program pays off the most.

A mission, not a product line.

Team Cymru’s mission is to save and improve lives. CSIRT AP exists because that mission is real, not because it’s a market segment. For as long as Team Cymru exists, CSIRT AP exists. The partnership doesn’t end. The relationship doesn’t get sunset.

In Practice

When the alert fires, here’s the partnership.

Same standing partnership, different CSIRT mandate. The pressure that lands on the team, what Team Cymru puts in the middle, and what gets defended on the other side.

National CSIRTS

Nation-state activity observed targeting infrastructure inside your borders.

Pressure

Cross-border attack

Cymru Action

Region-tuned intel feed

Outcome

Attack attributed faster

What changes

Coordinated national response.

Regional CSIRTS

Coordinating incident response across multiple countries during a shared campaign.

Pressure

Multi-country incident

Cymru Action

Shared intel across nodes

Outcome

Aligned regional view

What changes

Borders stop slowing response.

Sector CSIRTS

Banking, energy, or healthcare CSIRT responding to industry-targeted threats.

Pressure

Sector-targeted campaign

Cymru Action

Sector-specific signals

Outcome

Sector hardened together

What changes

Sector defense, not siloed.

Newly Formed CSIRTS

Standing up incident response capability with limited budget and operational history.

Pressure

Capability gap

Cymru Action

Immediate intel access

Outcome

CSIRT operational sooner

What changes

Year-one impact, not year-three.
Built with Defenders

CSIRT need something we’re not sharing? Tell us.

The program evolves as CSIRT priorities evolve. If there’s a threat category we’re not currently sharing, a region we should be tuning to more precisely, or a coordination capability that would help your team, submit a request. The TeamCymru analyst team reads every one.

CSIRTS WORLDWIDE

Standing with the teams defending consequential systems.

National CSIRTs. Regional CSIRTs. Sector CSIRTs. Government CSIRTs. Newly formed CSIRTs. Team Cymru’s CSIRT Assistance Program stands with incident response teams across six continents, in countries large and small. Same intelligence we use ourselves. Same standing partnership behind it.

National Csirts

Regional Csirts

Government CSIRTS

Sector CSIRTS

Newly Formed CSIRTS

  • SIX CONTINENTS REACHED
  • 10 THREAT INTELLIGENCE CATEGORIES
  • PURE SIGNAL™ INTELLIGENCE SHARED
  • OPERATED FOR THE COMMUNITY

Defense is Layered

Different problem? Different tool.

CSIRT AP is the coordination layer. If your operational priority is filtering bogon routes, mitigating volumetric DDoS, surfacing flow-level threats, or triaging hash-based IOCs, the Operational Marketplace has the right tool for the mission.

Infrastructure Intelligence

Bogon Networks

Reference data for unrouted, reserved, and unallocated IPv4 and IPv6 prefixes. Six access formats for filtering at the routing layer.

Access Bogon Reference

THREAT DEFENSE

DDoS Mitigation UTRS

Coordinated BGP blackholing for volumetric attack response. Community-driven mitigation, real-time signal sharing.

COORDINATE DDOS DEFENSE

Threat Defense

Nimbus Threat Monitor

Continuous threat detection across your network telemetry. Correlates NetFlow against global threat intelligence to surface malicious activity hourly.

Detect Threats in-Flow

INTELLIGENCE & REPUTATION

MHR API

Programmatic malware hash lookups against an indexed sample corpus. Sub-second response, built for triage workflows.

TRIAGE HASH IOCS

GLOBAL DEFENDER EXCHANGE COMMUNITY

The work matters.
Partner with us.

The CSIRT Assistance Program is Team Cymru’s direct partnership withthe national, regional, sector, and newly forming CSIRTs defending thesystems we all live on. Region-tuned. Underwritten by us. Operated aspart of our mission to save and improve lives, for as long as the mission needs it.

No-Cost Access · Underwritten by Team Cymru