The CERT Polska team operates within the structures of NASK (Research and Academic Computer Network) – National Research Institute, a research institute conducting scientific studies, operating the national .pl domain registry and providing advanced IT services. CERT Polska is the first computer emergency response team established in Poland. Through its active involvement in the incident response community since 1996, it has become a recognized and experienced organization in the field of cybersecurity.
Since its launch, the team's core activities have included incident handling and cooperation with similar organizations around the world, both in operational activities and research and development. Since 1998, CERT Polska has been a member of FIRST (Forum of Incident Response and Security Teams). Since 2000, it has participated in the European incident response community through TERENA TF-CSIRT and Trusted Introducer. In 2010, CERT Polska joined the Anti-Phishing Working Group (APWG), an international association of organizations actively combating online crime.
Since the entry into force of the Polish Act on the National Cybersecurity System on 5 July 2018, the team has carried out part of the statutory responsibilities of CSIRT NASK, one of three national-level CSIRTs.
Main responsibilities of CERT Polska include:
- monitoring cyber threats and incidents at the national level;
- providing information on cyber threats, vulnerabilities, incidents and risks, including early warning and alerting activities for entities within the national cybersecurity system;
- publishing communications regarding identified cyber threats;
- responding to reported incidents;
- classifying incidents, including severe incidents, as critical incidents and coordinating critical incident handling;
- cooperating with sectoral CSIRTs regarding the coordination of severe and critical incidents, including incidents affecting two or more EU Member States;
- conducting advanced malware analysis and vulnerability analysis;
- monitoring indicators of compromise and cyber threat indicators;
- developing tools and methods for detection and mitigation of cyber threats;
- carrying out cybersecurity awareness-building activities;
- creating and providing tools supporting voluntary cooperation and information sharing regarding cyber threats and incidents;
- monitoring smishing campaigns and maintaining smishing detection patterns in accordance with applicable regulations;
- participating in the EU CSIRTs Network;
- cooperating with incident response teams from third countries;
- coordinating incident handling for public institutions, research entities, designated essential and important entities, other organizations, and individual users within the scope defined by national legislation.
Coordinated vulnerability disclosure
As CSIRT NASK, we serve as the national coordinator for the purposes of coordinated vulnerability disclosure.
Since 2023 we are a Partner of CVE Program as a CNA (CVE Numbering Authority). Our CVD Policy is available here.
RFC 2350
The complete RFC 2350-compliant description of CERT Polska is available below. The document is signed with the CERT Polska PGP key.