Accessibility

Building a CSIRT: A Practical Blueprint for Success

The 5th LAC4 members-only seminar, led by EU CyberNet Experts Carlos Leonardo from the Dominican Republic and Roberto Lemaitre Picado from Costa Rica focused on building a computer security incident response team (CSIRT) and offering participants practical and structured guidelines to succeed.

Focusing on the practical aspects of CSIRT development, participants explored core functions and types of CSIRTs; learned to identify key organizational, technical and human components; and gained insights from real-life experiences of CSIRT implementation across the LAC region.

Most important take-aways from the seminar for successful building of CSIRT:

  • A CSIRT should include both an incident response team and an incident management team. The effective operation of both is crucial to maintaining trust and ensuring a coordinated response.
  • A thorough evaluation and proper preparation are essential for the effective operation of a CSIRT. It’s crucial to define why we need a CSIRT, what its mission will be, whom it will serve, and most importantly, who will support and fund it. Clear and sustainable funding is fundamental to ensuring its long-term success.
  • It’s better to start by offering a few but effective services, and gradually expand over time. To achieve this, having a clear roadmap and a service catalog is essential.
  • The CSIRT’s network infrastructure should be segregated from general organizational networks to prevent potential incidents from spreading and compromising other systems.
  • Cybersecurity measures often sound good from a legal standpoint, but are not realistic from a technological perspective, thus the legal area should be aligned with the technological one.
  • CSIRT personnel require not only strong technical skills but also interpersonal abilities: hiring should be based on an 80-20 balance, with 20% focused on technical capabilities and 80% on soft skills.
  • Depending on the CSIRT’s mission and objectives, it should have different dimensions and structures tailored to its specific needs.
  • The CSIRT must maintain clear communication and have an updated contact list and connections, fostering a trusted ecosystem to build a robust network that promotes cybersecurity.
  • One of the main objectives of a CSIRT is to minimize false negatives and maximize true positives—ensuring that real threats are not missed, while ignoring noise that doesn’t pose any real risk.

LAC4 remains committed to supporting its members in building and strengthening capacity for their CSIRT development and operations. Seminar was attended by 132 stakeholders and policymakers from LAC4 Participant Nations. Seminar was designed for cybersecurity stakeholders and policymakers from LAC4 member countries of Antigua and Barbuda, Colombia, the Dominican Republic, Ecuador, El Salvador, Guatemala, Honduras, Panama and Uruguay and members of RedCLARA.

Next LAC4 members-only seminar will take place in August 2025.


Keep reading similar articles
LAC4 to Participate in CAMP 11th Anniversary Celebration 2026

The Latin American and Caribbean Cyber Competence Centre (LAC4) will participate in the CAMP 11th Anniversary Celebration 2026, taking place from July 6 to July 10. The event will bring together members and partners of the Cybersecurity Alliance for Mutual Progress (CAMP) to strengthen international cooperation, exchange experiences and promote collective approaches to a safer and more resilient cyberspace.

LAC4 Members-Only Seminar: SOC Fundamentals & Comparative on European Models

As the Latin American and Caribbean region undergoes rapid digital transformation, the traditional Security Operations Center (SOC) model is being challenged by the need for increased agility and cross-border collaboration. To address these evolving demands, LAC4 hosted its latest members-only webinar on this topic, which aimed at providing participants with a foundational blueprint for building and scaling effective SOCs.

Cyber Policy Bootcamp Concludes in Santo Domingo, Advancing Regional Dialogue on Cyber Governance and Legislation

The Cyber Policy Bootcamp, held from 9 to 12 June 2026 in Santo Domingo, Dominican Republic, successfully concluded after four days of high-level discussions, technical exchanges and practical sessions dedicated to strengthening cybersecurity governance, policy development and legislative frameworks across Latin America and the Caribbean.

Cyber Policy Bootcamp to Take Place This Week

A four-day Cyber Policy Bootcamp focused on strengthening cybersecurity governance, policy development and legislative frameworks will take place from 9 to 12 June 2026 in Santo Domingo, Dominican Republic.

Supporting Cyber Resilience in Suriname

LAC4, in cooperation with the Ministry of Foreign Affairs, International Trade & Cooperation of the Republic of Suriname organised a specialized 3-day training “Open-Source Security for Implementing Enterprise-Grade Defense for Government Networks” from 3 to 5 June 2026 in Paramaribo, Suriname.

Guyana Joins LAC4

The Cooperative Republic of Guyana on behalf of the Office of the Prime Minister, Hon. Mark Phillips, has become the 19th member of LAC4. Accession ceremony took place on 4 June 2026 in Georgetown, Guyana in the presence of the Prime Minister of the Cooperative Republic of Guyana, the National Data Management Authority, the LAC4 team and the Delegation of the European Union to Guyana.