/// Service catalogue · rev 2026.02
What the CSIRT does, and what stays with your institution.
Our constituency is GARNET member institutions and the networks they operate. We coordinate; we do not administer member infrastructure or make decisions on a member’s behalf.
§ Reactive services
Triggered by an incident
Incident triage & coordination
ActiveWe assess the report, assign severity and impact, and stay with the case through containment, eradication, recovery, and written post-incident review. Where more than one member is affected, we run the cross-institution coordination so each site isn’t chasing the others.
§ Proactive services
Running whether or not anything is wrong
Compromise notifications
Member credentials, hosts, and IP ranges are matched against external feeds. Hits go to the institution’s registered security contact, not to a public list.
Advisories & bulletins
Signed write-ups of vulnerabilities that actually matter in academic environments — VLE platforms, library systems, campus wireless, research storage.
Training & workshops
The Network Monitoring and Management series, plus incident-handling sessions for staff who are on the hook when something breaks at 2am.
Vulnerability scanning
Opt-in external scanning of member ranges, with results delivered only to the member. Requires written authorisation per institution.
Forensics & legal
Evidence-grade forensics and law-enforcement liaison are referred to the Cyber Security Authority and national partners. We help you package the case.
§ Boundaries
Out of scope
Day-to-day administration of member networks, servers, or endpoints.
Incidents involving parties with no GARNET membership or peering relationship.
Disciplinary investigations, HR matters, and content disputes between members.