/// Service catalogue  ·  rev 2026.02

What the CSIRT does, and what stays with your institution.

Our constituency is GARNET member institutions and the networks they operate. We coordinate; we do not administer member infrastructure or make decisions on a member’s behalf.

§ Reactive services

Triggered by an incident

Incident triage & coordination

Active

We assess the report, assign severity and impact, and stay with the case through containment, eradication, recovery, and written post-incident review. Where more than one member is affected, we run the cross-institution coordination so each site isn’t chasing the others.

DELIVERY
ACKNOWLEDGE  ≤ 4 BUS. HRS
CHANNEL  EMAIL / TICKET
OUTPUT  PIR DOCUMENT

§ Proactive services

Running whether or not anything is wrong

Active

Compromise notifications

Member credentials, hosts, and IP ranges are matched against external feeds. Hits go to the institution’s registered security contact, not to a public list.

Active

Advisories & bulletins

Signed write-ups of vulnerabilities that actually matter in academic environments — VLE platforms, library systems, campus wireless, research storage.

Active

Training & workshops

The Network Monitoring and Management series, plus incident-handling sessions for staff who are on the hook when something breaks at 2am.

Active

Vulnerability scanning

Opt-in external scanning of member ranges, with results delivered only to the member. Requires written authorisation per institution.

Referral

Forensics & legal

Evidence-grade forensics and law-enforcement liaison are referred to the Cyber Security Authority and national partners. We help you package the case.

§ Boundaries

Out of scope

Day-to-day administration of member networks, servers, or endpoints.

Incidents involving parties with no GARNET membership or peering relationship.

Disciplinary investigations, HR matters, and content disputes between members.