About us

CERT Bulgaria is the National Computer Security Incident Response Team (CSIRT) responsible for responding to information security incidents at the national level. The mission of the Centre is to support its constituents through proactive measures that reduce the risk of information security incidents and to assist in responding to and recovering from incidents when they occur.

The Centre maintains a centralized repository of information and resources that contribute to a secure information environment.

 

 

Objectives:

  • Protecting information and technology assets;
  • Reducing the impact of information security incidents;
  • Assisting organizations in recovering from security incidents;
  • Assessing the impact of information security incidents;
  • Collecting, analyzing, and disseminating technical information related to information security incidents, system vulnerabilities, and methods for preventing and mitigating them;
  • Conducting research on emerging technologies in network and information security;
  • Providing training for information security and incident management. 

The National Accident Response Action Center provides its users with the re-active and proactive services described below.


 

Security Alerts and Warnings:

This service provides timely information on cyberattacks, security vulnerabilities, malware, unauthorized activities, and online scams. Alerts and advisories include recommendations for mitigating risks, preventing incidents, and restoring affected systems where necessary.

 


Vulnerability Management:

Vulnerability management services include:

  • Receiving and processing reports of vulnerabilities in hardware, software, systems, and applications.
  • Analyzing the nature, impact, and potential exploitation of identified vulnerabilities.
  • Developing recommendations for detecting, mitigating, and remediating vulnerabilities. Identifying appropriate security updates, patches, and mitigation measures.Notifying affected users of available security fixes and providing guidance on patch deployment where appropriate.


Security incidents management:

Incident management services include receiving, triaging, analyzing, and responding to security incident reports. These services may include:

  • Taking action to protect systems and networks that are affected by or at risk of cyberattacks;
  • Providing recommendations to reduce the likelihood and impact of similar incidents;
  • Assessing whether attacks have affected other systems or network segments;
  • Assisting with network traffic filtering and containment measures;
  • Supporting system recovery and restoration;
  • Advising on system updates and security improvements;
  • Developing alternative response strategies where appropriate.

 

Artifact Analysis:

Artifact analysis services involve collecting and examining malicious files, malware samples, and other digital artifacts associated with cyber incidents. These activities include analyzing their characteristics, behavior, and methods of operation, as well as developing or recommending strategies for detection, removal, and protection against future attacks.

 


Security Newsletters:

CERT Bulgaria publishes newsletters containing information on newly discovered vulnerabilities, emerging threats, attack techniques, and security best practices. These publications also provide practical guidance to help organizations strengthen their cybersecurity posture and protect their systems before vulnerabilities become widely exploited.

 


Information Sharing:

This service provides users with practical and accessible information designed to improve cybersecurity awareness and resilience. Resources may include:

  • Contact information and procedures for reporting incidents to CERT Bulgaria;
  • An archive of security alerts, advisories, and notifications;
  • Guidance on current cybersecurity best practices;
  • Basic computer and information security recommendations;
  • Security policies, procedures, and checklists;
  • Information on available security patches and updates;
  • Contacts with providers;
  • Statistics and trends related to cybersecurity incidents;
  • Additional resources that promote stronger security practices and greater cyber resilience.