BSI starts personal certification for incident experts

B2B Cyber ​​Security ShortNews

Share post

Attacks on IT systems in Germany cause tens of billions of euros in damage every year. Those affected are small to large companies, but also consumer households. Certified incident experts provide first aid in the event of a cyber attack.

Cyber ​​criminals break into IT systems, read out data, encrypt it and extort a ransom for releasing the data. In such an emergency situation, it can be difficult, especially for micro and small businesses, but also for medium-sized companies, to evaluate the competence and trustworthiness of IT service providers.

Incident expert certified by the BSI

Arne Schönbohm, President of the BSI: “With the cyber security network, we want to try out a practical and helpful offer that is intended to help micro, small and medium-sized companies in the event of a cyber attack. Along a digital rescue chain, it is primarily the incident experts who will provide first aid on initial contact. We will start the pilot phase in October and are now starting the first personal certifications, thereby ensuring the professional competence and quality of the actors. "

Further information on personal certification as incident experts and a list of the currently certified incident experts are available on the BSI website. About the cyber security network project:
In October, the BSI will start a six-month pilot phase of the cyber security network (CSN). The CSN is a voluntary association of qualified experts who agree to provide their individual expertise and know-how to resolve IT security incidents and thus contribute to improving the IT security situation in Germany. By taking on reactive activities, they help to recognize and analyze IT security incidents, to limit the extent of damage and to avert further damage. The certification enables qualified persons to carry out incident treatment within the framework of the cyber security network to ensure the quality and comparability of incident treatment.

Cyber ​​security network rescue chain

In a possible highest level of the cyber security network's rescue chain, larger IT service providers are available who operate supraregional and can provide at least three certified incident experts. In this way, a team of incident experts with special knowledge and skills for incident handling can be offered for more complex and larger IT security incidents.

A prerequisite for certification as an IT security service provider is the implementation and maintenance of the DIN EN ISO / IEC 17025 standard. After the certification has been granted, the BSI checks regularly so that the service providers continue to meet the requirements. Information and requirements for certification as an IT security service provider as well as the list of currently certified IT security service providers are available on the BSI website.

More at BSI.bund.de

 

Matching articles on the topic

Report: 40 percent more phishing worldwide

The current spam and phishing report from Kaspersky for 2023 speaks for itself: users in Germany are after ➡ Read more

BSI sets minimum standards for web browsers

The BSI has revised the minimum standard for web browsers for administration and published version 3.0. You can remember that ➡ Read more

Stealth malware targets European companies

Hackers are attacking many companies across Europe with stealth malware. ESET researchers have reported a dramatic increase in so-called AceCryptor attacks via ➡ Read more

IT security: Basis for LockBit 4.0 defused

Trend Micro, working with the UK's National Crime Agency (NCA), analyzed the unpublished version that was in development ➡ Read more

MDR and XDR via Google Workspace

Whether in a cafe, airport terminal or home office – employees work in many places. However, this development also brings challenges ➡ Read more

Test: Security software for endpoints and individual PCs

The latest test results from the AV-TEST laboratory show very good performance of 16 established protection solutions for Windows ➡ Read more

FBI: Internet Crime Report counts $12,5 billion in damage 

The FBI's Internet Crime Complaint Center (IC3) has released its 2023 Internet Crime Report, which includes information from over 880.000 ➡ Read more

HeadCrab 2.0 discovered

The HeadCrab campaign against Redis servers, which has been active since 2021, continues to successfully infect targets with the new version. The criminals' mini-blog ➡ Read more