CSOB-Group-CSIRT

The CSOB-Group-CSIRT provides IT security incident response for the ČSOB Group and its customers.

RFC 2350 Profile

This page contains the RFC 2350 profile of CSOB-Group-CSIRT.

1. Document Information

1.1 Date of Last Update

2026-06-03

1.2 Distribution List for Notifications

No public distribution list is available. Updates to this document are published on the official ČSOB website.

1.3 Locations where this Document May Be Found

The current version of this document is available at: https://www.csob.cz/kontakty/csob-group-csirt

1.4 Authenticating this Document

This document is published on the official website of Československá obchodní banka, a. s. (ČSOB). The authenticity of this document can be verified by accessing it through the official ČSOB domain.

2. Contact Information

2.1 Name of the Team

CSOB-Group-CSIRT

2.2 Address

CSOB-Group-CSIRT
Československá obchodní banka, a. s.
Radlická 333/150
150 57 Praha 5
Czech Republic

2.3 Time Zone

Europe/Prague
CET / CEST (UTC+1 / UTC+2)

2.4 Telephone Number

For ČSOB Group customers:
+420 495 800 111

2.5 Fax Number

Not available.

2.6 Other Telecommunication

Not publicly available.

2.7 Electronic Mail Address

For other CSIRT/CERT teams and trusted security partners:
cybersec@csob.cz

For ČSOB Group customers:
helpdeskeb@csob.cz

2.8 Public Keys and Encryption Information

PGP encryption is supported for secure communication.

User ID
CSOB-GROUP-CSIRT <cybersec@csob.cz>
Key ID
FA625348B25C7A1C
Key type
DSA
Key size
3072
Expires
Never
Fingerprint
643E42AF5ADF5715B548DE1CFA625348B25C7A1C

2.9 Team Members

Team member information is not publicly disclosed.

2.10 Other Information

Additional information about ČSOB can be found at: https://www.csob.cz

2.11 Points of Customer Contact

ČSOB Group customers should use standard ČSOB customer support channels.

Security-related communication from other CSIRT/CERT teams and trusted partners should be sent to: cybersec@csob.cz.

3. Charter

3.1 Mission Statement

The purpose of CSOB-Group-CSIRT is to provide IT security incident response for the ČSOB Group and its customers.

The team’s main responsibilities include:

  • handling computer security incidents;
  • performing ICT forensic analysis;
  • coordinating computer security incident response.

3.2 Constituency

The constituency of CSOB-Group-CSIRT includes:

  • ČSOB Group;
  • affiliated entities within ČSOB Group;
  • ČSOB Group customers, where relevant to security incidents;
  • systems, networks and services operated by or for ČSOB Group.

3.3 Constituency Type

Financial Sector

3.4 Country of Constituency

Czech Republic

3.5 ASNs, Domains and IP Ranges

The constituency includes, but is not limited to:

  • *.csob.cz
  • 193.245.32.0/21
  • 195.144.99.0/24

3.6 Sponsorship and/or Affiliation

CSOB-Group-CSIRT is part of Československá obchodní banka, a. s. (ČSOB).

3.7 Authority

CSOB-Group-CSIRT operates under the authority of ČSOB Group.

The team is authorized to coordinate and support the handling of computer security incidents affecting its defined constituency. The team may cooperate with external CSIRT/CERT teams, trusted partners, service providers and relevant authorities when required.

CSOB-Group-CSIRT does not have authority outside its defined constituency.

4. Policies

4.1 Types of Incidents and Level of Support

CSOB-Group-CSIRT handles security incidents affecting its constituency, including but not limited to:

  • phishing and fraud-related incidents;
  • malware infections;
  • unauthorized access;
  • network-based attacks;
  • data leakage or data breach incidents;
  • misuse of ČSOB Group systems, services or infrastructure;
  • other cybersecurity incidents affecting ČSOB Group or its customers.

The level of support depends on the type and severity of the incident, the affected systems and the relationship of the reporting party to the defined constituency.

4.2 Co-operation, Interaction and Disclosure of Information

CSOB-Group-CSIRT cooperates with other CSIRT/CERT teams, trusted security partners, service providers, regulators and relevant authorities where appropriate.

Information is disclosed on a need-to-know basis in accordance with internal policies, legal requirements and applicable regulations.

The Traffic Light Protocol (TLP) is used to classify and control information sharing. Sensitive information is shared only with trusted parties and always in accordance with the assigned TLP level.

Public disclosure is limited and subject to internal approval processes.

4.3 Communication and Authentication

The preferred communication channel for other CSIRT/CERT teams and trusted partners is email to: cybersec@csob.cz.

For sensitive information, PGP encryption should be used where appropriate.

The identity of external parties may be verified using:

  • trusted CSIRT/CERT directories;
  • previously established communication channels;
  • cryptographic signatures;
  • other reasonable verification methods.

5. Services

5.1 Incident Response

CSOB-Group-CSIRT provides incident response services for its defined constituency.

These services include:

  • incident triage;
  • incident analysis;
  • incident coordination;
  • support for incident containment, mitigation and resolution;
  • coordination with relevant internal and external parties.

5.1.1 Incident Triage

CSOB-Group-CSIRT receives and evaluates reported security incidents, assesses their relevance and severity, and determines appropriate handling steps.

5.1.2 Incident Coordination

CSOB-Group-CSIRT coordinates the handling of security incidents within ČSOB Group and, where necessary, with external CSIRT/CERT teams, trusted partners, service providers or authorities.

5.1.3 Incident Resolution

CSOB-Group-CSIRT supports the containment, mitigation and resolution of security incidents affecting its constituency.

5.2 Proactive Activities

CSOB-Group-CSIRT may perform proactive security activities, including:

  • security monitoring;
  • threat analysis;
  • vulnerability coordination;
  • security advisory and awareness activities;
  • cooperation with trusted cybersecurity communities.

5.3 Reactive Activities

CSOB-Group-CSIRT performs reactive activities related to reported or detected security incidents, including:

  • incident investigation;
  • ICT forensic analysis;
  • malware-related analysis and coordination;
  • coordination of remediation activities.

6. Incident Reporting

6.1 Reporting Security Incidents

Other CSIRT/CERT teams and trusted security partners should report security incidents to: cybersec@csob.cz.

ČSOB Group customers should use: helpdeskeb@csob.cz or telephone: +420 495 800 111.

6.2 Information to Include in Reports

Incident reports should include, where available:

  • contact details of the reporting party;
  • description of the incident;
  • affected systems, services, domains, IP addresses or accounts;
  • date and time of detection or occurrence;
  • relevant logs, indicators of compromise or technical evidence;
  • any actions already taken;
  • TLP classification, if applicable.

6.3 Response Expectations

CSOB-Group-CSIRT handles reports duringhr> CSOB-Group-CSIRT handles reports during its stated business hours.

7. Additional Information

7.1 Classification

Internal Corporate CSIRT for the financial services sector, serving ČSOB Group and its affiliated entities.

7.2 Exclusivity

Services are provided exclusively to the internal constituency of ČSOB Group and its affiliated entities. No services are offered to the public.

7.3 Disclosure

Information is disclosed on a need-to-know basis in accordance with internal policies and applicable regulations.

The Traffic Light Protocol (TLP) is used to classify and control information sharing. Sensitive information is shared only with trusted parties such as relevant CSIRT/CERT teams, partners and authorities, and always in accordance with the assigned TLP level.

Public disclosure is limited and subject to internal approval processes.

7.4 Legal Considerations

CSOB-Group-CSIRT operates in accordance with applicable national and European legislation, including data protection and cybersecurity regulations.

All activities are subject to legal and regulatory requirements relevant to the financial sector, including GDPR and applicable banking regulations.

Information handling and incident response activities are performed in compliance with internal policies, contractual obligations and legal constraints.

Any actions taken by CSOB-Group-CSIRT are limited to the authority of the team’s defined constituency.

7.5 Cryptography

CSOB-Group-CSIRT supports the use of cryptographic mechanisms to protect sensitive information.

PGP encryption is supported for secure email communication.

Secure communication protocols, such as TLS, are used where applicable.

Business hours:
Monday to Friday, 08:00–17:00 Europe/Prague time.

The response time depends on the severity, impact and relevance of the reported incident.

8. Disclaimers

CSOB-Group-CSIRT provides information and assistance on a best-effort basis.

While CSOB-Group-CSIRT makes reasonable efforts to ensure the accuracy and reliability of information provided, no warranty is given regarding completeness, accuracy or suitability for any particular purpose.

CSOB-Group-CSIRT accepts no liability for any damage resulting from the use of information provided by the team.

All activities are subject to applicable laws, regulations, contractual obligations and internal policies.