CSOB-Group-CSIRT
The CSOB-Group-CSIRT provides IT security incident response for the ČSOB Group and its customers.
RFC 2350 Profile
This page contains the RFC 2350 profile of CSOB-Group-CSIRT.
1. Document Information
1.1 Date of Last Update
2026-06-03
1.2 Distribution List for Notifications
No public distribution list is available. Updates to this document are published on the official ČSOB website.
1.3 Locations where this Document May Be Found
The current version of this document is available at: https://www.csob.cz/kontakty/csob-group-csirt
1.4 Authenticating this Document
This document is published on the official website of Československá obchodní banka, a. s. (ČSOB). The authenticity of this document can be verified by accessing it through the official ČSOB domain.
2. Contact Information
2.1 Name of the Team
CSOB-Group-CSIRT
2.2 Address
CSOB-Group-CSIRTČeskoslovenská obchodní banka, a. s.
Radlická 333/150
150 57 Praha 5
Czech Republic
2.3 Time Zone
Europe/Prague
CET / CEST (UTC+1 / UTC+2)
2.4 Telephone Number
For ČSOB Group customers:
+420 495 800 111
2.5 Fax Number
Not available.
2.6 Other Telecommunication
Not publicly available.
2.7 Electronic Mail Address
For other CSIRT/CERT teams and trusted security partners:
cybersec@csob.cz
For ČSOB Group customers:
helpdeskeb@csob.cz
2.8 Public Keys and Encryption Information
PGP encryption is supported for secure communication.
- User ID
- CSOB-GROUP-CSIRT <cybersec@csob.cz>
- Key ID
- FA625348B25C7A1C
- Key type
- DSA
- Key size
- 3072
- Expires
- Never
- Fingerprint
- 643E42AF5ADF5715B548DE1CFA625348B25C7A1C
2.9 Team Members
Team member information is not publicly disclosed.
2.10 Other Information
Additional information about ČSOB can be found at: https://www.csob.cz
2.11 Points of Customer Contact
ČSOB Group customers should use standard ČSOB customer support channels.
Security-related communication from other CSIRT/CERT teams and trusted partners should be sent to: cybersec@csob.cz.
3. Charter
3.1 Mission Statement
The purpose of CSOB-Group-CSIRT is to provide IT security incident response for the ČSOB Group and its customers.
The team’s main responsibilities include:
- handling computer security incidents;
- performing ICT forensic analysis;
- coordinating computer security incident response.
3.2 Constituency
The constituency of CSOB-Group-CSIRT includes:
- ČSOB Group;
- affiliated entities within ČSOB Group;
- ČSOB Group customers, where relevant to security incidents;
- systems, networks and services operated by or for ČSOB Group.
3.3 Constituency Type
Financial Sector
3.4 Country of Constituency
Czech Republic
3.5 ASNs, Domains and IP Ranges
The constituency includes, but is not limited to:
- *.csob.cz
- 193.245.32.0/21
- 195.144.99.0/24
3.6 Sponsorship and/or Affiliation
CSOB-Group-CSIRT is part of Československá obchodní banka, a. s. (ČSOB).
3.7 Authority
CSOB-Group-CSIRT operates under the authority of ČSOB Group.
The team is authorized to coordinate and support the handling of computer security incidents affecting its defined constituency. The team may cooperate with external CSIRT/CERT teams, trusted partners, service providers and relevant authorities when required.
CSOB-Group-CSIRT does not have authority outside its defined constituency.
4. Policies
4.1 Types of Incidents and Level of Support
CSOB-Group-CSIRT handles security incidents affecting its constituency, including but not limited to:
- phishing and fraud-related incidents;
- malware infections;
- unauthorized access;
- network-based attacks;
- data leakage or data breach incidents;
- misuse of ČSOB Group systems, services or infrastructure;
- other cybersecurity incidents affecting ČSOB Group or its customers.
The level of support depends on the type and severity of the incident, the affected systems and the relationship of the reporting party to the defined constituency.
4.2 Co-operation, Interaction and Disclosure of Information
CSOB-Group-CSIRT cooperates with other CSIRT/CERT teams, trusted security partners, service providers, regulators and relevant authorities where appropriate.
Information is disclosed on a need-to-know basis in accordance with internal policies, legal requirements and applicable regulations.
The Traffic Light Protocol (TLP) is used to classify and control information sharing. Sensitive information is shared only with trusted parties and always in accordance with the assigned TLP level.
Public disclosure is limited and subject to internal approval processes.
4.3 Communication and Authentication
The preferred communication channel for other CSIRT/CERT teams and trusted partners is email to: cybersec@csob.cz.
For sensitive information, PGP encryption should be used where appropriate.
The identity of external parties may be verified using:
- trusted CSIRT/CERT directories;
- previously established communication channels;
- cryptographic signatures;
- other reasonable verification methods.
5. Services
5.1 Incident Response
CSOB-Group-CSIRT provides incident response services for its defined constituency.
These services include:
- incident triage;
- incident analysis;
- incident coordination;
- support for incident containment, mitigation and resolution;
- coordination with relevant internal and external parties.
5.1.1 Incident Triage
CSOB-Group-CSIRT receives and evaluates reported security incidents, assesses their relevance and severity, and determines appropriate handling steps.
5.1.2 Incident Coordination
CSOB-Group-CSIRT coordinates the handling of security incidents within ČSOB Group and, where necessary, with external CSIRT/CERT teams, trusted partners, service providers or authorities.
5.1.3 Incident Resolution
CSOB-Group-CSIRT supports the containment, mitigation and resolution of security incidents affecting its constituency.
5.2 Proactive Activities
CSOB-Group-CSIRT may perform proactive security activities, including:
- security monitoring;
- threat analysis;
- vulnerability coordination;
- security advisory and awareness activities;
- cooperation with trusted cybersecurity communities.
5.3 Reactive Activities
CSOB-Group-CSIRT performs reactive activities related to reported or detected security incidents, including:
- incident investigation;
- ICT forensic analysis;
- malware-related analysis and coordination;
- coordination of remediation activities.
6. Incident Reporting
6.1 Reporting Security Incidents
Other CSIRT/CERT teams and trusted security partners should report security incidents to: cybersec@csob.cz.
ČSOB Group customers should use: helpdeskeb@csob.cz or telephone: +420 495 800 111.
6.2 Information to Include in Reports
Incident reports should include, where available:
- contact details of the reporting party;
- description of the incident;
- affected systems, services, domains, IP addresses or accounts;
- date and time of detection or occurrence;
- relevant logs, indicators of compromise or technical evidence;
- any actions already taken;
- TLP classification, if applicable.
6.3 Response Expectations
CSOB-Group-CSIRT handles reports duringhr> CSOB-Group-CSIRT handles reports during its stated business hours.
7. Additional Information
7.1 Classification
Internal Corporate CSIRT for the financial services sector, serving ČSOB Group and its affiliated entities.
7.2 Exclusivity
Services are provided exclusively to the internal constituency of ČSOB Group and its affiliated entities. No services are offered to the public.
7.3 Disclosure
Information is disclosed on a need-to-know basis in accordance with internal policies and applicable regulations.
The Traffic Light Protocol (TLP) is used to classify and control information sharing. Sensitive information is shared only with trusted parties such as relevant CSIRT/CERT teams, partners and authorities, and always in accordance with the assigned TLP level.
Public disclosure is limited and subject to internal approval processes.
7.4 Legal Considerations
CSOB-Group-CSIRT operates in accordance with applicable national and European legislation, including data protection and cybersecurity regulations.
All activities are subject to legal and regulatory requirements relevant to the financial sector, including GDPR and applicable banking regulations.
Information handling and incident response activities are performed in compliance with internal policies, contractual obligations and legal constraints.
Any actions taken by CSOB-Group-CSIRT are limited to the authority of the team’s defined constituency.
7.5 Cryptography
CSOB-Group-CSIRT supports the use of cryptographic mechanisms to protect sensitive information.
PGP encryption is supported for secure email communication.
Secure communication protocols, such as TLS, are used where applicable.
Business hours:
Monday to Friday, 08:00–17:00 Europe/Prague time.
The response time depends on the severity, impact and relevance of the reported incident.
8. Disclaimers
CSOB-Group-CSIRT provides information and assistance on a best-effort basis.
While CSOB-Group-CSIRT makes reasonable efforts to ensure the accuracy and reliability of information provided, no warranty is given regarding completeness, accuracy or suitability for any particular purpose.
CSOB-Group-CSIRT accepts no liability for any damage resulting from the use of information provided by the team.
All activities are subject to applicable laws, regulations, contractual obligations and internal policies.