CSIRT Description for Fidelir CSIRT =================================== (RFC 2350) ------------------------------------------------------------------------ 1. Document Information ------------------------------------------------------------------------ 1.1 Date of Last Update Version: 1.0 Date: 2026-08-02 1.2 Distribution List for Notifications None. Updates are indicated by the version number and date in section 1.1 on the canonical URL below. No announce mailing list. 1.3 Locations where this Document May Be Found Canonical (plain text, HTTPS): https://fidelir.com/csirt/rfc2350.txt OpenPGP clearsigned copy: https://fidelir.com/csirt/rfc2350.txt.asc Clearsign authority (document authenticity — not the SOC encryption key in section 2.8): Victor Tataru Fingerprint: 5CAA DDD2 56CC 09AD 93DC A322 F180 696F 0C73 7167 Key URL: https://fidelir.com/csirt/victor.tataru.asc ------------------------------------------------------------------------ 2. Contact Information ------------------------------------------------------------------------ 2.1 Name of the Team Fidelir CSIRT Short name: Fidelir-CSIRT 2.2 Address Fidelir S.R.L. IDNO: 1026023126883 Chișinău, MD-2028 Republic of Moldova 2.3 Time Zone Europe/Chisinau (EET / EEST, UTC+2 / UTC+3) 2.4 Telephone Number None published. Telephone contact for incident handling, where applicable, is provided under the relevant engagement contract. 2.5 Facsimile Number None. 2.6 Other Telecommunication None. 2.7 Electronic Mail Address Primary (incidents / Fidelir CSIRT): soc@fidelir.com Also handled by the same operational team: abuse@fidelir.com — network / ASN abuse (RIPE abuse-c) noc@fidelir.com — network operations Not for CSIRT triage (commercial / legal): contact@fidelir.com legal@fidelir.com 2.8 Public Keys and Encryption Information OpenPGP for soc@fidelir.com (CSIRT / SOC mail): Algorithm: Ed25519 (signing) / Cv25519 (encryption) Key ID: 0x4D29BE8DB3940160 Fingerprint: 3267 7975 25F2 FF76 A40D 478B 4D29 BE8D B394 0160 User ID: Fidelir Security Operations Center Key URL: https://fidelir.com/.well-known/pgp-key.txt Also via: Encryption field in https://fidelir.com/.well-known/security.txt Keyserver: not mirrored; fetch only from Key URL above Sensitive incident data SHOULD be OpenPGP-encrypted to this key. Unencrypted email is acceptable for low-sensitivity coordination. 2.9 Team Members Public contact is the team address soc@fidelir.com. Responsible (Team Lead): Victor Tataru Deputy: Cristina Canja (Jovmir) Other members are available to verified peers on request. 2.10 Other Information Operator: Fidelir S.R.L. (Republic of Moldova) Website: https://fidelir.com LinkedIn: https://www.linkedin.com/company/fidelir Autonomous System: AS219488 IPv6 allocation: 2a0c:b641:d40::/44 RIPE organisation: ORG-FS408-RIPE RIPE abuse contact: abuse@fidelir.com 2.11 Points of Customer Contact Report security incidents to: soc@fidelir.com Subject prefix: [INCIDENT] or [ABUSE] Operating model: soc@ is the shared intake mailbox for SOC and Fidelir CSIRT. Mail is accepted and monitored 24/7/365 (SOC intake — best-effort acknowledgement). Fidelir CSIRT duty / deep handling: Mon–Fri 09:00–18:00 (EET/EEST), except public holidays (aligned with published Contact hours on https://fidelir.com/contact) Outside CSIRT duty hours, SOC performs intake, triage of urgency and escalation; full CSIRT coordination continues on the next duty period unless severity requires immediate on-call escalation. Non-incident enquiries (contact@): Mon–Fri 09:00–18:00 (EET/EEST) as published on https://fidelir.com/contact. Use the reporting elements in section 6. Prefer OpenPGP (section 2.8) for sensitive material. ------------------------------------------------------------------------ 3. Charter ------------------------------------------------------------------------ 3.1 Mission Statement Fidelir CSIRT coordinates and supports response to computer security incidents affecting Fidelir S.R.L. and its defined constituency. The team works to reduce harm, restore secure operation, and enable trusted cooperation with peers, customers and authorities — consistent with applicable law, contractual obligations, and Fidelir’s Independence, Privacy & Security Charter (published on https://fidelir.com/declaration). 3.2 Constituency Fidelir CSIRT serves: 1. Fidelir S.R.L. corporate systems, public digital services (including fidelir.com) and network resources under AS219488 and allocated prefixes. 2. Organisations with an active Fidelir engagement that includes managed security operations and/or incident response support, within the written scope of that engagement. Fidelir CSIRT is not a national CSIRT and does not claim constituency over the Internet at large, nor over organisations without ownership or contractual relationship to Fidelir. 3.3 Sponsorship and/or Affiliation Sponsored and operated by: Fidelir S.R.L., Chișinău, Republic of Moldova Affiliations: FIRST: membership application in progress Other: none at publication of this document 3.4 Authority On Fidelir-owned and Fidelir-operated infrastructure, Fidelir CSIRT may investigate, contain and remediate incidents under company management authority. On customer systems, Fidelir CSIRT acts only within the applicable engagement contract (advisory and/or hands-on as agreed). The team has no authority over third-party systems outside that scope. ------------------------------------------------------------------------ 4. Policies ------------------------------------------------------------------------ 4.1 Types of Incidents and Level of Support In scope: - Compromised hosts or accounts affecting constituency systems - Malware, ransomware, C2 activity related to the constituency - Network abuse originating from AS219488 / Fidelir prefixes - Denial-of-service affecting Fidelir services - Phishing or brand abuse impersonating Fidelir - Vulnerability reports affecting Fidelir public services - Customer security incidents under an active IR / MSS scope Out of scope: - General IT support unrelated to security incidents - Legal advice (use legal@fidelir.com for legal matters) - Incidents with no link to the Fidelir constituency - Requests that would require action outside contractual or ownership authority Level of support: - Intake / acknowledgement via soc@: 24/7/365, best effort (target acknowledgement within 24 hours) - CSIRT handling: Mon–Fri 09:00–18:00 (EET/EEST); after-hours urgent cases escalated from SOC intake as required - Triage priority: by severity and constituency impact - Deep forensics / on-site / extended remediation: according to the applicable engagement contract, or case-by-case for Fidelir-owned systems 4.2 Co-operation, Interaction and Disclosure of Information Information is handled on a need-to-know basis and, where labelled, under the Traffic Light Protocol (TLP) version 2.0: TLP:RED — only for the named recipients; no further redistribution TLP:AMBER+STRICT — share only within the recipient organisation, need-to-know; not with customers or external parties TLP:AMBER — share with the recipient organisation and its clients/customers who need to know to protect themselves or prevent harm TLP:GREEN — community / peer sharing as appropriate TLP:CLEAR — may be shared freely (subject to law) Default for unmarked incident data from constituents: TLP:AMBER+STRICT Fidelir CSIRT may relabel upward (more restrictive) when onward sharing would expose constituent identity or sensitive detail; relabeling downward requires the source’s permission. Disclosure practice: - Constituents receive what they need to protect themselves - Peer CSIRTs / FIRST teams: shared when useful to resolve or prevent incidents, under TLP, after reasonable verification of bona fides - Vendors: technical vulnerability detail as needed to fix products; victim identity withheld unless permitted - Law enforcement: as required by applicable law - Public / press: no direct incident comment; refer to contact@fidelir.com for corporate communications Constituent confidential data is not disclosed to third parties except where legally compelled or expressly authorised. 4.3 Communication and Authentication Preferred channel: Email — soc@fidelir.com OpenPGP — fingerprint in section 2.8 Unencrypted email is acceptable for low-sensitivity coordination. Sensitive indicators, credentials, personal data or detailed forensic material SHOULD be OpenPGP-encrypted (or transferred by an agreed secure channel). Before relying on external reports or sharing restricted data, Fidelir CSIRT takes reasonable steps to authenticate the counterpart (FIRST directory when applicable, known peer contacts, organisational domain controls, callback where a number is known under contract, OpenPGP signatures). ------------------------------------------------------------------------ 5. Services ------------------------------------------------------------------------ 5.1 Incident Response 5.1.1 Incident Triage - Determine whether an incident occurred - Assess scope, severity and constituency impact - Assign handling priority 5.1.2 Incident Coordination - Facilitate contact with affected parties and peer teams - Exchange technical indicators under TLP - Engage abuse desks, providers or vendors as needed - Support lawful reporting to authorities when appropriate 5.1.3 Incident Resolution - Advise on containment, eradication and recovery - For Fidelir-operated systems: support remediation directly - For customers: support within contractual engagement scope - Post-incident notes / lessons learned when agreed 5.2 Proactive Activities - Maintain this RFC 2350 document and CSIRT contact channels - Hardening and monitoring of Fidelir infrastructure - Vulnerability intake for Fidelir public services (soc@) - Peer cooperation and FIRST participation as membership status allows - Security advisories for Fidelir services when warranted, published via the website and/or soc@fidelir.com ------------------------------------------------------------------------ 6. Incident Reporting Forms ------------------------------------------------------------------------ Email soc@fidelir.com with as much of the following as available: 1. Reporter name, organisation, role, callback contact 2. Date/time of observation (with time zone) 3. Affected systems / domains / IPs / ASNs 4. Description of the incident or vulnerability 5. Evidence (logs, headers, samples — malware only via agreed channel) 6. Impact observed or suspected 7. Actions already taken 8. Sharing permission / TLP label 9. Your OpenPGP fingerprint for encrypted replies (if any) The website contact form (https://fidelir.com/contact) is for general enquiries (contact@). Do not use it as the primary incident reporting channel; use soc@fidelir.com. No separate public web IR form at this time. ------------------------------------------------------------------------ 7. Disclaimers ------------------------------------------------------------------------ While every precaution will be taken in the preparation of information, notifications and alerts, Fidelir CSIRT assumes no responsibility for errors, omissions, or damages resulting from the use of the information provided. Support is provided on a best-effort basis according to the policies in this document and, for customers, the applicable contract. This document does not create a contractual SLA unless expressly incorporated into a signed agreement. Fidelir CSIRT is not a law-enforcement body and is not a national CSIRT. ------------------------------------------------------------------------ END OF Fidelir CSIRT RFC 2350 DESCRIPTION ------------------------------------------------------------------------