FIRST
- Company typePrivate
- Founded1989
- HeadquartersMorrisville, United States
- Headcount1–10
- GTM typeB2B
- OfferingServices
FIRST firmographics
Firmographics- Name
- FIRST
- Legal name
- FIRST.ORG, Inc.
- Website
- https://first.org
- Company type
- Private
- Founded year
- 1989
- Operating status
- Operating
- Headcount range
- 1–10 employees
- Ownership category
- akta.pro rank
FIRST industry classification
Industry- Product category
- Cybersecurity Standards & Incident Response Community
- NAICS
- Business Associations (813910), Convention and Trade Show Organizers (561920)
- SIC
- Services-Membership Organizations (8600), Services-Computer Programming, Data Processing, Etc. (7370)
- akta.pro primary industry
- Security Operations (SOC), Incident Response & Threat Hunting (EDAOAIAI)
- akta.pro secondary industries
- Executive/Board Security Advisory & Risk Briefings (BPAKADAK), Security Operations Center (SOC) as a Service (BPAEADAB)
Keywords
Where FIRST is headquartered
LocationHeadquarters
- HQ city
- Morrisville
- HQ country
- United States
- HQ region
- North America
Markets served
FIRST business model
Business model- GTM type
- B2B
- Offering type
- Services
- Cost components
- Personnel, Operations, Infrastructure, Technology or R&D
Revenue model
- Membership Fees: FIRST generates revenue through membership fees from teams, associates, and liaisons. The organization has more than 800 member organizations globally.
- Training and Education: FIRST offers training courses through FIRST Training, with certified trainers providing education on cybersecurity topics relevant to incident response.
- Conference and Event Registration: Revenue generated from annual conferences (FIRSTCON), regional symposiums, and technical colloquia registration fees.
- Sponsorships: Corporate sponsorship opportunities including FIRST CORE founding partnerships and event sponsorships.
Pricing tiers
| Model | Billing | Price |
|---|---|---|
| Subscription | Annual | Team Membership |
| Subscription | Annual | Associate Membership |
| Subscription | Annual | Liaison Membership |
Go-to-market motion1 record
Distribution channels5 records
Marketing channels7 records
FIRST product offering
Product offeringCore offering
FIRST (Forum of Incident Response and Security Teams) is a global non-profit membership organization for computer security incident response teams. It develops and maintains open cybersecurity standards such as CVSS, EPSS, and TLP, and provides members with community collaboration through Special Interest Groups, annual conferences, and training.
Product overview
FIRST (Forum of Incident Response and Security Teams) is a global membership organization, not a product company. It provides a suite of security standards, frameworks, and professional development programs rather than commercial software products. The core offerings include the Common Vulnerability Scoring System (CVSS) for vulnerability severity assessment, the Exploit Prediction Scoring System (EPSS) for prioritizing vulnerabilities, the Traffic Light Protocol (TLP) for information sharing classification, and the CSIRT/PSIRT Services Frameworks for structuring incident response operations. These are supplemented by the Information Exchange Policy (IEP) framework, an annual conference and regional technical colloquia, an IR team database directory, and professional development programs including fellowship and mentorship initiatives.
Differentiator
Problem solved
Functional benefit
Brands
- FIRSTCON: Annual FIRST Conference - the premier gathering for incident response and security teams globally
- FIRST Technical Colloquia
- Common Vulnerability Scoring System (CVSS)
- Exploit Prediction Scoring System (EPSS)
- Traffic Light Protocol (TLP)
- FIRST Impressions Podcast
- FIRSTCON Podcast
Products and services
- Common Vulnerability Scoring System (CVSS) A standardized method for describing the severity of security vulnerabilities. FIRST governs CVSS v4.0, v3.1, v3.0, and v2 specifications, calculators, user guides, and implementation guides. Used by security teams and vendors to assess and communicate vulnerability severity.
- Exploit Prediction Scoring System (EPSS) A data-driven / machine learning model that estimates the probability that a vulnerability will be exploited in the wild within the next 30 days, helping organizations prioritize remediation.
- Traffic Light Protocol (TLP) A set of color designations (RED, AMBER, GREEN, WHITE/CLEAR) used to ensure sensitive information is shared with the appropriate audience within security communities. TLP v2.0 is the current standard.
- CSIRT Services Framework A framework defining the services provided by Computer Security Incident Response Teams, helping organizations establish and operate effective incident response capabilities.
- PSIRT Services Framework A framework defining services provided by Product Security Incident Response Teams, guiding vendor product security teams in managing vulnerability disclosures.
- Information Exchange Policy (IEP) A standardized framework enabling organizations to share cyber threat intelligence and security information using policy-based rules and data formats, with an IEP 2.0 JSON specification.
- FIRST Conference (FIRSTCON) The annual flagship conference bringing together incident response teams, security professionals, and researchers globally, supplemented by regional symposiums. Registration-based access for members and non-members.
- FIRST Technical Colloquia Regional technical meetings providing forums for FIRST member teams and invited guests to discuss vulnerabilities, incidents, tools, and other incident response issues.
- FIRST Training Training courses and workshops delivered by certified FIRST trainers on incident response, threat intelligence, and security operations, including CVSS online training.
- IR Database A directory database of incident response teams worldwide, enabling organizations to locate and connect with relevant CSIRTs for coordination and collaboration.
- Fellowship & Mentorship Programs Professional development programs connecting experienced incident response professionals with emerging talent and enabling engagement with the FIRST community.
- Membership Program Annual membership for incident response teams available as Team, Associate, or Liaison categories, granting access to FIRST resources, Special Interest Groups, and the global trust community.
Quantifiable outcome
- 49,972 CVE disclosures tracked in 2025, with 2026 projections ranging from 59,000 (median) to 118,000 (90% CI upper bound)
- +1 more outcomes
Companies that use FIRST
Customer profileSegments4 records
Ideal customer profiles3 records
FIRST technology and API
TechnologyTechnology focussed No
API detail
- Has API
- No
- API docs
- API detail
Core technology
AI maturity
App detail
Feature6 records
FIRST partnerships and signals
Strategic signalPartnerships
Nine partnerships are on record, tiered core and moderate.
- Global Cyber AlliancecorePart of the 7-member secretariat for the Common Good Cyber Fund, coordinating efforts to support nonprofits protecting the internet with other partners including CyberPeace Institute and Shadowserver Foundation.
- CyberPeace InstitutecorePart of the 7-member secretariat for the Common Good Cyber Fund supporting nonprofits protecting the internet, coordinated with Global Cyber Alliance and Shadowserver Foundation.
- Shadowserver FoundationcorePart of the 7-member secretariat for the Common Good Cyber Fund, providing technical expertise alongside Global Cyber Alliance and CyberPeace Institute.
- ICASI (Industry Consortium for Advancement of Security on the Internet)moderateICASI proposed the establishment of the Vulnerability Coordination SIG to the FIRST Board of Directors after meetings at the FIRST Conference in Boston in 2014, demonstrating ongoing collaboration on vulnerability disclosure standards.
- APNIC (Asia Pacific Network Information Centre)moderateJointly organizes the FIRST-APNIC Technical Colloquium for the Asia Pacific region, combining FIRST's incident response community with APNIC's regional internet registry expertise.
- AfricaCERTmoderateJoint AfricaCERT Meeting held alongside the FIRST Regional Symposium for Africa, supporting capacity building for incident response across African nations.
- APCERT (Asia Pacific Computer Emergency Response Team)moderateJoint APCERT AGM conducted in conjunction with the FIRST Regional Symposium for Asia Pacific, coordinating regional incident response efforts.
- MITREcoreMITRE coordinates CVE (Common Vulnerabilities and Exposures) program which FIRST's CVSS SIG and VRDX-SIG work to support and integrate with, including joint activities in vulnerability identification summits.
- NIST (National Institute of Standards and Technology)moderateNIST participates in vulnerability reporting summits and standards development with FIRST, with NIST staff contributing to FIRST conferences and curriculum development.
Scale indicators5 records
Recent moves6 records
Expansion highlights5 records
FIRST competitors and assessment
Company assessmentDirect peers
- Cloud Security Alliance (CSA): Non-profit organization that promotes security best practices and standards in cloud computing, with global membership and working groups. Comparable to FIRST as a member-driven, standards-producing association with research working groups and conferences.
- (ISC)²: International non-profit association for information security professionals, best known for the CISSP certification. Comparable as a global membership body that issues credentials, runs annual conferences, and serves cybersecurity practitioners across regions.
- ISACA: Global, non-profit membership association for IT governance, risk, and cybersecurity professionals (CISA, CISM, CRISC). Directly comparable to FIRST as a member-driven organization that develops frameworks, offers training, and convenes security practitioners worldwide.
- OASIS Open: Non-profit standards body that develops open-source cybersecurity standards including STIX/TAXII, used in threat intelligence sharing. Closely comparable to FIRST as a member-governed, consensus-driven standards organization focused on security interoperability.
Emerging players
- EC-Council: Owner of the Certified Ethical Hacker (CEH) credential and operator of global cybersecurity certification programs. Comparable to FIRST Training as a certification body in the cybersecurity professional credentials market.
- APWG (Anti-Phishing Working Group): International coalition of industry, government, and law enforcement focused on cybercrime, including phishing and DNS abuse. Comparable to FIRST as a member-based, cross-sector convener producing shared data and standards for cyber incident response.
- SANS Institute: Provider of cybersecurity training and GIAC certifications, with strong overlap in the incident response and security operations training segment. Comparable to FIRST Training as a competing educational channel serving the same security practitioner audience.
Broad incumbents
- ENISA: European Union Agency for Cybersecurity, supporting CSIRTs and national cybersecurity capacity across EU member states. Comparable to FIRST as a coordinator of incident response capabilities with a standards-development and capacity-building mission.
- MITRE Corporation: US federally funded R&D center that operates the CVE program and maintains ATT&CK. A natural peer because FIRST's CVSS and VRDX-SIG work directly integrate with MITRE's CVE program, making them ecosystem partners and adjacent standards authorities.
- CERT Coordination Center (CERT/CC): Federally funded coordination center at Carnegie Mellon's Software Engineering Institute, focused on vulnerability analysis and incident response coordination. Comparable as a peer convener for the CSIRT community and historically connected to FIRST's origins.
Market position
Strengths4 records
Weaknesses4 records
Competitive moat5 records
Key risks5 records
Key highlights6 records
Customer concentration
FIRST social profiles
Digital presenceFIRST financial estimates
Financial estimateRevenue estimate
Valuation estimate
FIRST leadership team
Management profileNumber of profiles
Profiles2 records
FIRST funding detail
Funding detailFunding overview
Funding rounds
Investors
Funding detail is available on the Subscription and Enterprise plan.Contact sales →
FIRST M&A and investment
M&A and investmentM&A
Investments
M&A and investment is available on the Subscription and Enterprise plan.Contact sales →
Frequently asked questions about FIRST
What does FIRST do?
FIRST (Forum of Incident Response and Security Teams) is a global non-profit membership organization for computer security incident response teams. It develops and maintains open cybersecurity standards such as CVSS, EPSS, and TLP, and provides members with community collaboration through Special Interest Groups, annual conferences, and training.
Is FIRST a public or private company?
FIRST is a private company. It is classified as nonprofit foundation owned and is currently operating.
When was FIRST founded?
FIRST was founded in 1989. It employs 1 to 10 people.
Where is FIRST based?
FIRST is headquartered in Morrisville, United States, in the North America region.
How does FIRST make money?
Four revenue lines are on record. Membership Fees are the primary driver. The others are training and Education, conference and Event Registration and sponsorships.
Who are FIRST's main competitors?
Direct peers on record are Cloud Security Alliance (CSA), (ISC)², ISACA and OASIS Open. Emerging players are EC-Council, APWG (Anti-Phishing Working Group) and SANS Institute. Broad incumbents are ENISA, MITRE Corporation and CERT Coordination Center (CERT/CC).
Does FIRST have an API?
No public API is recorded for FIRST.
What industry is FIRST in?
FIRST's product category is Cybersecurity Standards & Incident Response Community. Its primary akta.pro industry code is EDAOAIAI, Security Operations (SOC), Incident Response & Threat Hunting, with a secondary code of BPAKADAK, Executive/Board Security Advisory & Risk Briefings. Its NAICS code is 813910 and its SIC code is 8600.