Developer docs
API playgroundTry for free, no card

Search company profiles

FIRST

Full company profile

uuid0009i4n

Namestring
FIRST
Legal namestring
FIRST.ORG, Inc.
Websiteurl
first.org
Company typeenum
Private
Founded yearint
1989
Operating statusenum
Operating
Ownership categoryenum
Headcount rangeband
1–10
akta.pro rankint
HeadquartersMorrisville, United States
HQ citystring
Morrisville
HQ countrystring
United States
HQ regionstring
North America
Markets served

Serves global market

Keyword5 values
incident response coordination, cybersecurity standards development, vulnerability scoring systems, threat intelligence sharing, security community membership
Industry3 codes
1Security Operations (SOC), Incident Response & Threat Hunting
CodeEDAOAIAIPrimaryYes
2Executive/Board Security Advisory & Risk Briefings
CodeBPAKADAKPrimaryNo
3Security Operations Center (SOC) as a Service
CodeBPAEADABPrimaryNo
NAICS code2 codes
  • Business Associations813910
  • Convention and Trade Show Organizers561920
SIC code2 codes
  • Services-Membership Organizations8600
  • Services-Computer Programming, Data Processing, Etc.7370
Product category
Cybersecurity Standards & Incident Response Community
GTM motion1 record

Each record includes

Type, Description, Source

Revenue model4 records
1Membership Fees
TypeSubscription Recurring
Description

FIRST generates revenue through membership fees from teams, associates, and liaisons. The organization has more than 800 member organizations globally.

first.org
2Training and Education
TypeProfessional Services
Description

FIRST offers training courses through FIRST Training, with certified trainers providing education on cybersecurity topics relevant to incident response.

first.org
3Conference and Event Registration
TypeTransaction Fee
Description

Revenue generated from annual conferences (FIRSTCON), regional symposiums, and technical colloquia registration fees.

first.org
4Sponsorships
TypeSubscription Recurring
Description

Corporate sponsorship opportunities including FIRST CORE founding partnerships and event sponsorships.

first.org
Marketing channels7 records

Each record includes

Title, Type, Stage, Description, Source

Distribution channels5 records

Each record includes

Title, Type, Scope, Target buyer, Description, Source

Cost components4 values
Personnel, Operations, Infrastructure, Technology or R&D
Pricing details3 tiers
1Team Membership
ModelSubscriptionBilling cadenceAnnual
Notes

Full membership for incident response teams with full access to FIRST resources, SIGs, and community.

first.org
2Associate Membership
ModelSubscriptionBilling cadenceAnnual
Notes

Membership category for organizations that support FIRST's mission but are not full CSIRTs.

first.org
3Liaison Membership
ModelSubscriptionBilling cadenceAnnual
Notes

For organizations seeking limited participation and connection with the FIRST community.

first.org
GTM typeB2B
B2B
Offering typeServices
Services
Brand1 of 7 records shown
1FIRSTCON
Description

Annual FIRST Conference - the premier gathering for incident response and security teams globally

first.org
+6 more records
Core offering1 text field

FIRST (Forum of Incident Response and Security Teams) is a global non-profit membership organization for computer security incident response teams. It develops and maintains open cybersecurity standards such as CVSS, EPSS, and TLP, and provides members with community collaboration through Special Interest Groups, annual conferences, and training.

Differentiator
Functional benefit
Problem solved
Quantifiable outcome1 of 2 values shown
  • 49,972 CVE disclosures tracked in 2025, with 2026 projections ranging from 59,000 (median) to 118,000 (90% CI upper bound)
+1 more record
Product overview1 text field

FIRST (Forum of Incident Response and Security Teams) is a global membership organization, not a product company. It provides a suite of security standards, frameworks, and professional development programs rather than commercial software products. The core offerings include the Common Vulnerability Scoring System (CVSS) for vulnerability severity assessment, the Exploit Prediction Scoring System (EPSS) for prioritizing vulnerabilities, the Traffic Light Protocol (TLP) for information sharing classification, and the CSIRT/PSIRT Services Frameworks for structuring incident response operations. These are supplemented by the Information Exchange Policy (IEP) framework, an annual conference and regional technical colloquia, an IR team database directory, and professional development programs including fellowship and mentorship initiatives.

Product and service12 records
1Common Vulnerability Scoring System (CVSS)
CategoryStandard/Framework
Description

A standardized method for describing the severity of security vulnerabilities. FIRST governs CVSS v4.0, v3.1, v3.0, and v2 specifications, calculators, user guides, and implementation guides. Used by security teams and vendors to assess and communicate vulnerability severity.

2Exploit Prediction Scoring System (EPSS)
CategoryStandard/Framework
Description

A data-driven / machine learning model that estimates the probability that a vulnerability will be exploited in the wild within the next 30 days, helping organizations prioritize remediation.

3Traffic Light Protocol (TLP)
CategoryStandard/Framework
Description

A set of color designations (RED, AMBER, GREEN, WHITE/CLEAR) used to ensure sensitive information is shared with the appropriate audience within security communities. TLP v2.0 is the current standard.

4CSIRT Services Framework
CategoryStandard/Framework
Description

A framework defining the services provided by Computer Security Incident Response Teams, helping organizations establish and operate effective incident response capabilities.

5PSIRT Services Framework
CategoryStandard/Framework
Description

A framework defining services provided by Product Security Incident Response Teams, guiding vendor product security teams in managing vulnerability disclosures.

6Information Exchange Policy (IEP)
CategoryStandard/Framework
Description

A standardized framework enabling organizations to share cyber threat intelligence and security information using policy-based rules and data formats, with an IEP 2.0 JSON specification.

7FIRST Conference (FIRSTCON)
CategoryEvent/Conference
Description

The annual flagship conference bringing together incident response teams, security professionals, and researchers globally, supplemented by regional symposiums. Registration-based access for members and non-members.

8FIRST Technical Colloquia
CategoryEvent/Conference
Description

Regional technical meetings providing forums for FIRST member teams and invited guests to discuss vulnerabilities, incidents, tools, and other incident response issues.

9FIRST Training
CategoryEducation/Training
Description

Training courses and workshops delivered by certified FIRST trainers on incident response, threat intelligence, and security operations, including CVSS online training.

10IR Database
CategoryDirectory/Resource
Description

A directory database of incident response teams worldwide, enabling organizations to locate and connect with relevant CSIRTs for coordination and collaboration.

11Fellowship & Mentorship Programs
CategoryProgram
Description

Professional development programs connecting experienced incident response professionals with emerging talent and enabling engagement with the FIRST community.

12Membership Program
CategoryMembership
Description

Annual membership for incident response teams available as Team, Associate, or Liaison categories, granting access to FIRST resources, Special Interest Groups, and the global trust community.

Scale indicator5 records

Each record includes

Type, Value, Description, Source

Partnership9 partners
Strategic tierCoreTypeStrategic or Co-development Partner
Description

Part of the 7-member secretariat for the Common Good Cyber Fund, coordinating efforts to support nonprofits protecting the internet with other partners including CyberPeace Institute and Shadowserver Foundation.

Strategic tierCoreTypeStrategic or Co-development Partner
Description

Part of the 7-member secretariat for the Common Good Cyber Fund supporting nonprofits protecting the internet, coordinated with Global Cyber Alliance and Shadowserver Foundation.

Strategic tierCoreTypeStrategic or Co-development Partner
Description

Part of the 7-member secretariat for the Common Good Cyber Fund, providing technical expertise alongside Global Cyber Alliance and CyberPeace Institute.

4ICASI (Industry Consortium for Advancement of Security on the Internet)
Strategic tierModerateTypeStrategic or Co-development Partner
Description

ICASI proposed the establishment of the Vulnerability Coordination SIG to the FIRST Board of Directors after meetings at the FIRST Conference in Boston in 2014, demonstrating ongoing collaboration on vulnerability disclosure standards.

first.org
Strategic tierModerateTypeStrategic or Co-development Partner
Description

Jointly organizes the FIRST-APNIC Technical Colloquium for the Asia Pacific region, combining FIRST's incident response community with APNIC's regional internet registry expertise.

Strategic tierModerateTypeStrategic or Co-development Partner
Description

Joint AfricaCERT Meeting held alongside the FIRST Regional Symposium for Africa, supporting capacity building for incident response across African nations.

7APCERT (Asia Pacific Computer Emergency Response Team)
Strategic tierModerateTypeStrategic or Co-development Partner
Description

Joint APCERT AGM conducted in conjunction with the FIRST Regional Symposium for Asia Pacific, coordinating regional incident response efforts.

first.org
Strategic tierCoreTypeTechnology or Integration
Description

MITRE coordinates CVE (Common Vulnerabilities and Exposures) program which FIRST's CVSS SIG and VRDX-SIG work to support and integrate with, including joint activities in vulnerability identification summits.

Strategic tierModerateTypeTechnology or Integration
Description

NIST participates in vulnerability reporting summits and standards development with FIRST, with NIST staff contributing to FIRST conferences and curriculum development.

Recent move6 records

Each record includes

Date, Type, Title, Description, Source

Expansion highlight5 records

Each record includes

Type, Description

Peers10 records
TypeDirect peer
Description

Non-profit organization that promotes security best practices and standards in cloud computing, with global membership and working groups. Comparable to FIRST as a member-driven, standards-producing association with research working groups and conferences.

TypeDirect peer
Description

International non-profit association for information security professionals, best known for the CISSP certification. Comparable as a global membership body that issues credentials, runs annual conferences, and serves cybersecurity practitioners across regions.

TypeEmerging player
Description

Owner of the Certified Ethical Hacker (CEH) credential and operator of global cybersecurity certification programs. Comparable to FIRST Training as a certification body in the cybersecurity professional credentials market.

TypeEmerging player
Description

International coalition of industry, government, and law enforcement focused on cybercrime, including phishing and DNS abuse. Comparable to FIRST as a member-based, cross-sector convener producing shared data and standards for cyber incident response.

5ENISA
TypeBroad incumbent
Description

European Union Agency for Cybersecurity, supporting CSIRTs and national cybersecurity capacity across EU member states. Comparable to FIRST as a coordinator of incident response capabilities with a standards-development and capacity-building mission.

TypeBroad incumbent
Description

US federally funded R&D center that operates the CVE program and maintains ATT&CK. A natural peer because FIRST's CVSS and VRDX-SIG work directly integrate with MITRE's CVE program, making them ecosystem partners and adjacent standards authorities.

TypeDirect peer
Description

Global, non-profit membership association for IT governance, risk, and cybersecurity professionals (CISA, CISM, CRISC). Directly comparable to FIRST as a member-driven organization that develops frameworks, offers training, and convenes security practitioners worldwide.

TypeEmerging player
Description

Provider of cybersecurity training and GIAC certifications, with strong overlap in the incident response and security operations training segment. Comparable to FIRST Training as a competing educational channel serving the same security practitioner audience.

TypeDirect peer
Description

Non-profit standards body that develops open-source cybersecurity standards including STIX/TAXII, used in threat intelligence sharing. Closely comparable to FIRST as a member-governed, consensus-driven standards organization focused on security interoperability.

TypeBroad incumbent
Description

Federally funded coordination center at Carnegie Mellon's Software Engineering Institute, focused on vulnerability analysis and incident response coordination. Comparable as a peer convener for the CSIRT community and historically connected to FIRST's origins.

Market position
Strengths4 records

Each record includes

Headline, Details, Source

Weaknesses4 records

Each record includes

Headline, Details, Source

Competitive moat5 records

Each record includes

Type, Details

Key risks5 records

Each record includes

Headline, Details, Source

Key highlights6 records

Each record includes

Headline, Details, Source

Customer concentration

Classification, Details

Segment4 records

Each record includes

Title, Type, Primary, Description, Pain point addressed, Use case, Source

Ideal customer profile3 records

Each record includes

Profile, Firmographic size, Sales motion, Sales cycle length, Buying structure, Purchase trigger, Buyer persona, Geography, Industry vertical, Primary use case, Description, Pain points, Evidence proof points, Target buyer

Technology focused
No
API detail
Has APIbool
No

Docs URL, Description

AI maturity
App detail

Has app

Feature6 records

Each record includes

Title, Differentiator, Description, Source

Core technology
Revenue estimate
Valuation estimate
Number of profiles
Profiles2 records

Each record includes

Name, Designation, Designation category, Overview, Profile commentary, Source

No data
No data
Funding overview

Funding stage, Last funding date, Total funding USD

Funding rounds

Each record includes

Round, Amount USD, Date, Pre money valuation, Total investors, Investors, News

Investors

Each record includes

Name, Type, Date of entry, Rounds participated, Website

Funding detail is available on the Subscription and Enterprise plan.Contact sales →

M&A

Each record includes

Name, Acquisition type, Announced date, Completed date, Status, Website, News

Investment

Each record includes

Name, Round, Announced date, Lead investor, Website, News

M&A and investment is available on the Subscription and Enterprise plan.Contact sales →

FIRST

Cybersecurity Standards & Incident Response Communityfirst.org

FIRST firmographics

Firmographics
Name
FIRST
Legal name
FIRST.ORG, Inc.
Website
https://first.org
Company type
Private
Founded year
1989
Operating status
Operating
Headcount range
1–10 employees
Ownership category
akta.pro rank

FIRST industry classification

Industry
Product category
Cybersecurity Standards & Incident Response Community
NAICS
Business Associations (813910), Convention and Trade Show Organizers (561920)
SIC
Services-Membership Organizations (8600), Services-Computer Programming, Data Processing, Etc. (7370)
akta.pro primary industry
Security Operations (SOC), Incident Response & Threat Hunting (EDAOAIAI)
akta.pro secondary industries
Executive/Board Security Advisory & Risk Briefings (BPAKADAK), Security Operations Center (SOC) as a Service (BPAEADAB)

Keywords

  • Incident response coordination
  • Cybersecurity standards development
  • Vulnerability scoring systems
  • Threat intelligence sharing
  • Security community membership

Where FIRST is headquartered

Location

Headquarters

HQ city
Morrisville
HQ country
United States
HQ region
North America

Markets served

FIRST business model

Business model
GTM type
B2B
Offering type
Services
Cost components
Personnel, Operations, Infrastructure, Technology or R&D

Revenue model

  1. Membership Fees: FIRST generates revenue through membership fees from teams, associates, and liaisons. The organization has more than 800 member organizations globally.
  2. Training and Education: FIRST offers training courses through FIRST Training, with certified trainers providing education on cybersecurity topics relevant to incident response.
  3. Conference and Event Registration: Revenue generated from annual conferences (FIRSTCON), regional symposiums, and technical colloquia registration fees.
  4. Sponsorships: Corporate sponsorship opportunities including FIRST CORE founding partnerships and event sponsorships.

Pricing tiers

ModelBillingPrice
SubscriptionAnnualTeam Membership
SubscriptionAnnualAssociate Membership
SubscriptionAnnualLiaison Membership

Go-to-market motion1 record

Distribution channels5 records

Marketing channels7 records

FIRST product offering

Product offering

Core offering

FIRST (Forum of Incident Response and Security Teams) is a global non-profit membership organization for computer security incident response teams. It develops and maintains open cybersecurity standards such as CVSS, EPSS, and TLP, and provides members with community collaboration through Special Interest Groups, annual conferences, and training.

Product overview

FIRST (Forum of Incident Response and Security Teams) is a global membership organization, not a product company. It provides a suite of security standards, frameworks, and professional development programs rather than commercial software products. The core offerings include the Common Vulnerability Scoring System (CVSS) for vulnerability severity assessment, the Exploit Prediction Scoring System (EPSS) for prioritizing vulnerabilities, the Traffic Light Protocol (TLP) for information sharing classification, and the CSIRT/PSIRT Services Frameworks for structuring incident response operations. These are supplemented by the Information Exchange Policy (IEP) framework, an annual conference and regional technical colloquia, an IR team database directory, and professional development programs including fellowship and mentorship initiatives.

Differentiator

Problem solved

Functional benefit

Brands

  • FIRSTCON: Annual FIRST Conference - the premier gathering for incident response and security teams globally
  • FIRST Technical Colloquia
  • Common Vulnerability Scoring System (CVSS)
  • Exploit Prediction Scoring System (EPSS)
  • Traffic Light Protocol (TLP)
  • FIRST Impressions Podcast
  • FIRSTCON Podcast

Products and services

  • Common Vulnerability Scoring System (CVSS) A standardized method for describing the severity of security vulnerabilities. FIRST governs CVSS v4.0, v3.1, v3.0, and v2 specifications, calculators, user guides, and implementation guides. Used by security teams and vendors to assess and communicate vulnerability severity.
  • Exploit Prediction Scoring System (EPSS) A data-driven / machine learning model that estimates the probability that a vulnerability will be exploited in the wild within the next 30 days, helping organizations prioritize remediation.
  • Traffic Light Protocol (TLP) A set of color designations (RED, AMBER, GREEN, WHITE/CLEAR) used to ensure sensitive information is shared with the appropriate audience within security communities. TLP v2.0 is the current standard.
  • CSIRT Services Framework A framework defining the services provided by Computer Security Incident Response Teams, helping organizations establish and operate effective incident response capabilities.
  • PSIRT Services Framework A framework defining services provided by Product Security Incident Response Teams, guiding vendor product security teams in managing vulnerability disclosures.
  • Information Exchange Policy (IEP) A standardized framework enabling organizations to share cyber threat intelligence and security information using policy-based rules and data formats, with an IEP 2.0 JSON specification.
  • FIRST Conference (FIRSTCON) The annual flagship conference bringing together incident response teams, security professionals, and researchers globally, supplemented by regional symposiums. Registration-based access for members and non-members.
  • FIRST Technical Colloquia Regional technical meetings providing forums for FIRST member teams and invited guests to discuss vulnerabilities, incidents, tools, and other incident response issues.
  • FIRST Training Training courses and workshops delivered by certified FIRST trainers on incident response, threat intelligence, and security operations, including CVSS online training.
  • IR Database A directory database of incident response teams worldwide, enabling organizations to locate and connect with relevant CSIRTs for coordination and collaboration.
  • Fellowship & Mentorship Programs Professional development programs connecting experienced incident response professionals with emerging talent and enabling engagement with the FIRST community.
  • Membership Program Annual membership for incident response teams available as Team, Associate, or Liaison categories, granting access to FIRST resources, Special Interest Groups, and the global trust community.

Quantifiable outcome

  • 49,972 CVE disclosures tracked in 2025, with 2026 projections ranging from 59,000 (median) to 118,000 (90% CI upper bound)
  • +1 more outcomes

Companies that use FIRST

Customer profile

Segments4 records

Ideal customer profiles3 records

FIRST technology and API

Technology

Technology focussed No

API detail

Has API
No
API docs
API detail

Core technology

AI maturity

App detail

Feature6 records

FIRST partnerships and signals

Strategic signal

Partnerships

Nine partnerships are on record, tiered core and moderate.

  • Global Cyber AlliancecoreStrategic or Co-development PartnerPart of the 7-member secretariat for the Common Good Cyber Fund, coordinating efforts to support nonprofits protecting the internet with other partners including CyberPeace Institute and Shadowserver Foundation.
  • CyberPeace InstitutecoreStrategic or Co-development PartnerPart of the 7-member secretariat for the Common Good Cyber Fund supporting nonprofits protecting the internet, coordinated with Global Cyber Alliance and Shadowserver Foundation.
  • Shadowserver FoundationcoreStrategic or Co-development PartnerPart of the 7-member secretariat for the Common Good Cyber Fund, providing technical expertise alongside Global Cyber Alliance and CyberPeace Institute.
  • ICASI (Industry Consortium for Advancement of Security on the Internet)moderateStrategic or Co-development PartnerICASI proposed the establishment of the Vulnerability Coordination SIG to the FIRST Board of Directors after meetings at the FIRST Conference in Boston in 2014, demonstrating ongoing collaboration on vulnerability disclosure standards.
  • APNIC (Asia Pacific Network Information Centre)moderateStrategic or Co-development PartnerJointly organizes the FIRST-APNIC Technical Colloquium for the Asia Pacific region, combining FIRST's incident response community with APNIC's regional internet registry expertise.
  • AfricaCERTmoderateStrategic or Co-development PartnerJoint AfricaCERT Meeting held alongside the FIRST Regional Symposium for Africa, supporting capacity building for incident response across African nations.
  • APCERT (Asia Pacific Computer Emergency Response Team)moderateStrategic or Co-development PartnerJoint APCERT AGM conducted in conjunction with the FIRST Regional Symposium for Asia Pacific, coordinating regional incident response efforts.
  • MITREcoreTechnology or IntegrationMITRE coordinates CVE (Common Vulnerabilities and Exposures) program which FIRST's CVSS SIG and VRDX-SIG work to support and integrate with, including joint activities in vulnerability identification summits.
  • NIST (National Institute of Standards and Technology)moderateTechnology or IntegrationNIST participates in vulnerability reporting summits and standards development with FIRST, with NIST staff contributing to FIRST conferences and curriculum development.

Scale indicators5 records

Recent moves6 records

Expansion highlights5 records

FIRST competitors and assessment

Company assessment

Direct peers

  • Cloud Security Alliance (CSA): Non-profit organization that promotes security best practices and standards in cloud computing, with global membership and working groups. Comparable to FIRST as a member-driven, standards-producing association with research working groups and conferences.
  • (ISC)²: International non-profit association for information security professionals, best known for the CISSP certification. Comparable as a global membership body that issues credentials, runs annual conferences, and serves cybersecurity practitioners across regions.
  • ISACA: Global, non-profit membership association for IT governance, risk, and cybersecurity professionals (CISA, CISM, CRISC). Directly comparable to FIRST as a member-driven organization that develops frameworks, offers training, and convenes security practitioners worldwide.
  • OASIS Open: Non-profit standards body that develops open-source cybersecurity standards including STIX/TAXII, used in threat intelligence sharing. Closely comparable to FIRST as a member-governed, consensus-driven standards organization focused on security interoperability.

Emerging players

  • EC-Council: Owner of the Certified Ethical Hacker (CEH) credential and operator of global cybersecurity certification programs. Comparable to FIRST Training as a certification body in the cybersecurity professional credentials market.
  • APWG (Anti-Phishing Working Group): International coalition of industry, government, and law enforcement focused on cybercrime, including phishing and DNS abuse. Comparable to FIRST as a member-based, cross-sector convener producing shared data and standards for cyber incident response.
  • SANS Institute: Provider of cybersecurity training and GIAC certifications, with strong overlap in the incident response and security operations training segment. Comparable to FIRST Training as a competing educational channel serving the same security practitioner audience.

Broad incumbents

  • ENISA: European Union Agency for Cybersecurity, supporting CSIRTs and national cybersecurity capacity across EU member states. Comparable to FIRST as a coordinator of incident response capabilities with a standards-development and capacity-building mission.
  • MITRE Corporation: US federally funded R&D center that operates the CVE program and maintains ATT&CK. A natural peer because FIRST's CVSS and VRDX-SIG work directly integrate with MITRE's CVE program, making them ecosystem partners and adjacent standards authorities.
  • CERT Coordination Center (CERT/CC): Federally funded coordination center at Carnegie Mellon's Software Engineering Institute, focused on vulnerability analysis and incident response coordination. Comparable as a peer convener for the CSIRT community and historically connected to FIRST's origins.

Market position

Strengths4 records

Weaknesses4 records

Competitive moat5 records

Key risks5 records

Key highlights6 records

Customer concentration

FIRST social profiles

Digital presence

FIRST financial estimates

Financial estimate

Revenue estimate

Valuation estimate

FIRST leadership team

Management profile

Number of profiles

Profiles2 records

FIRST funding detail

Funding detail

Funding overview

Funding rounds

Investors

Funding detail is available on the Subscription and Enterprise plan.Contact sales →

FIRST M&A and investment

M&A and investment

M&A

Investments

M&A and investment is available on the Subscription and Enterprise plan.Contact sales →

Frequently asked questions about FIRST

What does FIRST do?

FIRST (Forum of Incident Response and Security Teams) is a global non-profit membership organization for computer security incident response teams. It develops and maintains open cybersecurity standards such as CVSS, EPSS, and TLP, and provides members with community collaboration through Special Interest Groups, annual conferences, and training.

Is FIRST a public or private company?

FIRST is a private company. It is classified as nonprofit foundation owned and is currently operating.

When was FIRST founded?

FIRST was founded in 1989. It employs 1 to 10 people.

Where is FIRST based?

FIRST is headquartered in Morrisville, United States, in the North America region.

How does FIRST make money?

Four revenue lines are on record. Membership Fees are the primary driver. The others are training and Education, conference and Event Registration and sponsorships.

Who are FIRST's main competitors?

Direct peers on record are Cloud Security Alliance (CSA), (ISC)², ISACA and OASIS Open. Emerging players are EC-Council, APWG (Anti-Phishing Working Group) and SANS Institute. Broad incumbents are ENISA, MITRE Corporation and CERT Coordination Center (CERT/CC).

Does FIRST have an API?

No public API is recorded for FIRST.

What industry is FIRST in?

FIRST's product category is Cybersecurity Standards & Incident Response Community. Its primary akta.pro industry code is EDAOAIAI, Security Operations (SOC), Incident Response & Threat Hunting, with a secondary code of BPAKADAK, Executive/Board Security Advisory & Risk Briefings. Its NAICS code is 813910 and its SIC code is 8600.

Unlock the full company data

50 free credits on sign-up, no credit card required.

Contact sales
Live signals
Help Net SecurityAI vulnerability discovery is pushing 2026 CVEs toward 66,000AI-powered vulnerability discovery tools are driving a surge in CVE disclosures for 2026, with FIRST projecting the year to reach approximately 66,000 CVEs—well above original expectations. Tools such as Anthropic's Mythos and OpenAI's GPT-5.4-Cyber are autonomously hunting software flaws, exemplified by Mozilla's use of Anthropic's Project Glasswing to find and fix 271 bugs for Firefox 150. While total CVE counts are rising sharply, security researchers emphasize that the subset of actively exploited or high-risk vulnerabilities remains manageable, and organizations should focus patching efforts on that actionable subset rather than the inflated overall count.Computer WeeklyCVE volumes may plausibly reach 100,000 this yearThe Forum of Incident Response and Security Teams (FIRST) has released its annual Vulnerability Report predicting that CVE (Common Vulnerabilities and Exposures) disclosures in 2026 could reach 59,000 as a median figure, with realistic scenarios ranging from 70,000 to 100,000, and an upper bound of 118,000 within a 90% confidence interval. The organization noted that its 2025 prediction of 50,000 CVEs proved nearly accurate, with 49,972 actual disclosures recorded, and attributed the growth to rapid adoption of open source software, AI tools in vulnerability discovery, and the emergence of vibecoding. FIRST is urging organizations to scale their security operations and strategically prioritize vulnerability response ahead of what could be a record year for disclosures.FirstImproving Security TogetherFIRST is a global forum and premier organization for computer security incident response teams, facilitating cooperation and information sharing among its members. The organization currently has over 800 members from government, commercial, and educational sectors across Africa, the Americas, Asia, Europe, and Oceania.CodeantWhat Is EPSS? How Developers Can Fix the Right Vulnerabilities FirstIn 2026, CodeAnt integrates the Exploit Prediction Scoring System (EPSS) scores into its workflows to help developers prioritize vulnerabilities based on real-world exploit likelihood. This system, developed by FIRST.org, assigns a score indicating the probability of a vulnerability being exploited within the next 30 days, shifting the focus from severity to likelihood for improved security decision-making. The integration aims to streamline developer workflows and enhance risk management by providing actionable insights directly within the development environment.PR NewswireSpoločnosť Hikvision sa pripája k Fóru záchranných a bezpečnostných tímov s názvom FIRSTHikvision announced that its Hikvision Security Center (HSRC) has become a member of FIRST (Forum of Incident Response and Security Teams), a recognized global cybersecurity organization with over 400 member teams from 90 countries. The membership will enable Hikvision to share best practices and collaborate on addressing cybersecurity threats, with HSRC Director Wan Li having already presented at a FIRST Asia-Pacific symposium in Shanghai in October 2018. Hikvision stated it remains committed to adhering to cybersecurity standards including ISO 27001, ISO 9001:2008, CMMI Level 5, and AICPA SOC.PR NewswireHikvision ingressa no FIRST, o Fórum Global de Resposta a Incidentes e Equipes de SegurançaHikvision announced that its Security Response Center (HSRC) has become a full member of FIRST, the Forum of Incident Response and Security Teams, an international confederation of computer security incident response teams. The membership will enhance Hikvision's incident response capabilities and enable collaboration with over 400 member teams across 90 countries, while also connecting the company with major technology firms already part of the organization. The company participated in the FIRST Asia-Pacific Symposium in Shanghai in October, sharing insights on IoT botnets in the post-Mirai era.PR NewswireHikvision se une a FIRST, el Foro de Equipos de Respuesta a Incidentes de SeguridadHikvision announced that its Security Response Center (HSRC) has become a full member of FIRST (Forum of Incident Response and Security Teams), an international confederation of computer security incident response teams. The membership will enhance Hikvision's incident response capabilities and enable collaboration with over 400 member teams from 90 countries. Hikvision's HSRC head also presented research on IoT Botnets at the FIRST Asia-Pacific Symposium held in Shanghai in October.PR NewswireHikvision rejoint le FIRST, le Forum des équipes d'intervention et de sécurité en cas d'incidentHikvision announced that its Security Response Center (HSRC) has become a full member of the Forum of Incident Response and Security Teams (FIRST), an international confederation of cybersecurity incident response teams. The membership enables Hikvision to collaborate with over 400 teams from 90 countries and enhance its incident response capabilities. Hikvision also disclosed that its encryption module obtained FIPS 140-2 certification from the US National Institute of Standards and Technology.PR NewswireHikvision przyłącza się do forum reakcji na incydenty i zespołów bezpieczeństwa FIRSTHikvision's Security Response Center (HSRC) has joined FIRST, a leading international association for computer incident response teams. This membership allows Hikvision to collaborate with over 400 members across 90 countries to enhance incident response capabilities and share best practices in cybersecurity.PR NewswireHikvision Joins FIRST, the Forum of Incident Response and Security TeamsHikvision announced that its Hikvision Security Response Center (HSRC) has become a member of the Forum of Incident Response and Security Teams (FIRST), enabling collaboration with over 400 member teams from 90 countries. The membership aims to enhance Hikvision's incident response capabilities and contribute to global cybersecurity efforts. In October, HSRC participated in the FIRST Regional Symposium Asia-Pacific in Shanghai, presenting a case study on IoT Botnet challenges in the Post-Mirai Age.