The Computer Incident Response Center Luxembourg
- Company typePrivate
- Founded2008
- HeadquartersLuxembourg, Luxembourg
- Headcount11–50
- GTM typeB2B
- OfferingSoftware
The Computer Incident Response Center Luxembourg firmographics
Firmographics- Name
- The Computer Incident Response Center Luxembourg
- Legal name
- CIRCL Computer Incident Response Center Luxembourg
- Website
- https://circl.lu
- Company type
- Private
- Founded year
- 2008
- Operating status
- Operating
- Headcount range
- 11–50 employees
- Ownership category
- akta.pro rank
The Computer Incident Response Center Luxembourg industry classification
Industry- Product category
- Cybersecurity Incident Response Services
- SIC
- Communications Services, Nec (4899)
- akta.pro primary industry
- Critical Infrastructure Protection (CIP) & NERC-CIP Compliance (HDADAJAC)
Keywords
Where The Computer Incident Response Center Luxembourg is headquartered
LocationHeadquarters
- HQ city
- Luxembourg
- HQ country
- Luxembourg
- HQ region
- Europe
Offices1 record
Markets served
The Computer Incident Response Center Luxembourg business model
Business model- GTM type
- B2B
- Offering type
- Software
- Cost components
- Personnel, Technology or R&D, Operations, Infrastructure
Revenue model
- Government Funding: CIRCL is a government-driven initiative operated as part of Luxembourg's national cybersecurity infrastructure, funded through government appropriations rather than commercial revenue generation.
Go-to-market motion1 record
Distribution channels4 records
Marketing channels5 records
The Computer Incident Response Center Luxembourg product offering
Product offeringCore offering
CIRCL is the national Computer Emergency Response Team (CERT/CSIRT) for Luxembourg's private sector, communes, and non-governmental entities. It provides incident response coordination, threat intelligence sharing via MISP, malware analysis, coordinated vulnerability disclosure (CVD), and operates multiple open-source cybersecurity platforms and public services including Vulnerability-Lookup, GCVE, Pandora, and Hash Lookup.
Product overview
CIRCL operates as Luxembourg's national Computer Emergency Response Team (CERT/CSIRT), providing a comprehensive cybersecurity platform comprising open-source tools, public services, and coordinated vulnerability management. The core portfolio includes MISP for threat intelligence sharing, Dynamic Malware Analysis (DMA) for automated malware analysis, CIRCLean for USB sanitization, Passive DNS for historical DNS records, and Vulnerability-Lookup for aggregating vulnerability data from over 25 sources. The recently launched GCVE (Global CVE Allocation System) provides a decentralized alternative to the US CVE program, hosted on European-controlled infrastructure. Additional services include Hash Lookup API, BGP Ranking, PGP Key Server, Pandora document analysis, and various open-source tools including Lookyloo (web forensics), AIL Project (dark web monitoring), Kunai (threat hunting), FlowIntel (case management), and Cerebrate (trusted directory). CIRCL also serves as the national Coordinated Vulnerability Disclosure coordinator under NIS 2 and operates as a CVE Numbering Authority (CNA) under the ENISA CVE Root.
Differentiator
Problem solved
Functional benefit
Brands
- MISP: Malware Information Sharing Platform - a threat intelligence platform for sharing, storing and correlating Indicators of Compromise from targeted malware, attacks, or other cybersecurity threats.
- CIRCLean
- GCVE
- Vulnerability-Lookup
- Lookyloo
- Pandora
- Kunai
- Flowintel
- Cerebrate
- AIL Project
- Lacus
Products and services
- MISP (Malware Information Sharing Platform) Open-source threat intelligence platform for sharing, storing, and correlating Indicators of Compromise (IOCs) and tactical threat intelligence, enabling private sharing communities for coordinated defense across organizations.
- Dynamic Malware Analysis (DMA) Automated sandbox environment for analyzing malicious software, examining behavior patterns, and generating detailed threat reports for security researchers and incident responders.
- CIRCLean Open-source tool that automatically cleans documents from untrusted USB keys, removing potentially malicious content while preserving legitimate files, used by organizations handling untrusted media.
- Passive DNS Database service storing historical DNS records for incident response, threat intelligence, and security investigations, accessible to security professionals.
- Vulnerability-Lookup Fast vulnerability lookup and correlation platform aggregating data from over 25 public sources, providing a collaborative space for coordinated vulnerability disclosure.
- Global CVE Allocation System (GCVE) Decentralized alternative to the CVE program for identifying and numbering software security vulnerabilities. Allows independent numbering authorities to allocate identifiers without centralized control while maintaining backward compatibility with existing CVE infrastructure.
- Hash Lookup Public API service to lookup hash values against known database of malicious and benign files for threat identification, available to the security community.
- BGP Ranking Service for ranking and analyzing BGP (Border Gateway Protocol) data to identify potentially malicious network activity, used by network operators and security researchers.
- PGP Key Server Public key server for PGP/GPG keys, supporting secure communication and email encryption for the security community.
- Pandora Document and File Analysis
Quantifiable outcome
- Free incident reporting and response services for Luxembourg organizations
- +2 more outcomes
Companies that use The Computer Incident Response Center Luxembourg
Customer profileNamed customers3 records
Segments3 records
Ideal customer profiles3 records
The Computer Incident Response Center Luxembourg technology and API
TechnologyTechnology focussed Yes
API detail
- Has API
- Yes
- API docs
- API detail
Core technology
AI maturity
App detail
Feature15 records
The Computer Incident Response Center Luxembourg partnerships and signals
Strategic signalPartnerships
Seven partnerships are on record, tiered core, minor and flagship.
- ENISA (European Union Agency for Cybersecurity)coreCIRCL became a CVE Numbering Authority (CNA) under the ENISA CVE Root, enabling CIRCL to assign CVE IDs and publish CVE Records within its scope.
- MeliCERTes ProjectminorMeliCERTes was a three-year project to create open platforms for collaboration on cybersecurity, concluding in 2022.
- LHC - Luxembourg House of CybersecurityflagshipCIRCL operates under the Luxembourg House of Cybersecurity, a government initiative that houses Luxembourg's national cybersecurity capabilities. Copyright states 2008-2023 CIRCL operating under LHC.
- FIRST (Forum of Incident Response and Security Teams)coreCIRCL is a member of FIRST, the global forum for incident response and security teams, enabling collaboration and information sharing with other national and organizational CERTs worldwide.
- OASIS OpencoreCIRCL is a member of OASIS, participating in international standards development for cybersecurity and information sharing.
- GCVE InitiativecoreCIRCL launched and operates the Global CVE Allocation System (GCVE), a decentralized alternative for identifying software security vulnerabilities. The initiative addresses governance concerns after the traditional CVE program nearly collapsed.
- MISP ProjectcoreCIRCL is a key contributor and operator of the MISP (Malware Information Sharing Platform) threat intelligence sharing platform, offering private sharing communities.
Scale indicators4 records
Recent moves5 records
Expansion highlights5 records
The Computer Incident Response Center Luxembourg competitors and assessment
Company assessmentBroad incumbents
- ENISA (European Union Agency for Cybersecurity): EU-level cybersecurity agency that oversees the ENISA CVE Root under which CIRCL operates as a CNA. Directly comparable as the pan-European counterpart to CIRCL's national CERT role, with overlapping mandate in coordinated vulnerability disclosure and EU-wide cybersecurity coordination.
- CERT-Bund (Germany Federal Office for Information Security): Germany's federal CERT operated by BSI. Comparable as a national CERT providing incident response coordination and vulnerability disclosure for German public and private sector entities, with similar regulatory and sovereign positioning.
- NCSC-NL (National Cyber Security Centre Netherlands): Dutch national CERT providing incident response, threat intelligence, and coordinated vulnerability disclosure. Comparable as a European national CERT serving both private and public sector constituencies.
- NCSC (UK National Cyber Security Centre): UK's national CERT and cybersecurity authority. Directly comparable in role and function as a national government CERT providing incident response, vulnerability coordination, and threat intelligence to private and public sector entities.
- ANSSI (Agence Nationale de la Sécurité des Systèmes d'Information): France's national cybersecurity agency. Comparable as a peer national CERT providing incident response, vulnerability management, and threat intelligence services, with a similarly strong government-driven mandate.
- CISA (Cybersecurity and Infrastructure Security Agency): US national cybersecurity agency that operates alongside NIST NVD and MITRE in the CVE ecosystem. Comparable as a national CERT with a much larger scope, and a key stakeholder in the global vulnerability numbering infrastructure that GCVE seeks to complement.
- CCCS (Canadian Centre for Cyber Security): Canada's national CERT providing incident response and cybersecurity services to government, private sector, and critical infrastructure operators. Comparable in role and structure to CIRCL as a national authority.
Direct peers
- SWITCH-CERT: Swiss national CERT serving the academic, research, and private sector communities. Comparable as a smaller national CERT with similar mandate structure and active open-source tool contributions to the global CERT ecosystem.
Others
- Tenable (Nessus / Vulnerability Management): Commercial vulnerability management and exposure platform. While not a national CERT, Tenable is a relevant adjacent player whose commercial vulnerability intelligence capabilities overlap with CIRCL's Vulnerability-Lookup aggregation function.
Emerging players
- CVE Foundation: Independently funded successor initiative for the CVE program, explicitly formed as an alternative governance model. Directly comparable as a peer initiative addressing vulnerability numbering governance, and a competing alternative to CIRCL's GCVE.
Market position
Strengths5 records
Weaknesses2 records
Competitive moat5 records
Key risks5 records
Key highlights6 records
Customer concentration
The Computer Incident Response Center Luxembourg social profiles
Digital presenceThe Computer Incident Response Center Luxembourg compliance and trust
Trust signalCompliance5 records
The Computer Incident Response Center Luxembourg financial estimates
Financial estimateRevenue estimate
Valuation estimate
The Computer Incident Response Center Luxembourg leadership team
Management profileNumber of profiles
The Computer Incident Response Center Luxembourg funding detail
Funding detailFunding overview
Funding rounds
Investors
Funding detail is available on the Subscription and Enterprise plan.Contact sales →
The Computer Incident Response Center Luxembourg M&A and investment
M&A and investmentM&A
Investments
M&A and investment is available on the Subscription and Enterprise plan.Contact sales →
Frequently asked questions about The Computer Incident Response Center Luxembourg
What does The Computer Incident Response Center Luxembourg do?
CIRCL is the national Computer Emergency Response Team (CERT/CSIRT) for Luxembourg's private sector, communes, and non-governmental entities. It provides incident response coordination, threat intelligence sharing via MISP, malware analysis, coordinated vulnerability disclosure (CVD), and operates multiple open-source cybersecurity platforms and public services including Vulnerability-Lookup, GCVE, Pandora, and Hash Lookup.
Is The Computer Incident Response Center Luxembourg a public or private company?
The Computer Incident Response Center Luxembourg is a private company. It is classified as state government owned and is currently operating.
When was The Computer Incident Response Center Luxembourg founded?
The Computer Incident Response Center Luxembourg was founded in 2008. It employs 11 to 50 people.
Where is The Computer Incident Response Center Luxembourg based?
The Computer Incident Response Center Luxembourg is headquartered in Luxembourg, Luxembourg, in the Europe region.
How does The Computer Incident Response Center Luxembourg make money?
One revenue line is on record: government Funding.
Who are The Computer Incident Response Center Luxembourg's main competitors?
Broad incumbents on record are ENISA (European Union Agency for Cybersecurity), CERT-Bund (Germany Federal Office for Information Security), NCSC-NL (National Cyber Security Centre Netherlands), NCSC (UK National Cyber Security Centre), ANSSI (Agence Nationale de la Sécurité des Systèmes d'Information), CISA (Cybersecurity and Infrastructure Security Agency) and CCCS (Canadian Centre for Cyber Security). SWITCH-CERT is listed as a direct peer. Tenable (Nessus / Vulnerability Management) is listed as an others. CVE Foundation is listed as an emerging player.
Does The Computer Incident Response Center Luxembourg have an API?
Yes. Vulnerability-Lookup provides a public API for vulnerability data access. The API endpoint is available at /api/ with JSON dumps of vulnerability data including CSAF feeds from multiple vendors (Cisco, Microsoft, Siemens, F5, etc.), OSV data, NVD data, KEV entries, and other vulnerability catalogs. Hash lookup service provides a public API to lookup hash values against known database of files. Developer documentation is at vulnerability.circl.lu/api.
What industry is The Computer Incident Response Center Luxembourg in?
The Computer Incident Response Center Luxembourg's product category is Cybersecurity Incident Response Services. Its primary akta.pro industry code is HDADAJAC, Critical Infrastructure Protection (CIP) & NERC-CIP Compliance. Its SIC code is 4899.