CSIRT.global
CSIRT.global is a Dutch nonprofit, volunteer-led Computer Security Incident Response Team that delivers fully-funded bug bounty programs for charities and NGOs, conducts zero-day exploit research, and scans global university infrastructure through Project Global Universities.
- Company typePrivate
- Founded2022
- HeadquartersDen Haag, Netherlands
- Headcount11–50
- GTM typeB2B
- OfferingServices
What CSIRT.global does
CSIRT.global is a Dutch not-for-profit, volunteer-led Computer Security Incident Response Team founded in 2022 and headquartered in The Hague, Netherlands. It is structured as a sister organization to the Dutch Institute for Vulnerability Disclosure (DIVD), and operates three core service tracks: fully-funded Bug Bounty Programs for charities and NGOs, Exploit Research focused on zero-day vulnerability discovery, and Incident Response services delivered through named case identifiers (e.g., DIVD-CSIRT-2024-00035, DIVD-CSIRT-2024-00006). Its delivery model is organized around a three-tier researcher pipeline (Students → Professionals → Coordinators) and project-based programs such as Project Global Universities (PGU), which scans higher-education and NGO infrastructure to surface vulnerabilities at scale.
The underlying platform architecture combines scanning infrastructure for large-scale asset discovery with a coordinated human-research triage layer, supported by formal partnerships with DIVD Academy (training), DIVD Works (commercial arm), and basisbeveiliging.nl (responsible-disclosure outreach). Cases are publicly disclosed through numbered case files, providing transparency to affected organizations and the broader security community.
CSIRT.global runs as a mission-driven nonprofit rather than a commercial vendor. Revenue mechanics rely on donations, sponsorships, and partner contributions rather than customer fees; primary client segments are charities, NGOs, and universities served largely at no direct cost to the beneficiary. This positioning, together with the volunteer labor model, gives the organization a cost structure that is difficult for purely commercial CSIRTs to replicate while serving the same under-resourced client base.
CSIRT.global firmographics
Firmographics- Name
- CSIRT.global
- Legal name
- Stichting CSIRT.global
- Website
- https://csirt.global
- Company type
- Private
- Founded year
- 2022
- Operating status
- Operating
- Headcount range
- 11–50 employees
- Short description
- CSIRT.global is a Dutch nonprofit, volunteer-led Computer Security Incident Response Team that delivers fully-funded bug bounty programs for charities and NGOs, conducts zero-day exploit research, and scans global university infrastructure through Project Global Universities.
- Ownership category
- akta.pro rank
CSIRT.global industry classification
Industry- Product category
- Cybersecurity Vulnerability Disclosure and Incident Response Services
- NAICS
- Investigation and Security Services (5616), Investigation, Guard, and Armored Car Services (56161)
- akta.pro primary industry
- Vulnerability Management & Penetration Testing Services (BPAEADAD)
- akta.pro secondary industries
- Vulnerability Assessment, Security Audits & Compliance Testing (BPAKAHAG), Penetration Testing & Red Teaming (BPAKADAE), Vulnerability Intelligence & Exploit Prediction (HDADAHAI)
Keywords
Where CSIRT.global is headquartered
LocationHeadquarters
- HQ city
- Den Haag
- HQ country
- Netherlands
- HQ region
- Europe
Offices1 record
Markets served
CSIRT.global business model
Business model- GTM type
- B2B
- Offering type
- Services
- Cost components
- Personnel, Operations, Technology or R&D, Infrastructure, Others
Revenue model
- Not-for-profit / Donation-based: CSIRT.global is a not-for-profit organization. As a volunteer-led organization, they rely on volunteer contributions and likely donations/grants to fund operations. Bug bounty prize money is paid by CSIRT.global, suggesting some funding mechanism exists through grants or donations.
Pricing tiers
| Model | Billing | Price |
|---|---|---|
| Other | Pay-as-you-go | Free services for charities and NGOs |
Go-to-market motion1 record
Distribution channels3 records
Marketing channels4 records
CSIRT.global product offering
Product offeringCore offering
CSIRT.global runs fully funded Bug Bounty programs for charities and NGOs, conducts zero-day Exploit Research on public infrastructure, and provides Incident Response (CSIRT) services including vulnerability identification, owner notification, remediation assistance, and cooperation with National Cyber Security Centers. It also runs the Project Global Universities initiative that scans academic institutions worldwide for unpatched vulnerabilities.
Product overview
CSIRT.global is a volunteer-led, not-for-profit organization offering three core services: Bug Bounty Programs (fully funded for charities and NGOs), Exploit Research (zero-day vulnerability discovery), and Incident Response (CSIRT). The organization also runs Project Global Universities (PGU), a specific initiative focused on securing university systems, which serves as an internship opportunity for students while helping institutions improve their cybersecurity posture.
Differentiator
Problem solved
Functional benefit
Products and services
- Bug Bounty Programs
- Exploit Research
- Incident Response (CSIRT)
- Project Global Universities (PGU)
Quantifiable outcome
- Bug bounty programs fully funded by CSIRT.global - researchers paid based on severity of findings
- +1 more outcomes
Companies that use CSIRT.global
Customer profileNamed customers2 records
Segments2 records
Ideal customer profiles2 records
CSIRT.global technology and API
TechnologyTechnology focussed Yes
API detail
- Has API
- No
- API docs
- API detail
Core technology
AI maturity
App detail
Feature4 records
CSIRT.global partnerships and signals
Strategic signalPartnerships
Four partnerships are on record, tiered core and minor.
- Dutch Institute for Vulnerability Disclosure (DIVD)coreCSIRT.global is a sister organization to DIVD. In 2022, international CSIRT activities were moved to CSIRT.global as a first step to build an international network. Functionally, while DIVD is the primary source of vulnerability information and scanning information, CSIRT.global aims to have the issues fixed. They are two separate organisations and separate legal entities.
- DIVD AcademycoreDIVD Academy works together with CSIRT.global on the Project Global Universities (PGU). Students from DIVD Academy participate in security scanning and responsible vulnerability disclosure as part of their internship program.
- DIVD WorkscoreDIVD Works collaborates with CSIRT.global on the Project Global Universities (PGU), contributing volunteers and interns to the project scanning university systems for vulnerabilities.
- basisbeveiliging.nlminorPartner in the Project Global Universities (PGU) initiative, working together with CSIRT.global, DIVD Academy, and DIVD Works to help universities improve their security posture.
Scale indicators1 record
Recent moves6 records
Expansion highlights5 records
CSIRT.global competitors and assessment
Company assessmentDirect peers
- Bugcrowd: Crowdsourced cybersecurity platform running bug bounty, vulnerability disclosure, and pen testing programs. Directly comparable to CSIRT.global's bug bounty offering for charities and NGOs, though commercial and broader in customer base.
- NCSC-NL (National Cyber Security Centre Netherlands): Dutch government CSIRT that CSIRT.global explicitly cooperates with. Comparable as an incident response and vulnerability coordination body operating in the same national ecosystem and overlapping scope.
- Zero Day Initiative (Trend Micro): One of the longest-running vendor-agnostic zero-day vulnerability research programs. CSIRT.global's exploit research and zero-day discovery work is directly comparable in mission and methodology.
- HackerOne: Global bug bounty and vulnerability disclosure platform operating the same core category (vulnerability disclosure, researcher coordination). CSIRT.global's co-founder Michiel Prins works at HackerOne, and both run coordinated programs that incentivize external researchers to find and report vulnerabilities.
- Dutch Institute for Vulnerability Disclosure (DIVD): Sister organization of CSIRT.global and primary source of vulnerability scanning information. DIVD performs the scanning while CSIRT.global focuses on remediation, making them directly comparable as coordinated vulnerability disclosure organizations operating the same pipeline.
- CERT Coordination Center (CERT/CC) at Carnegie Mellon SEI: Pioneering computer security incident response team providing coordinated vulnerability disclosure and incident response services. Directly comparable to CSIRT.global's incident response and CVD mission at a global scale.
Emerging players
- Open Bug Bounty: Free, non-commercial bug bounty platform for responsible disclosure of web vulnerabilities. Comparable to CSIRT.global's free bug bounty offering for non-commercial beneficiaries.
- FIRST (Forum of Incident Response and Security Teams): Global association of CSIRTs and incident response teams that coordinates standards and best practices across the IR community. Comparable as the umbrella network in which CSIRT.global and similar national CSIRTs participate.
- Internet Bug Bounty: Community-funded bug bounty program targeting open-source and internet infrastructure, with HackerOne and Microsoft involvement. Closely comparable in mission to CSIRT.global's fully funded bug bounty for charities/NGOs.
Broad incumbents
- ENISA (European Union Agency for Cybersecurity): EU agency that coordinates vulnerability disclosure and supports national CSIRTs across member states. Comparable as a higher-level coordinator that CSIRT.global could increasingly partner with under frameworks like NIS2.
Market position
Strengths5 records
Weaknesses5 records
Competitive moat4 records
Key risks5 records
Key highlights6 records
Customer concentration
CSIRT.global social profiles
Digital presenceCSIRT.global financial estimates
Financial estimateRevenue estimate
Valuation estimate
CSIRT.global leadership team
Management profileNumber of profiles
Profiles12 records
CSIRT.global funding detail
Funding detailFunding overview
Funding rounds
Investors
Funding detail is available on the Subscription and Enterprise plan.Contact sales →
CSIRT.global M&A and investment
M&A and investmentM&A
Investments
M&A and investment is available on the Subscription and Enterprise plan.Contact sales →
Frequently asked questions about CSIRT.global
What does CSIRT.global do?
CSIRT.global runs fully funded Bug Bounty programs for charities and NGOs, conducts zero-day Exploit Research on public infrastructure, and provides Incident Response (CSIRT) services including vulnerability identification, owner notification, remediation assistance, and cooperation with National Cyber Security Centers. It also runs the Project Global Universities initiative that scans academic institutions worldwide for unpatched vulnerabilities.
Is CSIRT.global a public or private company?
CSIRT.global is a private company. It is classified as nonprofit foundation owned and is currently operating.
When was CSIRT.global founded?
CSIRT.global was founded in 2022. It employs 11 to 50 people.
Where is CSIRT.global based?
CSIRT.global is headquartered in Den Haag, Netherlands, in the Europe region.
How does CSIRT.global make money?
One revenue line is on record: not-for-profit / Donation-based.
Who are CSIRT.global's main competitors?
Direct peers on record are Bugcrowd, NCSC-NL (National Cyber Security Centre Netherlands), Zero Day Initiative (Trend Micro), HackerOne, Dutch Institute for Vulnerability Disclosure (DIVD) and CERT Coordination Center (CERT/CC) at Carnegie Mellon SEI. Emerging players are Open Bug Bounty, FIRST (Forum of Incident Response and Security Teams) and Internet Bug Bounty. ENISA (European Union Agency for Cybersecurity) is listed as a broad incumbent.
Does CSIRT.global have an API?
No public API is recorded for CSIRT.global.
What industry is CSIRT.global in?
CSIRT.global's product category is Cybersecurity Vulnerability Disclosure and Incident Response Services. Its primary akta.pro industry code is BPAEADAD, Vulnerability Management & Penetration Testing Services, with a secondary code of BPAKAHAG, Vulnerability Assessment, Security Audits & Compliance Testing. Its NAICS code is 5616.