A journey into the Forum of Incident Response and Security Teams: what it is, how it works, the benefits it offers, and the case of the Campania Region CERT, accredited with the support of NEVERHACK.
Cyber resilience starts with collaboration
In today’s cybersecurity landscape, no organization can treat incident management as a purely internal capability. Threats are distributed and cross-border. Criminal groups or state actors often coordinate them. They strike companies, public administrations, technology suppliers and critical infrastructure at the same time. Regulations such as NIS2, DORA and the CRA have raised the compliance threshold. They set very short notification deadlines and demand a level of operational maturity that is hard to sustain in isolation.
A ransomware attack can hit a company in Italy yet starting from another continent. It may exploit compromised servers in several countries. It can spread through suppliers located anywhere in the world. In this scenario, no organization can truly defend itself alone, however large or well structured they are.
This awareness gave rise to FIRST more than thirty years ago. FIRST is an International community built to help incident response teams talk and trust to each other, and work together. It is worth explaining what it is, how it works and why more and more international organizations, both public and private, now choose to join.
What FIRST is: a non-profit at the service of the community
FIRST, Forum of Incident Response and Security Teams, is an International non-profit organization.
It is not a company. It does not sell products. It does not deliver commercial services. It is a community that brings together incident response teams from around the world on a voluntary basis.
Their members include government CERTs, national CSIRTs, in-house teams from large companies, university groups and civil society organizations. CSIRT Italia, now part of ACN, has been a member since 2023.
FIRST began informally in the United States in 1990. A worm called WANK had shown how hard it was for teams from different countries to coordinate during a cyber crisis. Five years later, in 1995, it became a formal non-profit association. Today it counts more than 800 member teams across more than 113 countries. You can browse the list of current FIRST members on the interactive world map that FIRST recently added to make consultation easier.
Three verbs sum up its simple yet ambitious mission: cooperate, share, prevent. Cooperate between teams that, in other contexts, would often be competitors. Share threat information in a confidential and timely way. Prevent incidents by helping less mature organizations grow. All of this happens without profit, funded through member fees and the events FIRST organizes.
How to join
Membership is open but not automatic, because it requires the involvement of sponsors. The community has defined three membership types to welcome different kinds of members:
- Full Member: this suits those who run an operational incident response team and have their own “constituency”, meaning a defined set of users or systems to protect. Only Full Members can vote in board elections and benefit from reduced rates for events.
- Associate Member: this suits organizations that want to take part in community life without running an operational team, such as universities, research bodies and associations.
- Liaison: this is an individual membership, reserved for single professionals who want to contribute to FIRST in a personal capacity.
The benefits of membership
For an organization that works in heavily regulated sectors, finance (DORA), critical infrastructure (NIS2, CER), products with digital elements (CRA) and Artificial Intelligence (AI Act), joining FIRST delivers a measurable return across several dimensions.
To step outside strictly technical language, it feels like walking into a room filled with the best incident response professionals in the world. You can ask them for support during a crisis, knowing there is someone you can trust.
Access to a global network of experts
The first benefit is relational. When a team joins FIRST, it gains access to confidential communication channels with peer teams around the world. These include mailing lists, a Slack workspace, a Wiki and an IoC sharing platform (MISP). There, a team can exchange operational information with hundreds of others. Members can get support and advice from expert colleagues across the network. This proves especially useful when handling complex incidents or rolling out new security strategies.
Shared knowledge and continuous growth
The second benefit is educational. FIRST hosts many thematic groups, called Special Interest Groups. In them, members discuss and develop international standards on topics such as vulnerability classification, sharing of sensitive information and disclosure ethics. Some of these standards later feed into European regulations. Consider the use of CVSS and TLP within NIS2, both developed by FIRST. Taking part therefore means more than learning. It means helping write the rules of the sector.
Events, symposia and the “Web of Trust”
The third benefit is human. Every year, FIRST organizes a global conference and many regional symposia, often with sessions reserved for members only. The Annual Conference is the sector’s main global event. The National CSIRT Meeting often runs alongside it, though access there comes by invitation only.
The most authentic value of these events lies in building what we can rightly call the Web of Trust: the network of human trust that connects the key contacts of the main government and private CERTs. Knowing a colleague in person changes everything. In a moment of need, a request for support during an attack does not reach a generic contact. It reaches a trusted counterpart. This has a direct effect on mitigation times and, as a result, on reactive efficiency.
Market recognition and credibility
The fourth benefit is reputational. Being a FIRST member now sends a strong signal to clients, partners and authorities. It means the team has passed a rigorous, peer-led evaluation that confirms its maturity. In many regulated sectors, from finance to critical infrastructure, FIRST membership is becoming a mark of reliability and competence. It improves a CERT’s reputation and increases the trust of stakeholders and commercial partners.
Becoming a Full Member: a demanding but formative path
Becoming a Full Member is not a bureaucratic act. It is a real growth journey. On average, the application takes about seven months of work and unfolds across roughly fifteen steps. Without going into too much detail, three moments best capture the spirit of the process.
The first is the search for sponsors. To join the community, a candidate needs two accredited Full Members, at least one from outside their own organization, who agree to guarantee for them. The mechanism recalls the old guilds. You do not get in because you pay a fee. You get in because someone already inside the community is willing to put their own reputation behind the newcomer.
The second moment is the self-assessment. The candidate measures its own maturity through an international model called SIM3. This model examines 44 aspects of an incident response team, from governance to processes, from people’s training to technical tools. The exercise often reveals areas for improvement and turns the application itself into a chance to grow.
The third moment is the site visit, the inspection that the Primary Sponsor carries out at the candidate team. It is not an exam. It is an in-depth technical exchange that ends in a report shared with the community. The Membership Committee then evaluates the application package, submits it to the community, and the FIRST board grants the final approval.
NEVERHACK and the Campania CERT journey
NEVERHACK has been an official FIRST member since 2024, when the company still operated under the name Innovery. Over the years, its presence in the community has grown stronger and has taken on a role that goes beyond simple participation. NEVERHACK guides other organizations, both public and private, through the accreditation process. It acts both as a formal sponsor and as a specialized consultant.
The most representative case, unique in Italy so far, is the Campania Region CERT. The Region had decided to build an incident response structure able to protect not only its own systems, but also those of local administrations and regional healthcare bodies. To give this CERT a truly international dimension, the goal from the start was to join FIRST.
NEVERHACK supported the regional CERT through a structured path. As a consultant, it ran a thorough gap analysis against the SIM3 criteria and identified the areas to strengthen in terms of organization, people, tools and processes. It then guided the development of a remediation plan that involving internal documentation, service governance and the catalogue of services offered to the regional constituency, as well as alignment with international reference models. In parallel, it took on the role of Primary Sponsor. It ran the site visit, validated the SIM3 self-assessment, drafted the letter of support, and guided the Campania team through its exchanges with the FIRST Secretariat and the Membership Committee.
The goal was achieved. The Campania Region CERT is now part of the FIRST community. It is the first case in Italy of a regional CERT admitted to the Forum. This milestone places Campania in a position of real prominence in the national and European landscape of public cybersecurity. For NEVERHACK, it confirmed its support model and showed in concrete terms how FIRST membership can serve the broader growth of the country.
A cultural choice before a technical one
Telling the story of FIRST means, in the end, telling the story of an idea. It is the idea that cybersecurity is not built by raising ever higher walls around your own organization, but by building bridges with those who face the same challenges. This vision demands humility, because it forces you to acknowledge your own limits. It also demands generosity, because it asks you to share what you have learned.
For NEVERHACK, being part of FIRST marked a cultural turning point before an operational one. It let us guide important organizations like the Campania Region CERT, and others we are supporting, toward a prestigious goal. It strengthened our clients’ trust. It brought experiences, contacts and good practices to enrich our work every day.
For anyone in the sector, knowing FIRST and how it works is now part of the basic cultural toolkit. For those who decide to join, the experience becomes a training ground for continuous growth. And for those who, like NEVERHACK, have chosen to guide others along this path, a concrete opportunity opens up: to contribute to the maturity of the cyber security ecosystem, one team at a time.